| Course | HINF 500 Informatics for Health Administration (HINF/500) |
|---|---|
| Week | 2 |
| Paper type | Informatics law and ethics paper |
| Length | about 1,250 words, 5 double-spaced pages plus title page and references |
| Format | APA 7 student paper |
| School | University of Phoenix |
| Program | MHA |
| Updated | September 2026 |
Free sample paper for HINF 500 Week 2
A Ransomware Attack Next Door, a Nurse Who Looked Up a Neighbor and a Patient Who Wanted Her Records in an App: Legal and Ethical Duties in Hospital Informatics
[Student Name]
University of Phoenix
HINF/500: Informatics for Health Administration
Week 2 Assignment
[Instructor Name]
[Date]
The hospital, its incidents and its decisions are composites written for a model paper; laws, rules and research findings come from the sources listed.
On a Saturday morning in March, a neighboring health system 20 miles away lost access to its electronic records, phones and imaging after a ransomware attack and diverted ambulances. Within hours, the composite 310-bed community hospital's emergency department was full. The following Monday, the hospital's vice president of operations asked its information security officer, privacy officer and counsel for a review of the hospital's legal and ethical exposure in informatics. The review found three live issues. This paper analyzes each.
Case One: Ransomware
In a ransomware attack, criminals lock an organization's files and systems and sell back the key. It has become one of the most serious threats to health care. Researchers who built a database of every ransomware incident they could document against American care providers of all kinds found 374 over six years ending in 2021. The yearly count climbed from 43 to 91, the stolen or locked files held information on close to 42 million patients and about 44% of attacks interrupted care through system downtime, canceled appointments or ambulance diversion (Neprash et al., 2022). The effects spread beyond the victim. After an attack on a health system in San Diego, the daily census at a nearby, unaffected emergency department rose from a mean of 218 to 251 patients, with more ambulance arrivals and more stroke activations (Dameff et al., 2023). The hospital experienced exactly this spillover.
What the Law Requires
Under the HIPAA security rule, a hospital must analyze the risks to its electronic patient data and protect them in three ways: policies and training, physical protections for devices and facilities and technical controls such as access limits and audit logs. In January 2025, federal regulators proposed the most significant update to the rule in years, including requirements for multifactor authentication, encryption, an inventory of technology assets and network maps, regular vulnerability scanning and plans to restore critical systems within 72 hours (U.S. Department of Health and Human Services, 2025). If data are compromised in an attack, breach notification rules give the hospital at most 60 days from discovery, and less if a shorter delay is reasonable, to tell the people affected, and to federal regulators and the media when more than 500 people in a state are affected.
The Hospital's Gaps
Measured against the proposal, the hospital had gaps: multifactor authentication was used for remote access but not for administrator accounts, the asset inventory was two years old, backups were not tested for full restoration and downtime procedures had not been practiced since 2022. A phishing test sent to all employees the previous month had a click rate of 14%.
Case Two: A Nurse Looks Up a Neighbor
A routine audit of record access, run by the privacy office, flagged a medical-surgical nurse who had opened the record of a neighbor treated in the emergency department. She had no role in the neighbor's care. She said she was worried about him.
Law and Ethics in the Insider Case
The privacy rule permits use of protected health information for treatment, payment and operations and requires that access be limited to what staff need for their work. Viewing a record without a work reason is an impermissible use, whatever the motive. Ethically, the case turns on respect for privacy and trust: patients share information because they expect only their care team to see it. Curiosity and concern feel different to the person clicking, but to the patient both look like a stranger reading his chart. The hospital's policy called for discipline, retraining and an assessment of whether the incident was a reportable breach; because the access was unauthorized, the privacy officer documented a risk assessment and notified the patient.
Case Three: A Patient's Records and an App
A 58-year-old patient with diabetes asked the hospital to send her records to a smartphone app her endocrinologist recommended. The request sat for three weeks because staff were unsure whether sending data to an app was allowed.
