| Course | MHA 516 Operating in Structure: Health Sector Policy and Governance (MHA/516) |
|---|---|
| Week | 4 |
| Paper type | Risk-based governance paper |
| Length | about 1,186 words, 4 double-spaced pages plus title page and references |
| Format | APA 7 student paper |
| School | University of Phoenix |
| Program | MHA |
| Updated | September 2026 |
Free sample paper for MHA 516 Week 4
When the Screens Go Dark: A Risk-Based Governance Model and Cyber Policy for a Public Hospital District After Its Neighbor Was Hit by Ransomware
[Student Name]
University of Phoenix
MHA/516: Operating in Structure: Health Sector Policy and Governance
Week 4 Assignment
[Instructor Name]
[Date]
The public hospital district, the neighboring attack, the risk register and policies are composites written for a model paper; research findings and the proposed federal rule come from the sources cited.
On a Monday morning in March, the emergency departments of a composite Washington public hospital district began filling with ambulances. A neighboring health system forty miles away had been hit by ransomware over the weekend; its electronic records, imaging and phones were down, and it had diverted ambulances. By Wednesday the district's larger emergency department was holding patients in hallways. At the board's next meeting, a commissioner asked the question on everyone's mind: could this happen to us, and would we know if we were ready? This paper describes the risk-based governance model and cyber policy the board adopted.
Why a Risk-Based Model
Health care organizations face more risks than they can address equally. A risk-based model focuses attention and resources on the risks most likely to cause the greatest harm, sets how much risk the organization will accept and scales policy requirements to the level of risk, rather than applying the same rules everywhere.
The Risk Process
The district adopted a five-step process. Identify risks across clinical, financial, operational, technology, workforce, legal and strategic domains. Rate each on likelihood and impact using evidence. Compare the rating with the board's risk appetite. Assign an owner and controls to each risk above appetite. Monitor and report regularly.
Setting Risk Appetite
The board adopted a risk appetite statement. It has very low appetite for risks to patient safety, privacy and the continuity of critical care, moderate appetite for financial risks tied to its mission, such as serving uninsured patients, and higher appetite for innovation risks in pilots with clear limits. Appetite statements tell management where the board expects the strongest controls.
Rating Cyber Risk: How Often
Evidence shows ransomware is common and growing. A study of attacks on US health care delivery organizations counted 374 attacks over six years, from 2016 through 2021, that together put nearly 42 million patients' records at risk; annual attacks more than doubled from 43 to 91, increasingly struck large organizations with multiple facilities and were less likely to be restored from backups over time (Neprash et al., 2022).
Rating Cyber Risk: How Much Harm
The same study found that almost half of attacks, 44.4%, disrupted care delivery, most often through system downtime, and some through canceled appointments and ambulance diversion (Neprash et al., 2022). Harm spreads beyond the attacked organization. When ransomware struck one health system, an unaffected neighboring emergency department saw higher daily census, more ambulance arrivals, longer waits, more patients leaving without being seen and an increase in stroke code activations from 59 to 102 compared with before the attack (Dameff et al., 2023). The district did not need to be attacked to be harmed; its neighbor's outage had already filled its hallways.
The Rating
Cyber risk was rated high likelihood and severe impact, well above the board's appetite for risks to continuity of care. It joined the top three risks alongside workforce shortages and Medicaid coverage losses.
The Federal Direction
In January 2025, HHS proposed revisions to the HIPAA Security Rule to address significant increases in breaches and cyberattacks. The proposal would require a written technology asset inventory and network map and written procedures to restore critical systems and data within 72 hours of a loss, among other controls (U.S. Department of Health and Human Services, 2025). The district's policy does not depend on whether or when the rule is finalized, but it uses the proposal as a benchmark.
The Top Ten Register
The register lists ten risks, each with a rating, owner, key controls and indicators: cyber and technology failure; workforce shortages; Medicaid coverage losses; patient safety events; physician recruitment in rural clinics; capital needs of aging buildings; compliance and billing; extreme heat and wildfire smoke; supply chain disruption; and reputation.
