HINF 500 Week 2 Legal, Ethical and Cybersecurity Issues in Health Informatics Example

Reviewed by Lenora Whitcombe, MSN, RN · University of Phoenix · Updated

This HINF 500 Week 2 example analyzes legal, ethical and cybersecurity issues that shape health informatics, through three situations facing the composite 310-bed community hospital whose operations vice president led the first paper. University of Phoenix HINF 500 turns in its second week to the rules and responsibilities that come with health data, and HINF/500 MHA students usually examine privacy, security, breach notification, patient access and the ethics of data use. The APA 7 paper takes three cases: a ransomware attack that shut down a neighboring health system and pushed its patients into this hospital's emergency department, a nurse found through audit logs to have opened a neighbor's record and a patient whose request to send records to a smartphone app was delayed for three weeks. Each is analyzed under privacy and security rules, federal information blocking rules and ethical principles. A 2025 proposal frames the response.

CourseHINF 500 Informatics for Health Administration (HINF/500)
Week2
Paper typeInformatics law and ethics paper
Lengthabout 1,250 words, 5 double-spaced pages plus title page and references
FormatAPA 7 student paper
SchoolUniversity of Phoenix
ProgramMHA
UpdatedSeptember 2026

Free sample paper for HINF 500 Week 2

1

A Ransomware Attack Next Door, a Nurse Who Looked Up a Neighbor and a Patient Who Wanted Her Records in an App: Legal and Ethical Duties in Hospital Informatics

[Student Name]

University of Phoenix

HINF/500: Informatics for Health Administration

Week 2 Assignment

[Instructor Name]

[Date]

The hospital, its incidents and its decisions are composites written for a model paper; laws, rules and research findings come from the sources listed.

What this part is doingThe title names three different kinds of problems, an attack, an insider and a delay, which the paper shows are governed by different rules.
2

On a Saturday morning in March, a neighboring health system 20 miles away lost access to its electronic records, phones and imaging after a ransomware attack and diverted ambulances. Within hours, the composite 310-bed community hospital's emergency department was full. The following Monday, the hospital's vice president of operations asked its information security officer, privacy officer and counsel for a review of the hospital's legal and ethical exposure in informatics. The review found three live issues. This paper analyzes each.

Case One: Ransomware

In a ransomware attack, criminals lock an organization's files and systems and sell back the key. It has become one of the most serious threats to health care. Researchers who built a database of every ransomware incident they could document against American care providers of all kinds found 374 over six years ending in 2021. The yearly count climbed from 43 to 91, the stolen or locked files held information on close to 42 million patients and about 44% of attacks interrupted care through system downtime, canceled appointments or ambulance diversion (Neprash et al., 2022). The effects spread beyond the victim. After an attack on a health system in San Diego, the daily census at a nearby, unaffected emergency department rose from a mean of 218 to 251 patients, with more ambulance arrivals and more stroke activations (Dameff et al., 2023). The hospital experienced exactly this spillover.

What this part is doingCiting the spillover study shows the board that an attack elsewhere is also this hospital's problem.
3

What the Law Requires

Under the HIPAA security rule, a hospital must analyze the risks to its electronic patient data and protect them in three ways: policies and training, physical protections for devices and facilities and technical controls such as access limits and audit logs. In January 2025, federal regulators proposed the most significant update to the rule in years, including requirements for multifactor authentication, encryption, an inventory of technology assets and network maps, regular vulnerability scanning and plans to restore critical systems within 72 hours (U.S. Department of Health and Human Services, 2025). If data are compromised in an attack, breach notification rules give the hospital at most 60 days from discovery, and less if a shorter delay is reasonable, to tell the people affected, and to federal regulators and the media when more than 500 people in a state are affected.

The Hospital's Gaps

Measured against the proposal, the hospital had gaps: multifactor authentication was used for remote access but not for administrator accounts, the asset inventory was two years old, backups were not tested for full restoration and downtime procedures had not been practiced since 2022. A phishing test sent to all employees the previous month had a click rate of 14%.

Case Two: A Nurse Looks Up a Neighbor

A routine audit of record access, run by the privacy office, flagged a medical-surgical nurse who had opened the record of a neighbor treated in the emergency department. She had no role in the neighbor's care. She said she was worried about him.