What the Law Requires for Access
Patients have a right under the privacy rule to access their records, including in electronic form, and to direct them to a third party. Rules implementing the 21st Century Cures Act prohibit information blocking, meaning conduct that a provider knows is unreasonable and is likely to get in the way of patients or other providers obtaining or using electronic health information, unless an exception applies, such as preventing harm or protecting security (Office of the National Coordinator for Health Information Technology, 2020). Unnecessary delay in fulfilling a patient's request through a standard interface can be information blocking. Once data are in the app, the hospital is generally not responsible for how the app uses them, though it may educate patients about privacy risks.
Ethical Principles in Data Use
Four principles help frame informatics decisions. Respect for autonomy supports patient access and consent. Beneficence supports sharing data to improve care. Nonmaleficence requires protecting data from misuse and systems from failure. Justice asks whether protections and access are fair across patients, including those with limited technology. The three cases each involved a balance between protection and access.
The Board's Role
Cybersecurity and privacy are no longer only technical matters delegated to the information technology department. The hospital's board asked for a quarterly report covering phishing test results, the status of critical patches, backup restoration tests, audit findings and any incidents. Board members also joined a tabletop exercise simulating a ransomware attack, in which they had to decide whether to divert ambulances, how to communicate with patients and the public and whether to consider paying a ransom, which federal agencies discourage. The exercise revealed that no one knew who would authorize diversion if the chief executive could not be reached, a gap fixed with a written succession list.
Weighing Access Against Protection
The three cases pulled in opposite directions. The ransomware and insider cases called for tighter controls, while the app request called for easier access. A hospital that responds to attacks by locking everything down can end up blocking patients and other providers from information they have a right to. The review therefore paired every new control with a check on whether it would slow legitimate access, such as testing that multifactor authentication did not delay clinicians in emergencies.
Security Is People as Well as Technology
Many attacks start with people: a clicked phishing link, a reused password, an unlocked workstation. The hospital's 14% click rate showed that training and culture matter as much as software.
Seven Actions
The review recommended seven actions: extend multifactor authentication to all administrator and email accounts within 90 days; update the asset inventory and network map; test full restoration from backups twice a year; run a downtime drill in every department annually; repeat phishing tests quarterly with targeted training; expand automated access auditing with monthly reports to managers; and create a standard process for app-based record requests, with a five-day target.
Conclusion
The ransomware attack next door, the nurse's look at a neighbor's chart and the delayed app request each involved different rules: security safeguards, privacy limits and the duty not to block information. Together they show that legal and ethical duties in informatics run both ways: protect data from those who should not see it and deliver it promptly to those who should. The seven actions give the hospital a plan for both.
References
Dameff, C., Tully, J., Chan, T. C., Castillo, E. M., Savage, S., Maysent, P., Hemmen, T. M., Clay, B. J., & Longhurst, C. A. (2023). Ransomware attack associated with disruptions at adjacent emergency departments in the US. JAMA Network Open, 6(5), e2312270. https://doi.org/10.1001/jamanetworkopen.2023.12270
Neprash, H. T., McGlave, C. C., Cross, D. A., Virnig, B. A., Puskarich, M. A., Huling, J. D., Rozenshtein, A. Z., & Nikpay, S. S. (2022). Trends in ransomware attacks on US hospitals, clinics, and other health care delivery organizations, 2016-2021. JAMA Health Forum, 3(12), e224873. https://doi.org/10.1001/jamahealthforum.2022.4873
Office of the National Coordinator for Health Information Technology. (2020). 21st Century Cures Act: Interoperability, information blocking, and the ONC Health IT Certification Program. Federal Register, 85, 25642. https://www.federalregister.gov/d/2020-07419
U.S. Department of Health and Human Services. (2025). HIPAA Security Rule to strengthen the cybersecurity of electronic protected health information. Federal Register, 90, 898. https://www.federalregister.gov/d/2024-30983
What the HINF 500 Week 2 instructions ask
HINF 500 Week 2 usually asks students to analyze legal and ethical issues that affect health informatics. Students may be asked to explain privacy and security requirements for health information, describe cybersecurity threats and regulations, discuss breach notification, patient access and information sharing and apply ethical principles to data use. Some versions focus on cybersecurity regulations or ask students to analyze a recent, well-publicized breach. Strong papers state legal requirements accurately with sources, distinguish privacy from security, address current threats such as ransomware with data, include patients' rights to access their information and apply ethical reasoning to specific situations rather than listing principles.
