| Course | HINF 510 The Systems Life Cycle (HINF/510) |
|---|---|
| Week | 5 |
| Paper type | Security and continuity paper |
| Length | about 1,227 words, 4 double-spaced pages plus title page and references |
| Format | APA 7 student paper |
| School | University of Phoenix |
| Program | MHA |
| Updated | September 2026 |
Free sample paper for HINF 510 Week 5
If the Record Goes Dark at 9 a.m. on a Monday: Security, Disaster Recovery and Continuity Planning for a 14-Clinic Health Center Network's New System
[Student Name]
University of Phoenix
HINF/510: The Systems Life Cycle
Week 5 Assignment
[Instructor Name]
[Date]
The health center network, its systems, targets and exercises are composites written for a model paper; federal guidance, rules and research come from the sources listed.
Six weeks before the first clinics were due to switch systems, the project team ran a tabletop exercise built on one scenario: at 9 a.m. on a Monday, with about 900 patients scheduled across the network, the new electronic record becomes unavailable and the vendor reports a ransomware incident at its hosting center. The exercise revealed that no one was sure who would decide to reschedule patients, how clinicians would see medication lists or how prescriptions would be sent. This paper sets out the security, disaster recovery and continuity plan built from that exercise.
Three Different Problems
Security, disaster recovery and business continuity are related but distinct. Security aims to prevent, detect and respond to attacks and misuse. Disaster recovery restores systems and data after a failure, whatever the cause. Business continuity keeps essential work, especially patient care, going while systems are down. A plan that covers only one leaves the others to improvisation.
Starting From Risk
The network's security officer led a risk assessment covering the new record, the network, devices, the telehealth platform and remaining departmental systems. To set priorities, the team used the federal voluntary cybersecurity practices for health care, whose 2023 edition names five major threats, social engineering such as phishing, ransomware, loss or theft of equipment or data, insider accidental or malicious data loss and attacks on connected medical devices, and describes ten practices scaled to small, medium and large organizations (U.S. Department of Health and Human Services, 2023). The network, with about 390 users, fits the medium category.
Security Gaps and Controls
Mapping the network against the ten practices found gaps in five. Email protection lacked advanced filtering and simulated phishing training. Access management had no multifactor authentication for remote access to some systems. Asset management had no complete inventory of devices, including the outreach van's laptops and a dental imaging system. Vulnerability management applied patches irregularly. Incident response had a written plan no one had practiced. The plan adds advanced email filtering and quarterly phishing simulations, multifactor authentication for all remote and administrative access, a device inventory with encryption for every laptop, a monthly patching cycle with tracking and an incident response retainer with an outside firm.
Recovery Targets
For each critical system, the team set a recovery time objective, how quickly it must be restored, and a recovery point objective, how much recent data could be lost. The record: four hours and 15 minutes. E-prescribing: four hours. The telephone system: two hours, because patients must be able to reach clinics. The patient portal: 24 hours. Internet connections at each clinic: four hours, supported by a second connection from a different carrier at the six largest clinics.
What Hosting Changes
The new record is hosted by its vendor, which shifts responsibility for servers, backups and data center recovery to the vendor but does not remove the network's responsibility for its patients. The team reviewed the contract: the vendor commits to 99.9% availability, backups replicated to a second data center and restoration targets consistent with the network's, with notification of security incidents within 24 hours. The network added a contract requirement for an annual recovery test report.
Business Continuity Access
Each clinic receives a protected continuity workstation, updated every 15 minutes with the day's schedules and a read-only summary for each scheduled patient: problems, medications, allergies, recent results and care plans. The workstation runs on a battery backup and does not depend on the network connection once updated, so clinicians can see essential information even if the record is unreachable.
Clinic Downtime Procedures
Each clinic keeps a downtime binder with paper forms matching the record's templates, instructions for prescribing by phone or printed prescription, fax procedures for laboratory orders and results, a script for front-desk staff and a decision guide. For outages expected to last under two hours, clinics continue seeing patients using continuity workstations and paper. For longer outages, the medical director and operations director decide which visits to keep, prioritizing urgent, prenatal and medication-dependent patients. After recovery, paper documentation is entered into the record within 72 hours, with scanning of paper notes.