Board and Management Roles
The board sets appetite, approves the register annually and reviews the top risks quarterly. Management owns each risk, designs and runs controls and reports honestly, including when controls fail. The finance and audit committee oversees the process; the full board discusses the top three risks at every quarterly meeting.
A Tiered Cyber Policy
The cyber policy scales requirements to criticality. Tier one systems, including the electronic record, laboratory, imaging, pharmacy and phones, require multifactor authentication, immutable offline backups tested monthly, network segmentation, a restoration target of 72 hours and paper downtime procedures practiced twice a year. Tier two systems, such as scheduling and billing, require backups and restoration within a week. Tier three systems, such as internal reporting tools, follow standard controls.
Vendors and Connected Devices
Many attacks enter through vendors. Contracts with vendors that connect to tier one systems now require security assessments, prompt breach notification and restricted access. Connected medical devices are inventoried and isolated on separate networks.
Planning for a Neighbor's Outage
The policy includes surge plans for when a neighboring system goes down: extra emergency staffing, transfer agreements and early communication with emergency medical services.
Downtime Is a Clinical Skill
Paper downtime procedures fail if no one has practiced them. Newer nurses and physicians have never worked without an electronic record. Each unit now keeps a downtime box with paper order sets, medication records and registration forms, and runs a four-hour downtime drill twice a year. Pharmacy keeps printed medication profiles updated each shift so patients can still receive their medicines if systems fail.
Communicating During an Attack
In the neighboring system's outage, staff learned about the attack from news reports and patients could not reach clinics by phone. The district's plan sets out who speaks for the district, how staff receive updates if email is down, how patients learn which services are open and when regulators, law enforcement and the state hospital association are notified.
Insurance and Finances
Cyber insurance has become more expensive and more demanding. Insurers now ask for evidence of multifactor authentication, backups and incident response plans before offering coverage. The policy's controls reduced the district's premium increase and satisfied its insurer's requirements, an unexpected financial return on the board's decision.
Exercises
The district holds an annual exercise simulating a ransomware attack, involving clinicians, information technology, communications and at least two commissioners, so the board sees how the plan works in practice.
Reporting to the Board
Each quarter, the chief information security officer reports to the finance and audit committee on phishing test results, backup restoration tests, patching of critical vulnerabilities and progress on the asset inventory, using a one-page dashboard.
Costs
The policy adds about $1.3 million a year in staff, tools and backup systems. The board accepted the cost after comparing it with the harm documented in the research and the weeks of disrupted care neighbors had experienced.
Conclusion
A neighbor's ransomware attack showed the district that it could be harmed without being hacked. A risk-based model, with a process, a risk appetite, a register with owners and quarterly board review, placed cyber risk among the top three. Evidence on attacks and their spillover shaped a tiered policy that puts the strongest controls where failure would hurt patients most.
References
Dameff, C., Tully, J., Chan, T. C., Castillo, E. M., Savage, S., Maysent, P., Hemmen, T. M., Clay, B. J., & Longhurst, C. A. (2023). Ransomware attack associated with disruptions at adjacent emergency departments in the US. JAMA Network Open, 6(5), e2312270. https://doi.org/10.1001/jamanetworkopen.2023.12270
Neprash, H. T., McGlave, C. C., Cross, D. A., Virnig, B. A., Puskarich, M. A., Huling, J. D., Rozenshtein, A. Z., & Nikpay, S. S. (2022). Trends in ransomware attacks on US hospitals, clinics, and other health care delivery organizations, 2016-2021. JAMA Health Forum, 3(12), e224873. https://doi.org/10.1001/jamahealthforum.2022.4873
U.S. Department of Health and Human Services. (2025). HIPAA Security Rule to strengthen the cybersecurity of electronic protected health information. Federal Register, 90, 898. https://www.federalregister.gov/d/2024-30983
What the MHA 516 Week 4 instructions ask
MHA 516 Week 4 usually asks students to explain risk-based approaches to policy and governance in health care organizations. Typical instructions call for defining enterprise risk management, describing how boards identify, rate and oversee major risks, explaining how policies can be scaled to the level of risk and applying these ideas to a specific risk or organization. Some versions ask students to draft a policy. Details differ between versions, so follow your prompt. Strong papers use a recognized risk process, rate risks with evidence rather than impressions, distinguish the board's oversight role from management's control role, scale policy requirements to criticality and show how risk information reaches the board regularly.