Law and Ethics in the Insider Case

The privacy rule permits use of protected health information for treatment, payment and operations and requires that access be limited to what staff need for their work. Viewing a record without a work reason is an impermissible use, whatever the motive. Ethically, the case turns on respect for privacy and trust: patients share information because they expect only their care team to see it. Curiosity and concern feel different to the person clicking, but to the patient both look like a stranger reading his chart. The hospital's policy called for discipline, retraining and an assessment of whether the incident was a reportable breach; because the access was unauthorized, the privacy officer documented a risk assessment and notified the patient.

Case Three: A Patient's Records and an App

A 58-year-old patient with diabetes asked the hospital to send her records to a smartphone app her endocrinologist recommended. The request sat for three weeks because staff were unsure whether sending data to an app was allowed.

What this part is doingThe access case is included because administrators often focus on keeping data in and forget duties to let it out.
4

What the Law Requires for Access

Patients have a right under the privacy rule to access their records, including in electronic form, and to direct them to a third party. Rules implementing the 21st Century Cures Act prohibit information blocking, meaning conduct that a provider knows is unreasonable and is likely to get in the way of patients or other providers obtaining or using electronic health information, unless an exception applies, such as preventing harm or protecting security (Office of the National Coordinator for Health Information Technology, 2020). Unnecessary delay in fulfilling a patient's request through a standard interface can be information blocking. Once data are in the app, the hospital is generally not responsible for how the app uses them, though it may educate patients about privacy risks.

Ethical Principles in Data Use

Four principles help frame informatics decisions. Respect for autonomy supports patient access and consent. Beneficence supports sharing data to improve care. Nonmaleficence requires protecting data from misuse and systems from failure. Justice asks whether protections and access are fair across patients, including those with limited technology. The three cases each involved a balance between protection and access.

The Board's Role

Cybersecurity and privacy are no longer only technical matters delegated to the information technology department. The hospital's board asked for a quarterly report covering phishing test results, the status of critical patches, backup restoration tests, audit findings and any incidents. Board members also joined a tabletop exercise simulating a ransomware attack, in which they had to decide whether to divert ambulances, how to communicate with patients and the public and whether to consider paying a ransom, which federal agencies discourage. The exercise revealed that no one knew who would authorize diversion if the chief executive could not be reached, a gap fixed with a written succession list.

Weighing Access Against Protection

The three cases pulled in opposite directions. The ransomware and insider cases called for tighter controls, while the app request called for easier access. A hospital that responds to attacks by locking everything down can end up blocking patients and other providers from information they have a right to. The review therefore paired every new control with a check on whether it would slow legitimate access, such as testing that multifactor authentication did not delay clinicians in emergencies.

Security Is People as Well as Technology

Many attacks start with people: a clicked phishing link, a reused password, an unlocked workstation. The hospital's 14% click rate showed that training and culture matter as much as software.

Seven Actions

The review recommended seven actions: extend multifactor authentication to all administrator and email accounts within 90 days; update the asset inventory and network map; test full restoration from backups twice a year; run a downtime drill in every department annually; repeat phishing tests quarterly with targeted training; expand automated access auditing with monthly reports to managers; and create a standard process for app-based record requests, with a five-day target.

Conclusion

The ransomware attack next door, the nurse's look at a neighbor's chart and the delayed app request each involved different rules: security safeguards, privacy limits and the duty not to block information. Together they show that legal and ethical duties in informatics run both ways: protect data from those who should not see it and deliver it promptly to those who should. The seven actions give the hospital a plan for both.

5

References

Dameff, C., Tully, J., Chan, T. C., Castillo, E. M., Savage, S., Maysent, P., Hemmen, T. M., Clay, B. J., & Longhurst, C. A. (2023). Ransomware attack associated with disruptions at adjacent emergency departments in the US. JAMA Network Open, 6(5), e2312270. https://doi.org/10.1001/jamanetworkopen.2023.12270

Neprash, H. T., McGlave, C. C., Cross, D. A., Virnig, B. A., Puskarich, M. A., Huling, J. D., Rozenshtein, A. Z., & Nikpay, S. S. (2022). Trends in ransomware attacks on US hospitals, clinics, and other health care delivery organizations, 2016-2021. JAMA Health Forum, 3(12), e224873. https://doi.org/10.1001/jamahealthforum.2022.4873

