Running Head: HEALTH CARE a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a 1
2-1 Final Project Milestone One: Summary of Problem and Key Stakeholders
HIM 422
SNHU
May 15,2022
HEALTH CARE a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a 2
I. Summary of Problem
A. Explanation of the nature of the data breach
In the healthcare sector, breaches of data are very commonly observed. These breaches
are occurring due to several types of incidents in the healthcare settings that include lost laptops
or other devices where the data of the patient is recorded, an insider of the healthcare
organization who either accidentally or purposefully discloses the data of the patients to others,
credential-stealing malware and others (Data breaches: In the healthcare sector. CIS, 2021). In
the present case of ABC hospital, the presence of data breach has been alerted to the healthcare
organization where I am playing the role of a health information management (HIM) director. I
have found that the data breach is identified as protected health information (PHI). In this
healthcare organization, there are 7 medical coders who work remotely across different regions.
Among them, one of the coders has revealed a neighbor’s health record data where it has been
mentioned that the patient had an inpatient stay for complications from HIV. When the patient
found that the health data had been shared with others, the patient filed a complaint to the legal
department of the hospital. After that, the coder was terminated from the job.
B. The breach investigation
The breach investigation is considered an important part of a data breach response, which
aims to clarify the breach circumstances, assess the consequences and damages that have
occurred due to the data breaches, and, last, it will provide a further plan of action based on the
investigation results (Bassett et al., 2021). While doing the breach investigation, I have gone
through a risk assessment to identify the major issue. As a health information management
(HIM) director in the healthcare organization, I took the responsibility to do the risk assessment
HEALTH CARE a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a 3
by following the five steps that include identification of the hazards, identifying who might be
harmed from the data breach, and how evaluated the risks and took a decision on precautions,
recorded important findings and reviewed the assessment and updated the necessary things. This
risk assessment has identified that the data breaches happen due to the negligence of the coder.
Therefore, a communication plan has been created to inform the stakeholders that have been
mentioned below in the table-1.
Table-1: communication plan for data breaches
Targeted audiences
Goals
tools
Timeframe
Program stakeholders
Promote the progress
of the program
Providing the stories
of the successful
persons in the
healthcare
organization
Yearly basis
Program
implementation team
Informing them about
the required
improvement and
required adjustments
during the
implementation of the
plan
Meeting and briefing
the documents on a
monthly basis
Every 3 weeks
HEALTH CARE a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a 4
Thus, it is recommended for the healthcare organization to implement proper network security
and application security as well as the implementation of encryption. Here, providing proper
training on handling and usage of the PHI is essential to reduce the data breaches by accidental
disclosure or lost devices, or employee errors (Data breaches: In the healthcare sector. CIS,
2021).
C. The short-term and long-term consequences of data breaches
In the long term of the period, the healthcare organization has more chances to get the
negative impact of data breaches. Research says that after a data breach, the healthcare
organization can lose its potential stakeholders and users as well as lose its healthcare business.
Also, unexpected expenses and legal penalties come across the healthcare organization that
affects its overall growth. Moreover, the healthcare organization can be badly impacted because
of a data breach as it affects the years of reputation that they have achieved (Sharma et al., 2020).
In addition, the healthcare organization can also have some short-term consequences that
can include operation downtime and loss of sensitive data.
II. Key Stakeholders
A. Identification of the key internal workforce and external stakeholders
The federal law Health Insurance Portability and Accountability Act of 1996 (HIPAA) has
been set up with an aim to protect the sensitive health information of the patient from being
disclosed to others without the knowledge or consent of the patient. This federal law has set up
some national standards for this (Data breaches: In the healthcare sector. CIS, 2021). By
following this federal law, I have realized that I need to inform or notify the internal workforce
HEALTH CARE a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a 5
and the external stakeholders about the data breach incident in the healthcare organization. As a
health information management (HIM) director of the healthcare organization, I have identified
some of the key internal workforces that include board members and stags of the organization.
Moreover, I have identified some of the external stakeholders, such as vendors and patients, who
need to be notified about the issue.
B. Identification of the key federal stakeholders
The incident of data breach needs to be informed to the federal stakeholders, who can be the
government officials. This could help the healthcare organization in many ways. Here, the
Medicare Conditions for Coverage have been set up to protect the safety and health of the
beneficiaries (Conditions for coverage (cfcs) & conditions of participation (cops). CMS, 2021).
Moreover, it has aimed to achieve support from the Joint Commission to improve the quality of
health care in several ways. The state licensing regulation could help the healthcare organization
to boost its efficiency in the forecast period. However, these regulations and standards have been
negatively impacted by the data breaches.
C. Following the policy to avoid future breaches
Here, the key stakeholders who need to follow these policies are the organizational staff,
board members, and vendors to avoid future breaches in the healthcare organization. This is
because they are the pillar of the healthcare organization, and they must follow the essential
policies to maintain a good work environment with ethics.
HEALTH CARE a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a a 6
References
Bassett, G., Hylender, C. D., Langlois, P., Pinto, A., & Widup, S. (2021). Data breach
investigations report. Verizon DBIR Team, Tech. Rep.
Conditions for coverage (cfcs) & conditions of participation (cops). CMS. (2021). Retrieved
May 12, 2022, from https://www.cms.gov/Regulations-and-
Guidance/Legislation/CFCsAndCoPs
Data breaches: In the healthcare sector. CIS. (2021, July 14). Retrieved May 12, 2022, from
https://www.cisecurity.org/insights/blog/data-breaches-in-the-healthcare-sector
Sharma, N., Oriaku, E. A., & Oriaku, N. (2020). Cost and effects of data breaches, precautions,
and disclosure laws. International Journal of Emerging Trends in Social Sciences, 8(1), 33-
41.