MHA 516 Week 4 Risk-Based Policy and Governance Example

Reviewed by Lenora Whitcombe, MSN, RN · University of Phoenix · Updated

This MHA 516 Week 4 example explains risk-based policy and governance models in health care, following a composite Washington public hospital district as its board rebuilds risk oversight after ransomware shuts down a neighboring hospital. In University of Phoenix MHA 516, the fourth week addresses why risk-based policy and governance models matter in the health sector, and MHA/516 health administration students typically describe enterprise risk management, show how boards set risk appetite and oversee top risks and draft policy scaled to risk. The APA 7 paper draws on a count of 374 attacks on US care providers over six years, nearly half of which disrupted care. It adds research showing that an attack on one health system raised stroke code activations and walkouts at an unaffected neighboring emergency department. A 2025 federal proposal would require restoring critical systems within 72 hours. A tiered cyber policy closes the paper.

CourseMHA 516 Operating in Structure: Health Sector Policy and Governance (MHA/516)
Week4
Paper typeRisk-based governance paper
Lengthabout 1,186 words, 4 double-spaced pages plus title page and references
FormatAPA 7 student paper
SchoolUniversity of Phoenix
ProgramMHA
UpdatedSeptember 2026

Free sample paper for MHA 516 Week 4

1

When the Screens Go Dark: A Risk-Based Governance Model and Cyber Policy for a Public Hospital District After Its Neighbor Was Hit by Ransomware

[Student Name]

University of Phoenix

MHA/516: Operating in Structure: Health Sector Policy and Governance

Week 4 Assignment

[Instructor Name]

[Date]

The public hospital district, the neighboring attack, the risk register and policies are composites written for a model paper; research findings and the proposed federal rule come from the sources cited.

What this part is doingThe title describes the moment every clinician fears, because a risk that has been imagined vividly is easier for a board to govern.
2

On a Monday morning in March, the emergency departments of a composite Washington public hospital district began filling with ambulances. A neighboring health system forty miles away had been hit by ransomware over the weekend; its electronic records, imaging and phones were down, and it had diverted ambulances. By Wednesday the district's larger emergency department was holding patients in hallways. At the board's next meeting, a commissioner asked the question on everyone's mind: could this happen to us, and would we know if we were ready? This paper describes the risk-based governance model and cyber policy the board adopted.

Why a Risk-Based Model

Health care organizations face more risks than they can address equally. A risk-based model focuses attention and resources on the risks most likely to cause the greatest harm, sets how much risk the organization will accept and scales policy requirements to the level of risk, rather than applying the same rules everywhere.

The Risk Process

The district adopted a five-step process. Identify risks across clinical, financial, operational, technology, workforce, legal and strategic domains. Rate each on likelihood and impact using evidence. Compare the rating with the board's risk appetite. Assign an owner and controls to each risk above appetite. Monitor and report regularly.

What this part is doingNaming the steps lets the reader see that the cyber policy is the output of a process, not a reaction to one bad week.
3

Setting Risk Appetite

The board adopted a risk appetite statement. It has very low appetite for risks to patient safety, privacy and the continuity of critical care, moderate appetite for financial risks tied to its mission, such as serving uninsured patients, and higher appetite for innovation risks in pilots with clear limits. Appetite statements tell management where the board expects the strongest controls.

Rating Cyber Risk: How Often

Evidence shows ransomware is common and growing. A study of attacks on US health care delivery organizations counted 374 attacks over six years, from 2016 through 2021, that together put nearly 42 million patients' records at risk; annual attacks more than doubled from 43 to 91, increasingly struck large organizations with multiple facilities and were less likely to be restored from backups over time (Neprash et al., 2022).

Rating Cyber Risk: How Much Harm

The same study found that almost half of attacks, 44.4%, disrupted care delivery, most often through system downtime, and some through canceled appointments and ambulance diversion (Neprash et al., 2022). Harm spreads beyond the attacked organization. When ransomware struck one health system, an unaffected neighboring emergency department saw higher daily census, more ambulance arrivals, longer waits, more patients leaving without being seen and an increase in stroke code activations from 59 to 102 compared with before the attack (Dameff et al., 2023). The district did not need to be attacked to be harmed; its neighbor's outage had already filled its hallways.

