HINF 510 Week 5 IT Security, Disaster Recovery and Business Continuity Planning Example

Reviewed by Lenora Whitcombe, MSN, RN · University of Phoenix · Updated

This HINF 510 Week 5 example plans IT security, disaster recovery and business continuity for the new record at a composite group of health centers running 14 clinic sites. Week five of University of Phoenix HINF 510 considers how an organization protects a clinical system and keeps caring for patients when it fails, and HINF/510 MHA students usually cover security threats and controls, recovery objectives and the procedures clinics follow during downtime. The APA 7 paper uses the federal voluntary cybersecurity practices published for health care in 2023, which name five major threats and ten practices, to set security priorities for a medium-sized organization. It defines recovery time and data loss targets for each system, explains how a vendor-hosted record changes recovery planning and describes clinic operations during an outage. Federal emergency preparedness requirements for health centers and a sociotechnical approach to ransomware shape the plan.

CourseHINF 510 The Systems Life Cycle (HINF/510)
Week5
Paper typeSecurity and continuity paper
Lengthabout 1,227 words, 4 double-spaced pages plus title page and references
FormatAPA 7 student paper
SchoolUniversity of Phoenix
ProgramMHA
UpdatedSeptember 2026

Free sample paper for HINF 510 Week 5

1

If the Record Goes Dark at 9 a.m. on a Monday: Security, Disaster Recovery and Continuity Planning for a 14-Clinic Health Center Network's New System

[Student Name]

University of Phoenix

HINF/510: The Systems Life Cycle

Week 5 Assignment

[Instructor Name]

[Date]

The health center network, its systems, targets and exercises are composites written for a model paper; federal guidance, rules and research come from the sources listed.

What this part is doingThe title sets a specific time and day, because continuity plans are only useful if they work on an ordinary busy morning.
2

Six weeks before the first clinics were due to switch systems, the project team ran a tabletop exercise built on one scenario: at 9 a.m. on a Monday, with about 900 patients scheduled across the network, the new electronic record becomes unavailable and the vendor reports a ransomware incident at its hosting center. The exercise revealed that no one was sure who would decide to reschedule patients, how clinicians would see medication lists or how prescriptions would be sent. This paper sets out the security, disaster recovery and continuity plan built from that exercise.

Three Different Problems

Security, disaster recovery and business continuity are related but distinct. Security aims to prevent, detect and respond to attacks and misuse. Disaster recovery restores systems and data after a failure, whatever the cause. Business continuity keeps essential work, especially patient care, going while systems are down. A plan that covers only one leaves the others to improvisation.

Starting From Risk

The network's security officer led a risk assessment covering the new record, the network, devices, the telehealth platform and remaining departmental systems. To set priorities, the team used the federal voluntary cybersecurity practices for health care, whose 2023 edition names five major threats, social engineering such as phishing, ransomware, loss or theft of equipment or data, insider accidental or malicious data loss and attacks on connected medical devices, and describes ten practices scaled to small, medium and large organizations (U.S. Department of Health and Human Services, 2023). The network, with about 390 users, fits the medium category.

What this part is doingUsing the federal practices gives the plan an external benchmark, so priorities do not depend only on the team's opinions.
3

Security Gaps and Controls

Mapping the network against the ten practices found gaps in five. Email protection lacked advanced filtering and simulated phishing training. Access management had no multifactor authentication for remote access to some systems. Asset management had no complete inventory of devices, including the outreach van's laptops and a dental imaging system. Vulnerability management applied patches irregularly. Incident response had a written plan no one had practiced. The plan adds advanced email filtering and quarterly phishing simulations, multifactor authentication for all remote and administrative access, a device inventory with encryption for every laptop, a monthly patching cycle with tracking and an incident response retainer with an outside firm.

Recovery Targets

For each critical system, the team set a recovery time objective, how quickly it must be restored, and a recovery point objective, how much recent data could be lost. The record: four hours and 15 minutes. E-prescribing: four hours. The telephone system: two hours, because patients must be able to reach clinics. The patient portal: 24 hours. Internet connections at each clinic: four hours, supported by a second connection from a different carrier at the six largest clinics.