Ransomware Across the Whole System
Ransomware is not only a technical problem. Singh and Sittig's sociotechnical approach to ransomware looks across every dimension of a health information system, including hardware and software, clinical content, the user interface, people, workflow and communication, organizational policies, external rules and measurement, and recommends actions in each (Singh & Sittig, 2016). A backup that has never been restored is a hope, not a recovery plan. Following that approach, the plan includes staff training, downtime workflows, leadership decision rules, communication with patients and regular restoration tests, not only technical controls.
Regulatory Requirements
Federal emergency preparedness requirements apply to health centers participating in Medicare and Medicaid and expect each center to assess risks from all kinds of hazards, write an emergency plan with supporting procedures, keep a way to reach staff, patients and authorities during a crisis and train and drill its people (Centers for Medicare & Medicaid Services, 2016). The network's plan includes cyber events as a hazard alongside storms and power loss. The HIPAA security rule adds its own contingency duties: backing up data, planning recovery and keeping critical protections running while operating in emergency mode.
Medical Devices and the Outreach Van
Connected devices are often forgotten. The network's dental imaging sensors, spirometers, a retinal camera for diabetic eye screening and vaccine refrigerator monitors all connect to the network, some running outdated operating systems the manufacturers no longer update. The plan places these devices on a separate network segment, lists them in the asset inventory and requires security review before any new device connects. The mobile outreach van, which serves homeless shelters and farmworker camps, poses a different risk: it works where connections are unreliable. Its tablets encrypt data, synchronize when a connection returns and can be wiped remotely if lost.
People and Training
Most attacks begin with a person. All staff complete annual security training, with a short module on recognizing phishing, and new staff complete it before receiving access. Managers learn how to report a suspected incident immediately, since early reporting limits damage. The first phishing simulation, sent before training, had a click rate of 17%; the goal is below 5% within a year.
Communication
The communication plan assigns who informs staff, patients, partners and regulators, using text messaging and phone trees that do not depend on the network's email. A prepared patient notice explains delays without speculating about causes.
Testing the Plan
The plan is tested through quarterly downtime drills at each clinic, an annual network-wide tabletop exercise including the vendor and a restoration test of the network's own backups twice a year. The first drill after the tabletop found that two clinics' continuity workstations had not updated for three days because of a configuration error, which was fixed.
Conclusion
The Monday morning scenario exposed gaps in decisions, not only in technology. The plan now addresses security through federal practices, sets recovery targets for each critical system, clarifies the vendor's obligations, gives clinics continuity workstations and downtime procedures and meets emergency preparedness requirements. Regular drills will keep testing it, so that if the record goes dark on an ordinary Monday, patients are still seen.
References
Centers for Medicare & Medicaid Services. (2016). Medicare and Medicaid programs; Emergency preparedness requirements for Medicare and Medicaid participating providers and suppliers. Federal Register, 81, 63860. https://www.federalregister.gov/d/2016-21404
Singh, H., & Sittig, D. F. (2016). A socio-technical approach to preventing, mitigating, and recovering from ransomware attacks. Applied Clinical Informatics, 7(2), 624-632. https://doi.org/10.4338/ACI-2016-04-SOA-0064
U.S. Department of Health and Human Services. (2023). Health industry cybersecurity practices: Managing threats and protecting patients (2023 ed.). 405(d) Program. https://405d.hhs.gov/cornerstone/hicp
What the HINF 510 Week 5 instructions ask
HINF 510 Week 5 usually asks students to plan for IT security, disaster recovery and business continuity for a clinical information system. Students may be asked to identify threats and vulnerabilities, recommend security controls, define recovery objectives, describe backup and recovery strategies, plan how clinical operations continue during downtime and explain relevant regulations. Some versions ask for a formal recovery plan table. Strong papers base priorities on a risk assessment, use recognized frameworks or federal guidance, distinguish disaster recovery of systems from continuity of operations, set specific recovery targets, address people and processes as well as technology and describe how the plan will be tested.
