OM011 Protecting Patient Data
©2015 Walden University 1
OM011: Protecting Patient Data: Recommend policies and processes that protect the privacy, confidentiality, security, and integrity of patient
data.
Assessment Rubric
0 Not Present
1 Needs Improvement
2 Meets Expectations
3 Exceeds Expectations
Part I: Policy Manual Introduction
Sub-Competency 1: Explain the importance of organization-wide security programs.
Learning Objective 1.1: Describe the purpose of patient record protection and its importance in relation to organization-wide security programs.
Description of the purpose of patient record protection and its importance to the organization is missing.
Response vaguely describes the purpose of patient record protection. Response is unclear regarding the importance of patient record protection to the organization in the case study. Description is not supported by references to academic/professional resources or the resources are not relevant.
Response clearly describes the purpose of patient record protection. Response includes a concise explanation regarding the importance of patient record protection to the organization in the case study. Description is supported by references to relevant academic/professional resources.
Demonstrates the same level of achievement as “2,” plus the following: Response is supported by examples from a relevant authentic organization.
Learning Objective 1.2: Explain the legal requirements for protecting patient health records in relation to organization-wide security programs.
Explanation of the legal requirements for protecting patient health records is missing.
Response does not clearly explain relevant legal requirements for protecting patient health records. Explanation is not supported by references to
Response accurately explains the relevant legal requirements for protecting patient health records. Explanation is supported by references to relevant
Demonstrates the same level of achievement as “2,” plus the following: Response clearly explains how at least two relevant legal requirements could have protected the patient
©2015 Walden University 2
0 Not Present
1 Needs Improvement
2 Meets Expectations
3 Exceeds Expectations
relevant laws. laws.
records in the case study.
Part II: Risk Assessment
Sub-Competency 2: Evaluate significant threats to patient data from internal, external, intentional, and unintentional sources.
Learning Objective 2.1: Identify risks to both electronic and paper patient records.
Identification of risks to both electronic and paper patient records is missing.
Response vaguely identifies threats to electronic and paper patient records.
Response identifies two relevant threats to electronic and paper patient records.
Demonstrates the same level of achievement as “2,” plus the following: Response identifies one additional threat to electronic and paper patient records.
Learning Objective 2.2: Recommend remedies to protect patient records from compromise.
Recommendation for remedies to protect patient records from compromise is missing.
Response is vague about achievable remedies to protect patient records from compromise.
Response recommends five clear and achievable remedies to protect patient records from compromise.
Demonstrates the same level of achievement as “2,” plus the following: Response recommends an additional clear and achievable remedy to protect patient records from compromise.
Learning Objective 2.3: Create policy statements that comply with HIPAA regulations that address access to and disclosure of electronic and paper patient records.
Creation of the policy statements that comply with HIPAA regulations that address access to and disclosure of electronic and paper patient records is missing.
Response includes policy statements that vaguely address access to and disclosure of electronic and paper patient health records. Policy statements are not supported by references to academic/professional
Response includes at least two concise and relevant policy statements that address access to and disclosure of electronic and paper patient health records. Policy statements are supported by references to
Demonstrates the same level of achievement as “2,” plus the following: Response clearly describes how at least two concise and relevant policy statements that address access to and disclosure of electronic and paper
©2015 Walden University 3
0 Not Present
1 Needs Improvement
2 Meets Expectations
3 Exceeds Expectations
resources or the resources are not relevant.
relevant academic/professional resources.
patient health records apply to at least three staff positions.
Learning Objective 2.4: Describe training topics that will educate the staff on accessing and disclosing patient records.
Description of training topics that will educate the staff on accessing and disclosing patient records is missing.
Response includes a vague description of training topics for staff and does not include relevant strategies related to assessing identification required to access patient records. Training topics not supported by references to academic/professional resources or the resources are not relevant.
Response includes a thorough description of training topics for staff, including three relevant strategies related to assessing identification required to access patient records. Training topics are supported by references to relevant academic/professional resources.
Demonstrates the same level of achievement as “2,” plus the following: Response includes a thorough description one additional strategy related to assessing identification required to access patient records.
Part III: Alignment with Regulatory Requirements
Sub-Competency 3: Create policies to address HIPAA security regulations.
Learning Objective 3.1: Identify breaches in HIPAA regulations.
Identification of breaches in HIPAA regulations is missing.
Response vaguely identifies one breach in HIPAA regulations, based on the case study.
Response accurately identifies two breaches in HIPAA regulations, based on the case study.
Demonstrates the same level of achievement as “2,” plus the following: Response identifies an additional breach in HIPAA regulations, based on the case study.