What Hosting Changes

The new record is hosted by its vendor, which shifts responsibility for servers, backups and data center recovery to the vendor but does not remove the network's responsibility for its patients. The team reviewed the contract: the vendor commits to 99.9% availability, backups replicated to a second data center and restoration targets consistent with the network's, with notification of security incidents within 24 hours. The network added a contract requirement for an annual recovery test report.

Business Continuity Access

Each clinic receives a protected continuity workstation, updated every 15 minutes with the day's schedules and a read-only summary for each scheduled patient: problems, medications, allergies, recent results and care plans. The workstation runs on a battery backup and does not depend on the network connection once updated, so clinicians can see essential information even if the record is unreachable.

Clinic Downtime Procedures

Each clinic keeps a downtime binder with paper forms matching the record's templates, instructions for prescribing by phone or printed prescription, fax procedures for laboratory orders and results, a script for front-desk staff and a decision guide. For outages expected to last under two hours, clinics continue seeing patients using continuity workstations and paper. For longer outages, the medical director and operations director decide which visits to keep, prioritizing urgent, prenatal and medication-dependent patients. After recovery, paper documentation is entered into the record within 72 hours, with scanning of paper notes.

Ransomware Across the Whole System

Ransomware is not only a technical problem. Singh and Sittig's sociotechnical approach to ransomware looks across every dimension of a health information system, including hardware and software, clinical content, the user interface, people, workflow and communication, organizational policies, external rules and measurement, and recommends actions in each (Singh & Sittig, 2016). A backup that has never been restored is a hope, not a recovery plan. Following that approach, the plan includes staff training, downtime workflows, leadership decision rules, communication with patients and regular restoration tests, not only technical controls.

Regulatory Requirements

Federal emergency preparedness requirements apply to health centers participating in Medicare and Medicaid and expect each center to assess risks from all kinds of hazards, write an emergency plan with supporting procedures, keep a way to reach staff, patients and authorities during a crisis and train and drill its people (Centers for Medicare & Medicaid Services, 2016). The network's plan includes cyber events as a hazard alongside storms and power loss. The HIPAA security rule adds its own contingency duties: backing up data, planning recovery and keeping critical protections running while operating in emergency mode.

What this part is doingFolding cyber events into the all-hazards plan shows the network treating an outage as an emergency, not an IT inconvenience.
4

Medical Devices and the Outreach Van

Connected devices are often forgotten. The network's dental imaging sensors, spirometers, a retinal camera for diabetic eye screening and vaccine refrigerator monitors all connect to the network, some running outdated operating systems the manufacturers no longer update. The plan places these devices on a separate network segment, lists them in the asset inventory and requires security review before any new device connects. The mobile outreach van, which serves homeless shelters and farmworker camps, poses a different risk: it works where connections are unreliable. Its tablets encrypt data, synchronize when a connection returns and can be wiped remotely if lost.

People and Training

Most attacks begin with a person. All staff complete annual security training, with a short module on recognizing phishing, and new staff complete it before receiving access. Managers learn how to report a suspected incident immediately, since early reporting limits damage. The first phishing simulation, sent before training, had a click rate of 17%; the goal is below 5% within a year.

Communication

The communication plan assigns who informs staff, patients, partners and regulators, using text messaging and phone trees that do not depend on the network's email. A prepared patient notice explains delays without speculating about causes.

Testing the Plan

The plan is tested through quarterly downtime drills at each clinic, an annual network-wide tabletop exercise including the vendor and a restoration test of the network's own backups twice a year. The first drill after the tabletop found that two clinics' continuity workstations had not updated for three days because of a configuration error, which was fixed.

Conclusion

The Monday morning scenario exposed gaps in decisions, not only in technology. The plan now addresses security through federal practices, sets recovery targets for each critical system, clarifies the vendor's obligations, gives clinics continuity workstations and downtime procedures and meets emergency preparedness requirements. Regular drills will keep testing it, so that if the record goes dark on an ordinary Monday, patients are still seen.

