Running Head: Final Project Risk Analysis
IT-412 Cyberlaw and Ethics
Final Project Submission
Risk Analysis
Jason Popejoy
Southern New Hampshire University
Risk Analysis Paper
ABC Healthcare IT Structure
Having been hired as the IT network security officer, it has become my duty to create a
risk analysis report for the company. In this report, I will assess the company's IT systems for the
possible violations to ethics and cyberlaw compliance. Along with searching for IT ethics and
cyberlaw violations, I have also been tasked with creating a use-of-service technology policy and
a code of ethics policy for employees, after researching the company's existing IT framework.
The company has hired a network administrator with limited experience, and various vendors to
assist in the setup of the current simple system. This network consists of a router connected to
the internet and a switch. From the switch, three branches run to each of the departments. The
first branch leads to the management workstations, The second leads to the health records staff
and the wireless access point which allows staff and guests to access the network, and the final
branch leads to the bookkeeping staff and the company's only server.
The network has no security features installed to keep data safe, although a video
monitoring system has been installed by management as security. Employees of the company are
not aware of the monitoring system or that they are being monitored at all times. Since
installation of the company's computer software, usernames and passwords have not been
changed. They have been left on default settings. Employees of ABC Healthcare are permitted to
check personal email on company workstations as well as browse the web. They can also bring
wireless devices from home such as personal tablets to access the company's network. As a final
note, it should be noted that the company's only printer, which is accessible for use by al
employees is set up in the front office.
Risk Analysis Paper
3
Cyberlaws and Ethics Regulations
ABC Healthcare handles mainly healthcare records and as such the company is required
to follow certain laws and guidelines set forth by the Healthcare Insurance Portability and
Accountability Act (HIPAA). HIPAA is a federal law that protects sensitive patient health
information from being disclosed without the patient's consent or knowledge (Health Insurance
Portability and Accountability Act of 1996, 2018). There are Three rules that comprise HIPAA
These include the Privacy Rule, the Security Rule, and the Breach of Notification Rule
(Cybersecurity in Healthcare, 2021).
Another law that affects ABC Healthcare is the Health Information Technology for
Economic and Clinical Health (HITECH) Act. This law was enacted as part of the American
Recovery and Reinvestment Act of 2009 (Office for Civil Rights (OCR), 2017). HITECH was
designed to help promote the adoption and use of Health information technology. Subtitle D of
the HITECH Act focuses on the privacy and security concerns associated with the electronic
transmission of health information, through provisions that strengthen the civil and criminal
enforcement o