How this MHA 516 Week 4 example is built
The paper opens on a Monday when the district's emergency departments fill with ambulances diverted from a neighboring system hit by ransomware. The board asks whether the district could be next. Enterprise risk management is explained, from identifying risks to setting risk appetite and assigning owners. Research on ransomware attacks and on spillover to neighboring emergency departments rates cyber risk. A federal proposal to strengthen security rules is summarized. A risk register with the district's top ten risks follows, then a tiered cyber policy scaled by system criticality. Board reporting, vendor controls, annual exercises and measures of readiness close the paper.
MHA 516 Week 4 grading rubric: where the points go
The risk governance week is generally graded on clear explanation of risk-based governance and sound application. Graders look for a defined risk management process, the board's role in setting risk appetite and overseeing top risks, evidence used to rate risks, policies scaled to risk rather than one-size-fits-all rules, clear ownership and regular reporting to the board. Research and current federal proposals strengthen the analysis. Applying the model to a specific risk earns credit. Organization and APA style count for the last few points. Papers that describe risk management in general terms, or treat cyber risk as an information technology matter only, usually lose points, as do policies that apply identical controls to every system.
MHA 516 Week 4 help: mistakes to avoid
Too many MHA 516 Week 4 papers treat risk management as nothing more than a list of bad things that could happen. Use a process: identify risks, rate likelihood and impact with evidence, decide how much risk the organization will accept, assign owners and controls and monitor. Keep roles clear: the board sets appetite and oversees; management designs and runs controls. Scale policy to risk, requiring the strongest controls for the most critical systems. Use research and real events to rate risks rather than guessing. Finally, show how risk information reaches the board, how often and in what form, and how the board tests whether controls actually work, for example through exercises and independent audits.
Related MHA 516 sample papers
Other MHA 516 week samples
- MHA 516 Week 1: How Policy Shapes Health Systems
- MHA 516 Week 2: Interest Groups and Policy
- MHA 516 Week 3: Effective Governance Systems
- MHA 516 Week 5: Policies for Industry Trends
- MHA 516 Week 6: Policy and Governance Plan
More MHA sample papers
- MHA 506 Week 4: Value Proposition and Differentiation
- MHA 507 Week 4: Cases by City and Age
- MHA 508 Week 4: Ethical Duties of Leaders
- MHA 515 Week 4: Health Care Design Trends
MHA 516 Week 4 questions, answered
What does MHA/516 Week 4 usually ask for?
Prompts usually ask students to explain risk-based policy and governance, including enterprise risk management, board oversight of top risks and policies scaled to risk.
Where can I find a free MHA 516 Week 4 sample paper?
The ransomware governance paper above is open to every reader at no cost, with notes on each rating. Name the risk your course asks about, and your first paper is written free.
How common are ransomware attacks on hospitals?
Researchers counted 374 attacks on US care providers between 2016 and 2021, affecting records of nearly 42 million patients, with annual attacks more than doubling from 43 to 91.
Do ransomware attacks affect nearby hospitals?
Yes; a study found an unaffected emergency department next to an attacked health system saw higher census, more ambulance arrivals, longer waits, more patients leaving without being seen and more stroke code activations.
What is risk appetite in health care governance?
The amount and type of risk an organization's board is willing to accept in pursuit of its goals, used to decide which risks need stronger controls.
Write yours, or have the desk draft it
This paper is an original model document written by our desk, not a submitted student paper and not an official University of Phoenix document. Read it for the moves, then write your own to the instructions in your classroom. If you want one built to your exact prompt and rubric, the first custom sample is free and arrives in 24 to 48 hours.
Request this one custom, free · All MHA 516 week samples · All courses