How this HINF 500 Week 2 example is built
The paper opens with a Saturday morning when a neighboring health system's computers go dark after a ransomware attack and ambulances begin arriving at this hospital. Research showing that ransomware attacks on health care organizations more than doubled from 2016 to 2021 sets the scale. The hospital's own security gaps are measured against a proposed 2025 update to federal security rules. A nurse's unauthorized look at a neighbor's record is analyzed under privacy rules and ethics. A patient's delayed request to send records to an app is analyzed under information blocking rules. Seven actions, each with an owner and a deadline, close the paper, from multifactor authentication to a five-day target for app requests.
HINF 500 Week 2 grading rubric: where the points go
The law and ethics week is typically graded on accuracy about legal requirements and quality of reasoning in specific situations. Instructors look for correct explanation of privacy and security rules, breach notification, patient access and information blocking, current information on cybersecurity threats, ethical analysis using named principles and practical recommendations. Distinguishing what the law requires from what ethics suggests beyond it shows depth. Citing the rules and peer-reviewed research is expected, and dates matter because rules change. Organization and citation format make up the remainder, and papers that describe HIPAA in general terms without applying it to cases, or that treat security as only a technology problem, usually receive fewer points.
HINF 500 Week 2 help: mistakes to avoid
A common weakness in HINF 500 Week 2 is summarizing HIPAA without applying it. Work through specific situations: what does the law require here, and what does ethics add? Distinguish the privacy rule, which governs use and disclosure, from the security rule, which requires safeguards for electronic information. Include breach notification rules and patients' right of access. Cover information blocking, which many students forget. Use current data on cybersecurity threats and note that proposed rules may change requirements. Treat security as people and process as well as technology, since phishing and weak passwords cause many breaches. Finally, recommend actions with owners and deadlines, and explain how each would be checked and reported.
Related HINF 500 sample papers
Other HINF 500 week samples
- HINF 500 Week 1: Informatics as a Strategic Tool
- HINF 500 Week 3: How Data Are Collected and Reported
- HINF 500 Week 4: Information Systems Department Roles
- HINF 500 Week 5: Data for an Administrative Decision
- HINF 500 Week 6: Management Evaluation Report
More MHA sample papers
- GHA 548 Week 2: Myths and Stereotypes of Aging
- HCS 504 Week 2: Scholarly Sources
- HCS 529 Week 2: Needs Assessment and Site Selection
HINF 500 Week 2 questions, answered
What does HINF/500 Week 2 usually ask for?
Many sections ask students to analyze legal, ethical and cybersecurity issues in health informatics, including privacy and security rules, breaches, patient access and ethical use of data.
Where can I find a free HINF 500 Week 2 sample paper?
The three-case informatics law paper is posted above in full and anyone can read it for free, with margin notes on each case. If you need your own cases analyzed, we write your first paper at no charge.
How common are ransomware attacks on health care organizations?
A study found 374 ransomware attacks on U.S. health care delivery organizations from 2016 to 2021, exposing information on nearly 42 million patients, with annual attacks rising from 43 to 91.
What is information blocking?
Conduct by a provider, health IT developer or exchange that unreasonably gets in the way of obtaining or sharing electronic health information; rules under the 21st Century Cures Act prohibit it unless an exception applies.
What is the difference between the HIPAA privacy and security rules?
The privacy rule sets who may use or disclose patient information and for what purposes; the security rule sets the protections an organization must keep around electronic patient data, from training to encryption.
Write yours, or have the desk draft it
This paper is an original model document written by our desk, not a submitted student paper and not an official University of Phoenix document. Read it for the moves, then write your own to the instructions in your classroom. If you want one built to your exact prompt and rubric, the first custom sample is free and arrives in 24 to 48 hours.
Request this one custom, free · All HINF 500 week samples · All courses