How this HINF 510 Week 5 example is built
The paper opens with a tabletop exercise in which the record becomes unavailable at 9 a.m. on a Monday with 900 patients scheduled. The federal voluntary practices published in 2023 identify phishing, ransomware, loss or theft of equipment, insider data loss and attacks on connected medical devices as the main threats, and the network maps its gaps against ten practices. Recovery time and data loss targets are set for each system, with the vendor's contract obligations reviewed. Clinic downtime procedures follow. Federal emergency preparedness requirements and a sociotechnical approach to ransomware complete the plan, and results from the first drill, which found two continuity workstations three days out of date, close the paper.
HINF 510 Week 5 grading rubric: where the points go
The security and continuity week is generally graded on whether the plan is risk-based, specific and testable. Instructors look for identified threats and vulnerabilities, security controls tied to those threats, recovery objectives for critical systems, backup and restoration strategies, procedures for continuing care during downtime, relevant regulations and a testing plan. Using federal guidance or a recognized framework shows professional practice. Recognizing that a vendor-hosted system shifts but does not remove responsibility earns credit. Headings, clarity and APA citation account for the remaining points. Plans that list security tools without continuity procedures, or promise recovery without targets or testing, usually lose points, as do plans that ignore vendor contracts.
HINF 510 Week 5 help: mistakes to avoid
Students writing HINF 510 Week 5 often blur security, disaster recovery and continuity into one topic, which leaves gaps a grader will spot. Security prevents and detects attacks; disaster recovery restores systems and data; business continuity keeps patient care going while systems are down. Address all three. Start from a risk assessment and a recognized framework. Set recovery time and data loss targets for each critical system. If the system is hosted by a vendor, review the contract's recovery commitments. Write downtime procedures clinics can actually follow, and keep them on paper. Include people and training. Finally, test the plan through exercises and drills, and fix what the tests reveal before a real outage does.
Related HINF 510 sample papers
Other HINF 510 week samples
- HINF 510 Week 1: IT System Implementation
- HINF 510 Week 2: Interoperability Assessment
- HINF 510 Week 3: Key Design Elements
- HINF 510 Week 4: Training, Support and Buy-In
- HINF 510 Week 6: New and Advanced Technologies
More MHA sample papers
- GHA 548 Week 5: Community Resources for Older Adults
- HCS 504 Week 1: Career Alignment and SMART Goals
- HCS 529 Week 5: Operating Room Types and Safety
- HINF 500 Week 5: Data for an Administrative Decision
HINF 510 Week 5 questions, answered
What does HINF/510 Week 5 usually ask for?
Prompts usually ask students to plan IT security, disaster recovery and business continuity for a clinical information system, including threats, controls, recovery targets, downtime procedures and testing.
Where can I find a free HINF 510 Week 5 sample paper?
The Monday morning outage paper is posted above in full at no cost, and margin notes explain each part of the plan. A plan for your own organization is free for the first paper.
What are the main cybersecurity threats to health care organizations?
Federal voluntary practices published in 2023 name five: social engineering such as phishing, ransomware, loss or theft of equipment or data, insider accidental or malicious data loss and attacks on connected medical devices.
What is the difference between disaster recovery and business continuity?
Disaster recovery restores systems and data after a failure, while business continuity keeps essential operations, such as patient care, running during the outage.
What are RTO and RPO?
The recovery time objective is how quickly a system must be restored, and the recovery point objective is how much recent data the organization can afford to lose, measured in time.
Write yours, or have the desk draft it
This paper is an original model document written by our desk, not a submitted student paper and not an official University of Phoenix document. Read it for the moves, then write your own to the instructions in your classroom. If you want one built to your exact prompt and rubric, the first custom sample is free and arrives in 24 to 48 hours.
Request this one custom, free · All HINF 510 week samples · All courses