1 / 55100%
Assignment 1: Designing Information Security Policies for a Healthcare Provider
Imagine you are an Information Security consultant for a large healthcare provider that
operates multiple medical facilities. The healthcare provider must comply with Health
Insurance Portability and Accountability Act (HIPAA) regulations. Write a three to five-
page paper in which you:
1. Develop Information Security Policies: Outline a set of information security policies
tailored to the healthcare provider's environment. Address key areas such as data
privacy, patient confidentiality, and secure handling of electronic health records
(EHR).
2. Incident Response Plan: Design an incident response plan specific to potential
security breaches involving patient data. Include steps for detection, containment,
eradication, recovery, and lessons learned. Consider the unique challenges of
healthcare data breaches.
3. Employee Training and Awareness: Propose a comprehensive training program to
educate healthcare staff about the importance of information security, HIPAA
regulations, and best practices for safeguarding patient information. Include
strategies for continuous awareness.
4. Securing Medical Devices: Analyze the security risks associated with medical
devices connected to the healthcare provider's network. Recommend technical
safeguards and policies to ensure the integrity and confidentiality of data
transmitted and received by these devices.
Your assignment must follow the provided formatting requirements, be typed, double-
spaced, using Times New Roman font (size 12), with one-inch margins on all sides.
Citations and references must follow APA or school-specific format.
Include a cover page containing the title of the assignment, the student’s name, the
professor’s name, the course title, and the date. The cover page and the reference page are
not included in the required assignment page length.
The specific course learning outcomes associated with this assignment are:
Describe the role of information systems security (ISS) compliance and its relationship to
U.S. compliance laws.
Use technology and information resources to research issues in security strategy and
policy formation.
Write clearly and concisely about topics related to information technology audit and
control using proper writing mechanics and technical style conventions.
Click!here!to view the grading rubric.
Grading for this assignment will be based on answer quality, logic / organization of the paper,
and language and writing skills, using the following rubric.
Points: 50 Assignment 1: Designing Information Security Policies for a Healthcare Provider
Criteria Unacceptable
Below 60% F
Meets
Minimum
Expectation
s
60-69% D
Fair
70-79% C
Proficient
80-89% B
Exemplar
90-100%
1. Analyze
proper physical
access control
safeguards and
provide sound
recommendatio
ns to be
employed in the
registrar's
office.
Weight: 21%
Did not submit or
incompletely analyzed
proper physical access
control safeguards and
did not submit or
incompletely provided
sound recommendations
to be employed in the
registrar's office.
Insufficientl
y analyzed
proper
physical
access
control
safeguards
and
insufficiently
provided
sound
recommenda
tions to be
employed in
the
registrar's
office.
Partially!analyzed
proper physical
access control
safeguards and
partially!provided
sound
recommendations to
be employed in the
registrar's office.
Satisfactorily
analyzed proper
physical access
control safeguards
and satisfactorily
provided sound
recommendations
to be employed in
the registrar's
office.
Thoroughly
analyzed prop
physical acce
control safeg
and thorough
provided soun
recommendat
to be employ
the registrar's
office.
2. Recommend
the proper audit
Students also viewed