Learning Objective 3.2: Create policy statements for patient healthcare record
Creation of the policy statements for patient healthcare record handling and disposal that aligns
Response includes vague policy statements that address patient healthcare record handling and
Response includes two concise and relevant policy statements that address patient healthcare record
Demonstrates the same level of achievement as “2,” plus the following:
©2015 Walden University 4
0 Not Present
1 Needs Improvement
2 Meets Expectations
3 Exceeds Expectations
handling and disposal that aligns with HIPAA regulations.
with HIPAA regulations is missing.
disposal. Policy statements are not supported by references to academic/professional resources or the resources are not relevant.
handling and disposal. Policy statements are supported by references to relevant academic/professional resources.
Response clearly describes how at least two concise and relevant policy statements that address patient healthcare record handling and disposal apply to at least three staff positions.
Learning Objective 3.3: Describe training topics that will educate the staff on the handling and disposal of patient records.
Description of training topics that will educate the staff on the handling and disposal of patient records is missing.
Response includes a vague description of training topics for staff and does not include strategies related to the handling and disposal of patient records. Training topics are not supported by references to academic/professional resources or the resources are not relevant.
Response includes a thorough description of training topics for staff, including at least three relevant strategies related to the handling and disposal of patient records. Training topics are supported by references to relevant academic/professional resources.
Demonstrates the same level of achievement as “2,” plus the following: Response includes at least five relevant strategies related to the handling and disposal of patient records for at least three staff positions.
Part IV: Managerial Oversight
Sub-Competency 4: Implement administrative, physical, and technical security protections in healthcare organizations.
Learning Objective 4.1: Create clear instructions for management oversight in the area of handling and accessing patient
Creation of the clear instructions for management oversight in the area of handling and accessing patient records is missing.
Response includes vague instructions related to the area of handling and accessing patient records. Instructions do not
Response includes at least four relevant and concise instructions related to the area of handling and accessing patient records.
Response demonstrates the same level of achievement as “2,” plus the following: Response includes at least
©2015 Walden University 5
0 Not Present
1 Needs Improvement
2 Meets Expectations
3 Exceeds Expectations
records. demonstrate compliance with HIPAA regulations.
Instructions comply with HIPAA regulations.
three relevant and concise instructions related to the area of handling and accessing paper-based patient records and at least three relevant and concise instructions related to the area of handling and accessing electronic patient records.
Learning Objective 4.2: Create policy statements for role- based security level access to patient records.
Creation of the policy statements for role-based security level access to patient records is missing.
Response includes vague
policy statements that
outline role-based security
level access to patient
records.
Policy statements are not supported by references to academic/professional resources or the resources are not relevant.
Response includes two
concise and relevant policy
statements that outline
role-based security level
access to patient records.
Policy statements are supported by references to relevant academic/professional resources.
Demonstrates the same level of achievement as “2,” plus the following: Response clearly describes how at least two concise and relevant policy statements that outline role-based security level access to patient records apply to at least three staff positions.
Learning Objective 4.3: Describe methods to set security levels for accessing patient records.
Description of methods to set security levels for accessing patient records is missing.
Response vaguely describes about methods to set security levels for accessing patient records.
Response clearly describes three methods to set security levels for accessing patient records.
Demonstrates the same level of achievement as “2,” plus the following: Response clearly describes one additional method to set security levels for accessing electronic
©2015 Walden University 6
0 Not Present
1 Needs Improvement
2 Meets Expectations
3 Exceeds Expectations
patient records and at least one additional method to secure access of paper-based patient records.
Part V: Emerging Technologies
Sub-Competency 5: Evaluate emerging technologies and their impact on the risks to patient data.
Learning Objective 5.1: Evaluate the role that emerging technologies played in improper access to patient records.
Evaluation of the role that emerging technologies played in improper access to patient records is missing.
Response vaguely evaluates the role of emerging technologies in the scenario, and does not address the role of mobile access and wireless access.
Response clearly evaluates the role of emerging technologies in the scenario, specifically explaining the role of mobile access and wireless access.
Response demonstrates the same level of achievement as “2,” plus the following: Response clearly evaluates how mobile and wireless access applies to at least three staff positions.
Learning Objective 5.2: Create policy statements for the use of wireless technology and access, and for the introduction of emerging and mobile technology into an organization.
Creation of policy statements for the use of wireless technology and access, and for the introduction of emerging and mobile technology into an organization is missing.
Response includes vague policy statements regarding the use of wireless access. Response vaguely explains how to introduce emerging and mobile technology
into an organization. Policy statements are not supported by references to academic/professional resources or the resources are not relevant.
Response includes at least two concise and relevant policy statements regarding the use of wireless access. Response clearly explains how to introduce emerging and mobile technology
into an organization. Policy statements are supported by references to relevant academic/professional
Response demonstrates the same level of achievement as “2,” plus the following: Response clearly describes how at least two concise and relevant policy statements regarding the use of wireless access apply to at least three staff positions.