5

References

Centers for Medicare & Medicaid Services. (2016). Medicare and Medicaid programs; Emergency preparedness requirements for Medicare and Medicaid participating providers and suppliers. Federal Register, 81, 63860. https://www.federalregister.gov/d/2016-21404

Singh, H., & Sittig, D. F. (2016). A socio-technical approach to preventing, mitigating, and recovering from ransomware attacks. Applied Clinical Informatics, 7(2), 624-632. https://doi.org/10.4338/ACI-2016-04-SOA-0064

U.S. Department of Health and Human Services. (2023). Health industry cybersecurity practices: Managing threats and protecting patients (2023 ed.). 405(d) Program. https://405d.hhs.gov/cornerstone/hicp

What the HINF 510 Week 5 instructions ask

HINF 510 Week 5 usually asks students to plan for IT security, disaster recovery and business continuity for a clinical information system. Students may be asked to identify threats and vulnerabilities, recommend security controls, define recovery objectives, describe backup and recovery strategies, plan how clinical operations continue during downtime and explain relevant regulations. Some versions ask for a formal recovery plan table. Strong papers base priorities on a risk assessment, use recognized frameworks or federal guidance, distinguish disaster recovery of systems from continuity of operations, set specific recovery targets, address people and processes as well as technology and describe how the plan will be tested.

How this HINF 510 Week 5 example is built

The paper opens with a tabletop exercise in which the record becomes unavailable at 9 a.m. on a Monday with 900 patients scheduled. The federal voluntary practices published in 2023 identify phishing, ransomware, loss or theft of equipment, insider data loss and attacks on connected medical devices as the main threats, and the network maps its gaps against ten practices. Recovery time and data loss targets are set for each system, with the vendor's contract obligations reviewed. Clinic downtime procedures follow. Federal emergency preparedness requirements and a sociotechnical approach to ransomware complete the plan, and results from the first drill, which found two continuity workstations three days out of date, close the paper.

HINF 510 Week 5 grading rubric: where the points go

The security and continuity week is generally graded on whether the plan is risk-based, specific and testable. Instructors look for identified threats and vulnerabilities, security controls tied to those threats, recovery objectives for critical systems, backup and restoration strategies, procedures for continuing care during downtime, relevant regulations and a testing plan. Using federal guidance or a recognized framework shows professional practice. Recognizing that a vendor-hosted system shifts but does not remove responsibility earns credit. Headings, clarity and APA citation account for the remaining points. Plans that list security tools without continuity procedures, or promise recovery without targets or testing, usually lose points, as do plans that ignore vendor contracts.

HINF 510 Week 5 help: mistakes to avoid

Students writing HINF 510 Week 5 often blur security, disaster recovery and continuity into one topic, which leaves gaps a grader will spot. Security prevents and detects attacks; disaster recovery restores systems and data; business continuity keeps patient care going while systems are down. Address all three. Start from a risk assessment and a recognized framework. Set recovery time and data loss targets for each critical system. If the system is hosted by a vendor, review the contract's recovery commitments. Write downtime procedures clinics can actually follow, and keep them on paper. Include people and training. Finally, test the plan through exercises and drills, and fix what the tests reveal before a real outage does.

Related HINF 510 sample papers

Other HINF 510 week samples

More MHA sample papers

HINF 510 Week 5 questions, answered

What does HINF/510 Week 5 usually ask for?

Prompts usually ask students to plan IT security, disaster recovery and business continuity for a clinical information system, including threats, controls, recovery targets, downtime procedures and testing.

Where can I find a free HINF 510 Week 5 sample paper?

The Monday morning outage paper is posted above in full at no cost, and margin notes explain each part of the plan. A plan for your own organization is free for the first paper.

What are the main cybersecurity threats to health care organizations?

Federal voluntary practices published in 2023 name five: social engineering such as phishing, ransomware, loss or theft of equipment or data, insider accidental or malicious data loss and attacks on connected medical devices.

What is the difference between disaster recovery and business continuity?

Disaster recovery restores systems and data after a failure, while business continuity keeps essential operations, such as patient care, running during the outage.

What are RTO and RPO?

The recovery time objective is how quickly a system must be restored, and the recovery point objective is how much recent data the organization can afford to lose, measured in time.

Write yours, or have the desk draft it

This paper is an original model document written by our desk, not a submitted student paper and not an official University of Phoenix document. Read it for the moves, then write your own to the instructions in your classroom. If you want one built to your exact prompt and rubric, the first custom sample is free and arrives in 24 to 48 hours.