Office of the National Coordinator for Health Information Technology. (2020). 21st Century Cures Act: Interoperability, information blocking, and the ONC Health IT Certification Program. Federal Register, 85, 25642. https://www.federalregister.gov/d/2020-07419

U.S. Department of Health and Human Services. (2025). HIPAA Security Rule to strengthen the cybersecurity of electronic protected health information. Federal Register, 90, 898. https://www.federalregister.gov/d/2024-30983

What the HINF 500 Week 2 instructions ask

HINF 500 Week 2 usually asks students to analyze legal and ethical issues that affect health informatics. Students may be asked to explain privacy and security requirements for health information, describe cybersecurity threats and regulations, discuss breach notification, patient access and information sharing and apply ethical principles to data use. Some versions focus on cybersecurity regulations or ask students to analyze a recent, well-publicized breach. Strong papers state legal requirements accurately with sources, distinguish privacy from security, address current threats such as ransomware with data, include patients' rights to access their information and apply ethical reasoning to specific situations rather than listing principles.

How this HINF 500 Week 2 example is built

The paper opens with a Saturday morning when a neighboring health system's computers go dark after a ransomware attack and ambulances begin arriving at this hospital. Research showing that ransomware attacks on health care organizations more than doubled from 2016 to 2021 sets the scale. The hospital's own security gaps are measured against a proposed 2025 update to federal security rules. A nurse's unauthorized look at a neighbor's record is analyzed under privacy rules and ethics. A patient's delayed request to send records to an app is analyzed under information blocking rules. Seven actions, each with an owner and a deadline, close the paper, from multifactor authentication to a five-day target for app requests.

HINF 500 Week 2 grading rubric: where the points go

The law and ethics week is typically graded on accuracy about legal requirements and quality of reasoning in specific situations. Instructors look for correct explanation of privacy and security rules, breach notification, patient access and information blocking, current information on cybersecurity threats, ethical analysis using named principles and practical recommendations. Distinguishing what the law requires from what ethics suggests beyond it shows depth. Citing the rules and peer-reviewed research is expected, and dates matter because rules change. Organization and citation format make up the remainder, and papers that describe HIPAA in general terms without applying it to cases, or that treat security as only a technology problem, usually receive fewer points.

HINF 500 Week 2 help: mistakes to avoid

A common weakness in HINF 500 Week 2 is summarizing HIPAA without applying it. Work through specific situations: what does the law require here, and what does ethics add? Distinguish the privacy rule, which governs use and disclosure, from the security rule, which requires safeguards for electronic information. Include breach notification rules and patients' right of access. Cover information blocking, which many students forget. Use current data on cybersecurity threats and note that proposed rules may change requirements. Treat security as people and process as well as technology, since phishing and weak passwords cause many breaches. Finally, recommend actions with owners and deadlines, and explain how each would be checked and reported.

Related HINF 500 sample papers

Other HINF 500 week samples

More MHA sample papers

HINF 500 Week 2 questions, answered

What does HINF/500 Week 2 usually ask for?

Many sections ask students to analyze legal, ethical and cybersecurity issues in health informatics, including privacy and security rules, breaches, patient access and ethical use of data.

Where can I find a free HINF 500 Week 2 sample paper?

The three-case informatics law paper is posted above in full and anyone can read it for free, with margin notes on each case. If you need your own cases analyzed, we write your first paper at no charge.

How common are ransomware attacks on health care organizations?

A study found 374 ransomware attacks on U.S. health care delivery organizations from 2016 to 2021, exposing information on nearly 42 million patients, with annual attacks rising from 43 to 91.

What is information blocking?

Conduct by a provider, health IT developer or exchange that unreasonably gets in the way of obtaining or sharing electronic health information; rules under the 21st Century Cures Act prohibit it unless an exception applies.

What is the difference between the HIPAA privacy and security rules?

The privacy rule sets who may use or disclose patient information and for what purposes; the security rule sets the protections an organization must keep around electronic patient data, from training to encryption.

Write yours, or have the desk draft it

This paper is an original model document written by our desk, not a submitted student paper and not an official University of Phoenix document. Read it for the moves, then write your own to the instructions in your classroom. If you want one built to your exact prompt and rubric, the first custom sample is free and arrives in 24 to 48 hours.