©2015 Walden University 1
OM011: Protecting Patient Data: Recommend policies and processes that protect the privacy, confidentiality, security, and integrity of patient
data.
Assessment Rubric
0
Not Present
1
Needs Improvement
2
Meets Expectations
3
Exceeds Expectations
Part I: Policy Manual Introduction
Sub-Competency 1: Explain the importance of organization-wide security programs.
Learning Objective 1.1:
Describe the purpose
of patient record
protection and its
importance in relation
to organization-wide
security programs.
Description of the purpose
of patient record
protection and its
importance to the
organization is missing.
Response vaguely
describes the purpose of
patient record protection.
Response is unclear
regarding the importance
of patient record
protection to the
organization in the case
study.
Description is not
supported by references to
academic/professional
resources or the resources
are not relevant.
Response clearly describes
the purpose of patient
record protection.
Response includes a
concise explanation
regarding the importance
of patient record
protection to the
organization in the case
study.
Description is supported
by references to
relevant
academic/professional
resources.
Demonstrates the same
level of achievement as
“2,” plus the following:
Response is supported by
examples from a relevant
authentic organization.
Learning Objective 1.2:
Explain the legal
requirements for
protecting patient
health records in
relation to
organization-wide
security programs.
Explanation of the legal
requirements for
protecting patient health
records is missing.
Response does not clearly
explain relevant legal
requirements for
protecting patient health
records.
Explanation is not
supported by references to
Response accurately
explains the relevant legal
requirements for
protecting patient health
records.
Explanation is supported
by references to relevant
Demonstrates the same
level of achievement as
“2,” plus the following:
Response clearly explains
how at least two relevant
legal requirements could
have protected the patient
©2015 Walden University 2
0
Not Present
1
Needs Improvement
2
Meets Expectations
3
Exceeds Expectations
relevant laws. laws.
records in the case study.
Part II: Risk Assessment
Sub-Competency 2: Evaluate significant threats to patient data from internal, external, intentional, and unintentional sources.
Learning Objective 2.1:
Identify risks to both
electronic and paper
patient records.
Identification of risks to
both electronic and paper
patient records is missing.
Response vaguely
identifies threats to
electronic and paper
patient records.
Response identifies two
relevant threats to
electronic and paper
patient records.
Demonstrates the same
level of achievement as
“2,” plus the following:
Response identifies one
additional threat to
electronic and paper
patient records.
Learning Objective 2.2:
Recommend remedies
to protect patient
records from
compromise.
Recommendation for
remedies to protect
patient records from
compromise is missing.
Response is vague about
achievable remedies to
protect patient records
from compromise.
Response recommends
five clear and achievable
remedies to protect
patient records from
compromise.
Demonstrates the same
level of achievement as
“2,” plus the following:
Response recommends an
additional clear and
achievable remedy to
protect patient records
from compromise.
Learning Objective 2.3:
Create policy
statements that
comply with HIPAA
regulations that
address access to and
disclosure of electronic
and paper patient
records.
Creation of the policy
statements that comply
with HIPAA regulations
that address access to and
disclosure of electronic
and paper patient records
is missing.
Response includes policy
statements that vaguely
address access to and
disclosure of electronic
and paper patient health
records.
Policy statements are not
supported by references to
academic/professional
Response includes at least
two concise and relevant
policy statements that
address access to and
disclosure of electronic
and paper patient health
records.
Policy statements are
supported by references to
Demonstrates the same
level of achievement as
“2,” plus the following:
Response clearly describes
how at least two concise
and relevant policy
statements that address
access to and disclosure of
electronic and paper
©2015 Walden University 3
0
Not Present
1
Needs Improvement
2
Meets Expectations
3
Exceeds Expectations
resources or the resources
are not relevant.
relevant
academic/professional
resources.
patient health records
apply to at least three staff
positions.
Learning Objective 2.4:
Describe training topics
that will educate the
staff on accessing and
disclosing patient
records.
Description of training
topics that will educate the
staff on accessing and
disclosing patient records
is missing.
Response includes a vague
description of training
topics for staff and does
not include relevant
strategies related to
assessing identification
required to access patient
records.