The Rating

Cyber risk was rated high likelihood and severe impact, well above the board's appetite for risks to continuity of care. It joined the top three risks alongside workforce shortages and Medicaid coverage losses.

The Federal Direction

In January 2025, HHS proposed revisions to the HIPAA Security Rule to address significant increases in breaches and cyberattacks. The proposal would require a written technology asset inventory and network map and written procedures to restore critical systems and data within 72 hours of a loss, among other controls (U.S. Department of Health and Human Services, 2025). The district's policy does not depend on whether or when the rule is finalized, but it uses the proposal as a benchmark.

What this part is doingUsing a proposed rule as a benchmark, while not relying on its adoption, is itself a risk-based choice.
4

The Top Ten Register

The register lists ten risks, each with a rating, owner, key controls and indicators: cyber and technology failure; workforce shortages; Medicaid coverage losses; patient safety events; physician recruitment in rural clinics; capital needs of aging buildings; compliance and billing; extreme heat and wildfire smoke; supply chain disruption; and reputation.

Board and Management Roles

The board sets appetite, approves the register annually and reviews the top risks quarterly. Management owns each risk, designs and runs controls and reports honestly, including when controls fail. The finance and audit committee oversees the process; the full board discusses the top three risks at every quarterly meeting.

A Tiered Cyber Policy

The cyber policy scales requirements to criticality. Tier one systems, including the electronic record, laboratory, imaging, pharmacy and phones, require multifactor authentication, immutable offline backups tested monthly, network segmentation, a restoration target of 72 hours and paper downtime procedures practiced twice a year. Tier two systems, such as scheduling and billing, require backups and restoration within a week. Tier three systems, such as internal reporting tools, follow standard controls.

Vendors and Connected Devices

Many attacks enter through vendors. Contracts with vendors that connect to tier one systems now require security assessments, prompt breach notification and restricted access. Connected medical devices are inventoried and isolated on separate networks.

Planning for a Neighbor's Outage

The policy includes surge plans for when a neighboring system goes down: extra emergency staffing, transfer agreements and early communication with emergency medical services.

Downtime Is a Clinical Skill

Paper downtime procedures fail if no one has practiced them. Newer nurses and physicians have never worked without an electronic record. Each unit now keeps a downtime box with paper order sets, medication records and registration forms, and runs a four-hour downtime drill twice a year. Pharmacy keeps printed medication profiles updated each shift so patients can still receive their medicines if systems fail.

Communicating During an Attack

In the neighboring system's outage, staff learned about the attack from news reports and patients could not reach clinics by phone. The district's plan sets out who speaks for the district, how staff receive updates if email is down, how patients learn which services are open and when regulators, law enforcement and the state hospital association are notified.

Insurance and Finances

Cyber insurance has become more expensive and more demanding. Insurers now ask for evidence of multifactor authentication, backups and incident response plans before offering coverage. The policy's controls reduced the district's premium increase and satisfied its insurer's requirements, an unexpected financial return on the board's decision.

Exercises

The district holds an annual exercise simulating a ransomware attack, involving clinicians, information technology, communications and at least two commissioners, so the board sees how the plan works in practice.

Reporting to the Board

Each quarter, the chief information security officer reports to the finance and audit committee on phishing test results, backup restoration tests, patching of critical vulnerabilities and progress on the asset inventory, using a one-page dashboard.

Costs

The policy adds about $1.3 million a year in staff, tools and backup systems. The board accepted the cost after comparing it with the harm documented in the research and the weeks of disrupted care neighbors had experienced.

Conclusion

A neighbor's ransomware attack showed the district that it could be harmed without being hacked. A risk-based model, with a process, a risk appetite, a register with owners and quarterly board review, placed cyber risk among the top three. Evidence on attacks and their spillover shaped a tiered policy that puts the strongest controls where failure would hurt patients most.