©2015 Walden University 7
0 Not Present
1 Needs Improvement
2 Meets Expectations
3 Exceeds Expectations
resources.
Learning Objective 5.3: Describe training topics that will educate staff on the possibilities presented by emerging technology.
Description of training topics that will educate staff on the possibilities presented by emerging technology, and the process for introducing emerging technology is missing.
Response vaguely describes training topics for staff and does not describe any relevant strategies related to emerging technology and the process for introducing emerging technology. The training topics are not supported by references to academic/professional resources or the resources are not relevant.
Response thoroughly describes training topics for staff, including at least three relevant strategies related to emerging technology and the process for introducing emerging technology. The training topics are supported by references to relevant academic/professional resources.
Response demonstrates the same level of achievement as “2,” plus the following: Response includes clearly written training material that addresses at least five strategies related to emerging technology and the process for introducing emerging technology for at least three staff positions.
PS001: Written Communication: Demonstrate graduate-level writing skills.
Learning Objective PS 1.1: Use proper grammar, spelling, and mechanics.
Multiple major and minor errors in grammar, spelling, and/or mechanics are highly distracting and seriously impact readability.
Multiple minor errors in grammar, spelling, and/or mechanics are distracting and negatively impact readability.
Writing reflects competent use of standard edited American English. Errors in grammar, spelling, and/or mechanics do not negatively impact readability.
Grammar, spelling, and mechanics reflect a high level of accuracy in standard American English and enhance readability.
Learning Objective PS 1.2: Organize writing to enhance clarity.
Writing is poorly organized and incoherent. Introductions, transitions, and conclusions are missing or inappropriate.
Writing is loosely organized. Limited use of introductions, transitions, and conclusions provides partial continuity.
Writing is generally well- organized. Introductions, transitions, and conclusions provide continuity and a logical
Writing is consistently well-organized. Introductions, transitions, and conclusions are used effectively to enhance
©2015 Walden University 8
0 Not Present
1 Needs Improvement
2 Meets Expectations
3 Exceeds Expectations
progression of ideas. clarity, cohesion, and flow.
Learning Objective PS 1.3: Apply APA style to written work.
APA conventions are not applied.
APA conventions for attribution of sources, structure, formatting, etc., are applied inconsistently.
APA conventions for attribution of sources, structure, formatting, etc., are generally applied correctly in most instances. Sources are generally cited appropriately and accurately.
APA conventions for attribution of sources, structure, formatting, etc., are applied correctly and consistently throughout the paper. Sources are consistently cited appropriately and accurately.
Learning Objective PS 1.4: Use appropriate vocabulary and tone for the audience and purpose.
Vocabulary and tone are inappropriate and negatively impact clarity of concepts to be conveyed.
Vocabulary and tone have limited relevance to the audience.
Vocabulary and tone are generally appropriate for the audience and support communication of key concepts.
Vocabulary and tone are consistently tailored to the audience and effectively and directly support communication of key concepts.
PS005: Critical Thinking and Problem Solving: Use critical-thinking and problem-solving skills to analyze professional issues and inform best practice.
Learning Objective PS 5.1: Analyze assumptions and fallacies.
Analysis of assumptions is missing.
Response is weak in assessing the reasonableness of assumptions in a given argument. Response does not adequately identify and discuss the implications of fallacies or logical weaknesses in a given argument.
Response generally assesses the reasonableness of assumptions in a given argument. Response identifies and discusses the implications of fallacies and/or logical weaknesses in a given argument.
Response clearly and comprehensively assesses the reasonableness of assumptions in a given argument. Response provides a detailed and compelling analysis of implications of fallacies and logical weaknesses in a given argument.
Learning Objective Assumptions are missing. Response does not Response presents and Response justifies the
©2015 Walden University 9
0 Not Present
1 Needs Improvement
2 Meets Expectations
3 Exceeds Expectations
PS 5.2: Generate reasonable and appropriate assumptions.
adequately present and discuss key assumptions in an original argument.
discusses key assumptions in an original argument.
reasonableness and need for assumptions in an original argument.
Learning Objective PS 5.3: Assess multiple perspectives and alternatives.
Assessment of multiple perspectives is missing.
Response does not identify nor adequately consider multiple perspectives or alternatives.
Response identifies and considers multiple perspectives and alternatives.
Response justifies selection of chosen alternative relative to others.
Learning Objective PS 5.4: Use problem-solving skills.
Problems and solutions are not identified.
Response presents solutions, but they are ineffective in addressing the specific problem.
Response presents solutions that are practical and work in addressing the specific problem.
Response presents compelling supporting arguments for proposed solutions.