Training topics not
supported by references to
academic/professional
resources or the resources
are not relevant.
Response includes a
thorough description of
training topics for staff,
including three relevant
strategies related to
assessing identification
required to access patient
records.
Training topics are
supported by references to
relevant
academic/professional
resources.
Demonstrates the same
level of achievement as
“2,” plus the following:
Response includes a
thorough description one
additional strategy related
to assessing identification
required to access patient
records.
Part III: Alignment with Regulatory Requirements
Sub-Competency 3: Create policies to address HIPAA security regulations.
Learning Objective 3.1:
Identify breaches in
HIPAA regulations.
Identification of breaches
in HIPAA regulations is
missing.
Response vaguely
identifies one breach in
HIPAA regulations, based
on the case study.
Response accurately
identifies two breaches in
HIPAA regulations, based
on the case study.
Demonstrates the same
level of achievement as
“2,” plus the following:
Response identifies an
additional breach in HIPAA
regulations, based on the
case study.
Learning Objective 3.2:
Create policy
statements for patient
healthcare record
Creation of the policy
statements for patient
healthcare record handling
and disposal that aligns
Response includes vague
policy statements that
address patient healthcare
record handling and
Response includes two
concise and relevant policy
statements that address
patient healthcare record
Demonstrates the same
level of achievement as
“2,” plus the following:
©2015 Walden University 4
0
Not Present
1
Needs Improvement
2
Meets Expectations
3
Exceeds Expectations
handling and disposal
that aligns with HIPAA
regulations.
with HIPAA regulations is
missing.
disposal.
Policy statements are not
supported by references to
academic/professional
resources or the resources
are not relevant.
handling and disposal.
Policy statements are
supported by references to
relevant
academic/professional
resources.
Response clearly describes
how at least two concise
and relevant policy
statements that address
patient healthcare record
handling and disposal
apply to at least three staff
positions.
Learning Objective 3.3:
Describe training topics
that will educate the
staff on the handling
and disposal of patient
records.
Description of training
topics that will educate the
staff on the handling and
disposal of patient records
is missing.
Response includes a vague
description of training
topics for staff and does
not include strategies
related to the handling and
disposal of patient records.
Training topics are not
supported by references to
academic/professional
resources or the resources
are not relevant.
Response includes a
thorough description of
training topics for staff,
including at least three
relevant strategies related
to the handling and
disposal of patient records.
Training topics are
supported by references to
relevant
academic/professional
resources.
Demonstrates the same
level of achievement as
“2,” plus the following:
Response includes at least
five relevant strategies
related to the handling and
disposal of patient records
for at least three staff
positions.
Part IV: Managerial Oversight
Sub-Competency 4: Implement administrative, physical, and technical security protections in healthcare organizations.
Learning Objective 4.1:
Create clear
instructions for
management oversight
in the area of handling
and accessing patient
Creation of the clear
instructions for
management oversight in
the area of handling and
accessing patient records
is missing.
Response includes vague
instructions related to the
area of handling and
accessing patient records.
Instructions do not
Response includes at least
four relevant and concise
instructions related to the
area of handling and
accessing patient records.
Response demonstrates
the same level of
achievement as “2,” plus
the following:
Response includes at least
©2015 Walden University 5
0
Not Present
1
Needs Improvement
2
Meets Expectations
3
Exceeds Expectations
records. demonstrate compliance
with HIPAA regulations.
Instructions comply with
HIPAA regulations.
three relevant and concise
instructions related to the
area of handling and
accessing paper-based
patient records and at
least three relevant and
concise instructions
related to the area of
handling and accessing
electronic patient records.
Learning Objective 4.2:
Create policy
statements for role-
based security level
access to patient
records.
Creation of the policy
statements for role-based
security level access to
patient records is missing.
Response includes vague
policy statements that
outline role-based security
level access to patient
records.
Policy statements are not
supported by references to
academic/professional
resources or the resources
are not relevant.
Response includes two
concise and relevant policy
statements that outline
role-based security level
access to patient records.
Policy statements are
supported by references to
relevant
academic/professional
resources.