5

References

Dameff, C., Tully, J., Chan, T. C., Castillo, E. M., Savage, S., Maysent, P., Hemmen, T. M., Clay, B. J., & Longhurst, C. A. (2023). Ransomware attack associated with disruptions at adjacent emergency departments in the US. JAMA Network Open, 6(5), e2312270. https://doi.org/10.1001/jamanetworkopen.2023.12270

Neprash, H. T., McGlave, C. C., Cross, D. A., Virnig, B. A., Puskarich, M. A., Huling, J. D., Rozenshtein, A. Z., & Nikpay, S. S. (2022). Trends in ransomware attacks on US hospitals, clinics, and other health care delivery organizations, 2016-2021. JAMA Health Forum, 3(12), e224873. https://doi.org/10.1001/jamahealthforum.2022.4873

U.S. Department of Health and Human Services. (2025). HIPAA Security Rule to strengthen the cybersecurity of electronic protected health information. Federal Register, 90, 898. https://www.federalregister.gov/d/2024-30983

What the MHA 516 Week 4 instructions ask

MHA 516 Week 4 usually asks students to explain risk-based approaches to policy and governance in health care organizations. Typical instructions call for defining enterprise risk management, describing how boards identify, rate and oversee major risks, explaining how policies can be scaled to the level of risk and applying these ideas to a specific risk or organization. Some versions ask students to draft a policy. Details differ between versions, so follow your prompt. Strong papers use a recognized risk process, rate risks with evidence rather than impressions, distinguish the board's oversight role from management's control role, scale policy requirements to criticality and show how risk information reaches the board regularly.

How this MHA 516 Week 4 example is built

The paper opens on a Monday when the district's emergency departments fill with ambulances diverted from a neighboring system hit by ransomware. The board asks whether the district could be next. Enterprise risk management is explained, from identifying risks to setting risk appetite and assigning owners. Research on ransomware attacks and on spillover to neighboring emergency departments rates cyber risk. A federal proposal to strengthen security rules is summarized. A risk register with the district's top ten risks follows, then a tiered cyber policy scaled by system criticality. Board reporting, vendor controls, annual exercises and measures of readiness close the paper.

MHA 516 Week 4 grading rubric: where the points go

The risk governance week is generally graded on clear explanation of risk-based governance and sound application. Graders look for a defined risk management process, the board's role in setting risk appetite and overseeing top risks, evidence used to rate risks, policies scaled to risk rather than one-size-fits-all rules, clear ownership and regular reporting to the board. Research and current federal proposals strengthen the analysis. Applying the model to a specific risk earns credit. Organization and APA style count for the last few points. Papers that describe risk management in general terms, or treat cyber risk as an information technology matter only, usually lose points, as do policies that apply identical controls to every system.

MHA 516 Week 4 help: mistakes to avoid

Too many MHA 516 Week 4 papers treat risk management as nothing more than a list of bad things that could happen. Use a process: identify risks, rate likelihood and impact with evidence, decide how much risk the organization will accept, assign owners and controls and monitor. Keep roles clear: the board sets appetite and oversees; management designs and runs controls. Scale policy to risk, requiring the strongest controls for the most critical systems. Use research and real events to rate risks rather than guessing. Finally, show how risk information reaches the board, how often and in what form, and how the board tests whether controls actually work, for example through exercises and independent audits.

Related MHA 516 sample papers

Other MHA 516 week samples

More MHA sample papers

MHA 516 Week 4 questions, answered

What does MHA/516 Week 4 usually ask for?

Prompts usually ask students to explain risk-based policy and governance, including enterprise risk management, board oversight of top risks and policies scaled to risk.

Where can I find a free MHA 516 Week 4 sample paper?

The ransomware governance paper above is open to every reader at no cost, with notes on each rating. Name the risk your course asks about, and your first paper is written free.

How common are ransomware attacks on hospitals?

Researchers counted 374 attacks on US care providers between 2016 and 2021, affecting records of nearly 42 million patients, with annual attacks more than doubling from 43 to 91.

Do ransomware attacks affect nearby hospitals?

Yes; a study found an unaffected emergency department next to an attacked health system saw higher census, more ambulance arrivals, longer waits, more patients leaving without being seen and more stroke code activations.

What is risk appetite in health care governance?

The amount and type of risk an organization's board is willing to accept in pursuit of its goals, used to decide which risks need stronger controls.

Write yours, or have the desk draft it

This paper is an original model document written by our desk, not a submitted student paper and not an official University of Phoenix document. Read it for the moves, then write your own to the instructions in your classroom. If you want one built to your exact prompt and rubric, the first custom sample is free and arrives in 24 to 48 hours.