HCA 120 Module 7 Security and Privacy in Daily Use Example

Reviewed by Douglas Renshaw, MBA Aspen University Updated September 2026

This HCA 120 Module 7 sample paper argues that security and privacy in health care depend on the daily habits of every system user, not only on the IT department. It was written for Healthcare Information Systems, taught in Aspen University's health care administration program. The three safeguard types of the HIPAA Security Rule frame the paper, followed by a composite phishing email that a billing specialist stopped before entering her password. Simulated campaigns at six US institutions, in which one in seven test emails was clicked, and ransomware attacks that exposed data on nearly 42 million patients from 2016 to 2021 show the stakes. A table pairs daily risks with controls, and sections cover shared logins, screens, texting, curious access, vendors, incident response and training.

CourseHCA 120 Healthcare Information Systems
ModuleModule 7
Paper typeSecurity and privacy paper
LengthAbout 1,046 words, 6 pages
FormatAPA 7 student paper
SchoolAspen University
ProgramHealth Care Administration
UpdatedSeptember 2026

Free sample paper for HCA 120 Module 7

1

Everyday Defense: Security and Privacy in the Daily Use of Health Care Systems

Student Name

Health Care Administration Program, Aspen University

HCA 120: Healthcare Information Systems

Instructor Name

Month Day, Year

What this page is doingThe title stresses that most defense happens in routine tasks, not in the IT department. APA 7 student title page.
2

Everyday Defense: Security and Privacy in the Daily Use of Health Care Systems

Most breaches of health information do not begin with sophisticated hacking. They begin with a click on a fake email, a password written on a sticky note, a screen left open or a laptop left in a car. Security and privacy depend on the daily habits of every person who uses a practice's systems. This paper examines security and privacy in the everyday work of a composite six-provider family practice, applying federal requirements to real tasks and proposing a training plan.

The Security Rule

Under the HIPAA Security Rule, health plans, clearinghouses and most providers must shield patient data held in electronic form with three kinds of safeguards: administrative safeguards such as risk analysis, workforce training and access policies; physical safeguards such as control of facility access and workstations; and technical safeguards such as access controls, audit controls and transmission security (U.S. Department of Health and Human Services, 2022). The rule is flexible about how a small practice meets these standards but expects it to analyze its own risks.

A Phishing Email

One Monday, a billing specialist opened a message dressed up as a notice from the practice's clearinghouse, asking her to log in to resolve a payment problem. The link led to a convincing copy of the login page. She entered her username but stopped before her password because the web address looked wrong, and she reported it to the office manager, who alerted all staff and the IT vendor. Had she entered her password, the attacker could have reached claims containing thousands of patients' information.

What this page is doingOpening with a near miss that a staff member stopped makes the point that individual habits are a security control.
3

How Often Staff Click

Such emails work often enough to be dangerous. In simulated phishing campaigns at six US health care institutions, 14.2% of nearly 3 million test emails were clicked, almost one in seven, yet institutions that ran more campaigns saw clicking fall (Gordon et al., 2019). The finding suggests that regular practice with realistic test emails can reduce risk.

Why It Matters

A single compromised account can open the door to ransomware. The 374 ransomware attacks on American care providers counted between 2016 and 2021 put data on close to 42 million people at risk, and nearly half of them interrupted patient care (Neprash et al., 2022). For a small practice, an attack can halt scheduling, billing and records for days and lead to notification costs and lost trust.

Daily Risks and Controls

The table lists common daily risks at the practice and the controls in place.

Daily riskControl
Phishing emailsTraining, test emails, report button, two-step login
Shared or written passwordsUnique logins, password manager, badge tap login
Unlocked screensAutomatic lock after short idle time, privacy filters
Curious access to recordsRole-based access, audit log review, sanctions
Lost phones and laptopsEncryption, remote wipe, no local storage
Texting patient detailsSecure messaging app only
Conversations overheardPrivate areas for calls, lowered voices

Shared Logins

In busy clinics, staff sometimes stay logged in and let a coworker use their session. This defeats audit trails, since the record shows the wrong person, and it spreads access beyond each person's role. The practice installed badge tap login so that switching users takes seconds, removing the main excuse for sharing.

Screens and Spaces

Front desk screens face the waiting room in many offices. The practice turned monitors away from public view, added privacy filters and set screens to lock after two minutes. Staff make calls about patients from a back office rather than the front desk. These physical measures cost little and prevent the most common privacy lapses.

Mobile Devices and Texting

Staff and providers use phones for work, and texting a coworker a patient's name and result is tempting. The practice provided a secure messaging app and prohibited sending patient information by regular text. Work phones and laptops are encrypted and can be wiped remotely if lost.

Curious Access

Not all privacy risks come from outsiders. Staff may look up a neighbor, a coworker or a celebrity patient out of curiosity. Role-based access limits what each user can see, and the office manager reviews audit reports for any opening of a coworker's chart or of a chart that shares the user's surname. Violations lead to sanctions under the practice's policy.

Vendors and Remote Access

The practice's IT vendor, billing clearinghouse and record system vendor all have some access to its systems or data. Each has signed a business associate agreement, and remote access by vendors requires two-step login and is logged. When the practice changed IT vendors, it removed the old vendor's accounts the same day.

Training Plan

The practice's plan includes security training at hire and every year, a monthly simulated phishing email with immediate feedback for anyone who clicks, a one-click report button in email, quarterly reminders on screens and texting, and a short review of any incident at the next staff meeting. The office manager tracks click rates and report rates as measures of progress.