Demonstrates the same
level of achievement as
“2,” plus the following:
Response clearly describes
how at least two concise
and relevant policy
statements that outline
role-based security level
access to patient records
apply to at least three staff
positions.
Learning Objective 4.3:
Describe methods to
set security levels for
accessing patient
records.
Description of methods to
set security levels for
accessing patient records
is missing.
Response vaguely
describes about methods
to set security levels for
accessing patient records.
Response clearly describes
three methods to set
security levels for
accessing patient records.
Demonstrates the same
level of achievement as
“2,” plus the following:
Response clearly describes
one additional method to
set security levels for
accessing electronic
©2015 Walden University 6
0
Not Present
1
Needs Improvement
2
Meets Expectations
3
Exceeds Expectations
patient records and at
least one additional
method to secure access
of paper-based patient
records.
Part V: Emerging Technologies
Sub-Competency 5: Evaluate emerging technologies and their impact on the risks to patient data.
Learning Objective 5.1:
Evaluate the role that
emerging technologies
played in improper
access to patient
records.
Evaluation of the role that
emerging technologies
played in improper access
to patient records is
missing.
Response vaguely
evaluates the role of
emerging technologies in
the scenario, and does not
address the role of mobile
access and wireless access.
Response clearly evaluates
the role of emerging
technologies in the
scenario, specifically
explaining the role of
mobile access and wireless
access.
Response demonstrates
the same level of
achievement as “2,” plus
the following:
Response clearly evaluates
how mobile and wireless
access applies to at least
three staff positions.
Learning Objective 5.2:
Create policy
statements for the use
of wireless technology
and access, and for the
introduction of
emerging and mobile
technology into an
organization.
Creation of policy
statements for the use of
wireless technology and
access, and for the
introduction of emerging
and mobile technology
into an organization is
missing.
Response includes vague
policy statements
regarding the use of
wireless access.
Response vaguely explains
how to introduce emerging
and mobile technology
into an organization.
Policy statements are not
supported by references to
academic/professional
resources or the resources
are not relevant.
Response includes at least
two concise and relevant
policy statements
regarding the use of
wireless access.
Response clearly explains
how to introduce emerging
and mobile technology
into an organization.
Policy statements are
supported by references to
relevant
academic/professional
Response demonstrates
the same level of
achievement as “2,” plus
the following:
Response clearly describes
how at least two concise
and relevant policy
statements regarding the
use of wireless access
apply to at least three staff
positions.
©2015 Walden University 7
0
Not Present
1
Needs Improvement
2
Meets Expectations
3
Exceeds Expectations
resources.
Learning Objective 5.3:
Describe training topics
that will educate staff
on the possibilities
presented by emerging
technology.
Description of training
topics that will educate
staff on the possibilities
presented by emerging
technology, and the
process for introducing
emerging technology is
missing.
Response vaguely
describes training topics
for staff and does not
describe any relevant
strategies related to
emerging technology and
the process for introducing
emerging technology.
The training topics are not
supported by references to
academic/professional
resources or the resources
are not relevant.
Response thoroughly
describes training topics
for staff, including at least
three relevant strategies
related to emerging
technology and the
process for introducing
emerging technology.
The training topics are
supported by references to
relevant
academic/professional
resources.
Response demonstrates
the same level of
achievement as “2,” plus
the following:
Response includes clearly
written training material
that addresses at least five
strategies related to
emerging technology and
the process for introducing
emerging technology for at
least three staff positions.
PS001: Written Communication: Demonstrate graduate-level writing skills.
Learning Objective
PS 1.1:
Use proper grammar,
spelling, and
mechanics.
Multiple major and minor
errors in grammar,
spelling, and/or mechanics
are highly distracting and
seriously impact
readability.
Multiple minor errors in
grammar, spelling, and/or
mechanics are distracting
and negatively impact
readability.
Writing reflects competent
use of standard edited
American English.
Errors in grammar,
spelling, and/or mechanics
do not negatively impact
readability.
Grammar, spelling, and
mechanics reflect a high
level of accuracy in
standard American English
and enhance readability.
Learning Objective
PS 1.2:
Organize writing to
enhance clarity.
Writing is poorly organized
and incoherent.
Introductions, transitions,
and conclusions are
missing or inappropriate.
Writing is loosely
organized. Limited use of
introductions, transitions,
and conclusions provides
partial continuity.
Writing is generally well-
organized. Introductions,
transitions, and
conclusions provide
continuity and a logical
Writing is consistently
well-organized.
Introductions, transitions,
and conclusions are used
effectively to enhance
©2015 Walden University 8
0
Not Present
1
Needs Improvement
2
Meets Expectations
3
Exceeds Expectations
progression of ideas. clarity, cohesion, and flow.
Learning Objective
PS 1.3:
Apply APA style to
written work.
APA conventions are not
applied.
APA conventions for
attribution of sources,
structure, formatting, etc.,
are applied inconsistently.
APA conventions for
attribution of sources,
structure, formatting, etc.,
are generally applied
correctly in most
instances. Sources are
generally cited
appropriately and
accurately.
APA conventions for
attribution of sources,
structure, formatting, etc.,
are applied correctly and
consistently throughout
the paper. Sources are
consistently cited
appropriately and
accurately.
Learning Objective
PS 1.4:
Use appropriate
vocabulary and tone
for the audience and
purpose.
Vocabulary and tone are
inappropriate and
negatively impact clarity of
concepts to be conveyed.
Vocabulary and tone have
limited relevance to the
audience.
Vocabulary and tone are
generally appropriate for
the audience and support
communication of key
concepts.
Vocabulary and tone are
consistently tailored to the
audience and effectively
and directly support
communication of key
concepts.
PS005: Critical Thinking and Problem Solving: Use critical-thinking and problem-solving skills to analyze professional issues and inform best
practice.
Learning Objective
PS 5.1:
Analyze assumptions
and fallacies.
Analysis of assumptions is
missing.
Response is weak in
assessing the
reasonableness of
assumptions in a given
argument.
Response does not
adequately identify and
discuss the implications of
fallacies or logical
weaknesses in a given
argument.
Response generally
assesses the
reasonableness of
assumptions in a given
argument.
Response identifies and
discusses the implications
of fallacies and/or logical
weaknesses in a given
argument.
Response clearly and
comprehensively assesses
the reasonableness of
assumptions in a given
argument.
Response provides a
detailed and compelling
analysis of implications of
fallacies and logical
weaknesses in a given
argument.
Learning Objective Assumptions are missing. Response does not Response presents and Response justifies the
©2015 Walden University 9
0
Not Present
1
Needs Improvement
2
Meets Expectations
3
Exceeds Expectations
PS 5.2:
Generate reasonable
and appropriate
assumptions.
adequately present and
discuss key assumptions in
an original argument.
discusses key assumptions
in an original argument.
reasonableness and need
for assumptions in an
original argument.
Learning Objective
PS 5.3:
Assess multiple
perspectives and
alternatives.
Assessment of multiple
perspectives is missing.
Response does not identify
nor adequately consider
multiple perspectives or
alternatives.
Response identifies and
considers multiple
perspectives and
alternatives.
Response justifies
selection of chosen
alternative relative to
others.
Learning Objective
PS 5.4:
Use problem-solving
skills.
Problems and solutions are
not identified.
Response presents
solutions, but they are
ineffective in addressing
the specific problem.
Response presents
solutions that are practical
and work in addressing the
specific problem.
Response presents
compelling supporting
arguments for proposed
solutions.
Access the following to complete this Assessment:
·
United General Hospital Patient Privacy Case Study
This assessment has five-parts. Click each of the items below to complete this assessment.
Part I: Policy Manual Introduction
United General’s hospital administrator reviewed the hospital’s policy manual and discovered that it inadequately addresses the area of patient records. The hospital administrator tasks you with reviewing the hospital policy manual and reporting on the thoroughness of its coverage of patient records. After a review of the policy manual, you report that the coverage of patient records is sparse and outdated. The hospital administrator then asks you to update the policy manual.