Responding to an Incident

When something does go wrong, speed matters. Staff who suspect they clicked a phishing link or lost a device must report it immediately, without fear of punishment for honest mistakes. The office manager and IT vendor then reset passwords, check the account's activity, and decide whether protected health information was exposed. If a breach occurred, federal rules require notification of affected individuals and the government within set time limits, so the practice keeps a written incident response checklist.

What this page is doingIncluding a response step shows that security is a cycle of prevention, detection and response, not prevention alone.
4

Balancing Security and Speed

Security controls can slow work, and staff will find ways around controls that cost too much time. Screens that lock after one minute lead staff to jiggle mice; complex password rules lead to written passwords. The practice chose controls, such as badge tap login and a password manager, that protect data while keeping tasks quick, and it asks staff which controls get in the way.

Conclusion

Security and privacy depend on ordinary actions: checking a link before logging in, locking a screen, using one's own login and keeping patient details off personal texts. The HIPAA Security Rule sets the framework, but the practice's defense lies in daily habits, supported by simple controls and regular practice. The billing specialist who stopped before entering her password showed what good habits can prevent.

References

Gordon, W. J., Wright, A., Aiyagari, R., Corbo, L., Glynn, R. J., Kadakia, J., Kufahl, J., Mazzone, C., Noga, J., Parkulo, M., Sanford, B., Scheib, P., & Landman, A. B. (2019). Assessment of employee susceptibility to phishing attacks at US health care institutions. JAMA Network Open, 2(3), Article e190393. https://doi.org/10.1001/jamanetworkopen.2019.0393

Neprash, H. T., McGlave, C. C., Cross, D. A., Virnig, B. A., Puskarich, M. A., Huling, J. D., Rozenshtein, A. Z., & Nikpay, S. S. (2022). Trends in ransomware attacks on US hospitals, clinics, and other health care delivery organizations, 2016-2021. JAMA Health Forum, 3(12), Article e224873. https://doi.org/10.1001/jamahealthforum.2022.4873

U.S. Department of Health and Human Services. (2022). Summary of the HIPAA security rule. https://www.hhs.gov/hipaa/for-professionals/security/laws-regulations/index.html

Reading the HCA 120 Module 7 assignment instructions

The HCA 120 catalog text covers technology in the everyday work of health care, and because module instructions stay in the Aspen classroom, security in routine system use became the focus. Security assignments usually ask you to explain legal requirements, identify common threats and recommend protections for a practice or department. Some ask for a training plan or policy. Check your prompt for the setting and whether it names HIPAA specifically. Anchor abstract rules in concrete tasks, such as logging in, answering email or texting a colleague, since graders look for application. Use measured evidence on phishing or breaches rather than news stories where possible. Include how staff should report a suspected incident.

How this HCA 120 Module 7 example is built

At about 1,035 words, the example has sixteen headings and a seven-row table of daily risks and controls. It opens with the Security Rule's three safeguard types, then tells the phishing near miss. Two evidence sections cover click rates and ransomware. The table follows, then sections on shared logins, screens and spaces, mobile devices and texting, and curious access to records. Incident response, vendor access, the balance between security and speed and a training plan with measures precede the conclusion. One note in the margin explains why the near miss opens the paper and why response is included alongside prevention. The conclusion returns to the billing specialist whose caution opened the paper. Short sections keep each risk separate and easy to find.

Reading the HCA 120 Module 7 grading rubric

Security papers tend to be marked on accurate treatment of requirements, identification of realistic threats, fitting controls and evidence. Requirements are summarized from HHS guidance and applied to tasks. Threats are the everyday ones staff meet: phishing, shared logins, open screens, lost phones, curiosity. Controls are matched to each threat in the table and explained, including why some controls backfire when they slow work too much. Two peer-reviewed studies and the HHS summary are referenced in APA style. Graders also look for a cycle of prevention, detection and response; this paper includes all three. The training plan also names the measures that will show progress. Each control is also weighed against the time it costs staff.

HCA 120 Module 7 help: mistakes that cost marks

Weak security papers restate HIPAA in general terms without showing what staff do differently on Monday morning. Tie each safeguard to a task. Students also forget insider risks, such as looking up a coworker's record. Another common gap is ignoring response: what to do after a click or a lost laptop. Controls that slow work lead to workarounds, so discuss that trade-off. If your prompt asks for a training plan, include how you will measure it. Our tutors can review your plan or draft and help you match each threat with a control that fits a real office. Keep examples ordinary, because everyday tasks are where most breaches start.

Write yours, or have the desk draft it

This paper is an original model document written by our desk, not a submitted student paper and not an official Aspen University document. Read it for the moves, then write your own to the instructions in your classroom. If you want one built to your exact prompt and rubric, the first custom sample is free and arrives in 24 to 48 hours.

More HCA 120 and Health Care Administration sample papers

HCA 120 Module 7 questions, answered

What does HCA 120 Module 7 usually ask for?

The HCA 120 description covers technology in everyday health care work, so a paper on security and privacy in system use is a typical assignment. Follow your Aspen classroom prompt.

What are the three types of HIPAA Security Rule safeguards?

Administrative, physical and technical safeguards for electronic protected health information.

How common is clicking on phishing emails in health care?

Test campaigns at six US institutions drew clicks on about one email in seven, and clicking dropped as campaigns were repeated.

Where can I find a free HCA 120 Module 7 sample paper?

Look above: the complete everyday security and privacy paper, risk table and margin notes included, is published for open reading. It is the seventh of the HCA 120 samples.

What is the most common way attackers get into health care systems in HCA 120 Module 7?

Phishing emails that trick staff into entering passwords or opening harmful links are a leading route, which is why training and test emails matter.