Develop a policy manual introduction that includes the following (1–2 pages):
· Write an update to the manual’s introduction, which includes more depth in the area of patient records. As you write this section, describe the purpose of patient record protection and its importance to the organization.
· Include an explanation of the legal requirements for protecting patient health records.
Part II: Risk Assessment
Because Pete compromised Winnie’s patient records, the hospital administrator tasks you with identifying other potential risks that the hospital and the primary care physicians may need to address to protect patient records.
Conduct a risk assessment, and write a report that includes the following (5–7 pages):
· Identify risks to both electronic and paper patient records, and recommend remedies the United General can put in place to protect the records from compromise.
· Create policy statements that comply with HIPAA regulations, addressing access to and disclosure of electronic and paper patient records.
· Describe relevant training topics that will educate the staff on accessing and disclosing patient records.
Part III: Alignment With Regulatory Requirements
Winnie’s lawsuit refers to the violation of patient record protection and privacy regulations, by the United General, as the prime cause of the problem. This has now opened United General to governmental inquiries, as well as to federal lawsuits.
In 5–7 pages, complete the following:
· Review the requirements of the HIPAA regulations, and identify areas in the case study that breached HIPAA regulations—remembering your analysis of the hospital’s policy manual (the policies applicable to patient record handling and disposal require an update to align with HIPAA regulations).
· Create policy statements that align with HIPAA regulations that address patient healthcare record handling and disposal.
· Describe relevant training topics for staff in order to educate them on the handling and disposal of patient records.
Part IV: Managerial Oversight
During Pete’s exit interview, he stated that he did not receive managerial direction or training in regard to accessing computer systems and online patient records. The hospital administrator reviewed the management training manual and found that the area detailing instructions that management needs to give to staff is sparse. The hospital administrator asks that you write a section of the management training manual to provide clear instructions for management oversight in the area of handling and accessing patient records. As part of managerial oversight of hospital staff, access to patient records should be restricted and only available to appropriate staff members. For instance, in this case study, Pete should not have had access to Winnie’s patient record.
Develop a section of the management training manual that includes the following (5–7 pages):
· Write at least four clear instructions for management oversight in the area of handling and accessing patient records.
· Create at least two policy statements for role-based security level access to patient records.
· Include at least three methods to set security levels for accessing patient records to support the policy statements.
Part V: Emerging Technologies
Because Pete accessed Winnie’s record using mobile and wireless technology, the United General is concerned about their approach to emerging technology. To deal with this potential threat, the United General brought in a security consultant to assess the hospital’s technology environment. The consultant found that the wireless network is unprotected, allowing for unauthorized access to patient records and hospital personnel records. To address this issue, you are tasked to work with the security consultant to describe the role that emerging technologies played in the “United General Hospital Patient Privacy Case Study” document.
Develop a report for the security consultant that addresses the following (5–7 pages):
· Evaluate the role that emerging technologies play in access to patient records.
· Create policy statements for the use of wireless technology and access.
· Describe relevant training topics for staff in order to introduce emerging technology, and educate them regarding the possibilities presented by emerging technology.
Essay Writing Service Features
Our Experience
No matter how complex your assignment is, we can find the right professional for your specific task. Achiever Papers is an essay writing company that hires only the smartest minds to help you with your projects. Our expertise allows us to provide students with high-quality academic writing, editing & proofreading services.Free Features
Free revision policy
$10Free bibliography & reference
$8Free title page
$8Free formatting
$8How Our Dissertation Writing Service Works
First, you will need to complete an order form. It's not difficult but, if anything is unclear, you may always chat with us so that we can guide you through it. On the order form, you will need to include some basic information concerning your order: subject, topic, number of pages, etc. We also encourage our clients to upload any relevant information or sources that will help.
Complete the order form
Once we have all the information and instructions that we need, we select the most suitable writer for your assignment. While everything seems to be clear, the writer, who has complete knowledge of the subject, may need clarification from you. It is at that point that you would receive a call or email from us.
Writer’s assignment
As soon as the writer has finished, it will be delivered both to the website and to your email address so that you will not miss it. If your deadline is close at hand, we will place a call to you to make sure that you receive the paper on time.
Completing the order and download