How to write HIM-FPX2660 Assessment 2

The short answer

This manual is for HIM-FPX2660 Assessment 2, start to submission. Assessment 2 of HIM-FPX2660, Ethics and Compliance in Healthcare Data Management, turns the analysis outward: instead of judging one incident, you write the thing an organization would follow the next time. The assessment usually asks you to produce or evaluate compliance guidance built on the safeguard and breach notification requirements, and your scoring guide decides whether that arrives as a policy, a procedure, a report or a training document. Guidance written as good intentions is the middle of the guide. Below is the method our tutors use for this deliverable, a structure built from the criteria, and an annotated sample excerpt. Prefer to hand it off? A premium original sample for this exact assessment comes back in 24 to 48 hours, revised free until it meets the guide. Your courseroom may print this as HIM FPX 2660 Assessment 2 or HIM2660 Assessment 2; it is the same deliverable, and HIM-FPX2660 Assessment 2 is what this manual walks through.

One honesty note before the manual: Capella revises courses and scoring guides over time, so always write to the exact scoring guide attached to your assessment in the courseroom. The course identity above is verified on capella.edu; the method and structure below are our tutors' approach to it, not Capella's official rubric text.

HIM-FPX2660 Assessment 2 grading scale at Capella FlexPath, the criterion levels this assessment is scored on, from Capella Tutors
How Capella FlexPath grades HIM-FPX2660 Assessment 2, visualized by Capella Tutors.

How HIM-FPX2660 Assessment 2 is scored

Each criterion is marked on its own against four written levels, and on written guidance the levels separate by whether a stranger could follow the document:

LevelWhat it means on a compliance policy or procedure
DistinguishedEvery requirement is traced to the rule that imposes it, every step has an owner and a deadline, the document distinguishes what is mandatory from what the organization chose, and it says how anybody would know whether it was followed.
ProficientAccurate, complete and usable, with responsibilities assigned to departments rather than to roles and no verification step.
BasicA correct restatement of the regulation reformatted as a policy, with nothing in it specific to an organization that could act on it.
Non-performanceA required component is absent, most often the notification timing or the vendor obligations, or the guidance conflicts with the rule it claims to implement.

The sample runs on a scenario that starts outside the building. An imaging center learns from an outside security researcher that its billing company left a folder of claim files, patient names, account numbers and diagnosis codes among them, on a cloud server readable by anyone who found the address. The center did nothing wrong at the keyboard and still owns most of the problem.

The HIM-FPX2660 Assessment 2 method, step by step

  1. Draft the criteria as the table of contents

    Guidance is graded row by row like everything else in FlexPath, so let the criteria decide your headings and your order.

  2. Sort the three rules before you write a single step

    Say which duty comes from the standard governing uses and disclosures, which from the safeguard requirements over electronic information, and which from the notification obligation that starts when something goes wrong. Blur them and no step in the document can be traced to anything, which is the failure the second criterion usually catches.

  3. Handle addressable specifications honestly

    An implementation specification marked addressable is not optional. The organization either puts it in place, or records why it is not reasonable in its environment and installs an equivalent measure instead. Encryption is the example worth writing out, because information rendered unreadable is treated differently when an incident happens, and a policy that says encryption is encouraged has answered nothing.

  4. Give the vendor relationship its own section

    A company that handles information on the organization's behalf is bound by a written agreement, is directly subject to the safeguard requirements, and has to report incidents back. Your procedure should state the reporting window it requires, what evidence it demands, and what happens to the contract when the vendor misses it.

  5. Put the clocks in the document

    Notification to individuals without unreasonable delay and no later than 60 days after discovery, prominent media notice and immediate reporting to the Secretary where an incident touches 500 or more residents of a state, and everything smaller on a log filed within 60 days after the calendar year ends. Write the dates as steps with owners rather than as facts in a paragraph, and say when the clock starts, because discovery is the trigger and it is the part people misplace.

  6. Build in the check, then self-score

    End with how compliance with your own document gets verified: who samples what, how often, and what happens when the sample fails. Then mark yourself against each criterion, rewrite anything under the top level, and submit early in the week so a two business day evaluation does not stall you.

A structure that maps to the criteria

The word counts below are our tutors' planning targets for guidance of this scope, not Capella requirements, and your scoring guide sets the format.

SectionWhat it must doGuide
Purpose and scopeWhat the document covers, which workforce and which vendors it binds, and what triggers its use.~175 words
Requirements and sourcesEach obligation stated with the rule behind it, and the mandatory parts separated from organizational choices.~300 words
SafeguardsAdministrative, physical and technical measures, with addressable specifications either implemented or reasoned away in writing.~275 words
Vendor obligationsThe written agreement, the reporting window, the evidence required, and the consequence for missing it.~225 words
Incident response stepsDiscovery, containment, the documented assessment, notifications with their deadlines, and who owns each step.~300 words
Verification and referencesHow adherence is sampled and reported, plus regulations and guidance cited in current APA both ways.as needed

Annotated sample excerpt

An original model excerpt from our team, showing procedure language that a person could actually be held to. Learn the shape, then write yours to your own prompt.

Sample excerpt: incident response steps Original model · Capella Tutors

Step 4. Within one business day of discovery, the privacy officer requires the vendor to confirm in writing the exact files exposed, the period during which the server was reachable, and any evidence of retrieval, and records the date on which discovery occurred, since the 60 day notification clock runs from that date and not from the day the vendor replies.1 Step 5. The privacy officer completes and signs the four-factor assessment, and where a low probability of compromise cannot be demonstrated, treats the event as a breach; access logs showing retrieval by an unknown address weigh against the organization, and the absence of logs is not evidence in its favor.2 Step 6. The compliance committee reviews the written agreement with the vendor against the reporting window it imposes, and where the vendor reported late, the contract owner issues a corrective action notice within five business days and the renewal decision is documented rather than automatic.3

  • 1A role, a deadline and the trigger date in one step, with the common error corrected inside the sentence.
  • 2The assessment is a signed act by a named person, and the missing-log problem is stated instead of being quietly used as comfort. That refusal is what reads as top column judgment.
  • 3Carries the consequence into the contract, which is where undergraduate drafts usually stop. A remedy with an owner and a number of days is a control rather than an intention.

The full premium sample for your exact assessment, written fresh to your scoring guide and issue, is free to request. Study it, revise it into your own voice, and submit work you understand.

Get the full sample free

The five mistakes that cost Distinguished

  • The regulation retyped as a policy. Restating the rule in numbered paragraphs adds nothing an organization could follow on a Tuesday morning.
  • Addressable read as optional. A document that treats encryption as a suggestion has skipped the requirement to justify the alternative in writing.
  • The vendor left at the agreement. Naming the contract without a reporting window, required evidence and a consequence leaves the criterion half answered.
  • Clocks with no starting point. Sixty days from discovery only means something once the document says who decides that discovery happened and records the date.
  • Steps assigned to departments. Health information will review is nobody. A role, a deadline and a named backup is somebody.

Pre-submission checklist

  • Every obligation traced to the specific rule that imposes it
  • Mandatory requirements separated from choices the organization made
  • Addressable specifications implemented or reasoned away in writing
  • Vendor reporting window, evidence and consequence all stated
  • Notification deadlines written as steps with owners and a recorded discovery date
  • A verification method with a sample size and a reporting route, APA reconciled both ways

Policy or procedure due and it reads like a regulation?

Send the prompt, the guide and the organization type you were given, and tell us who is meant to read the finished document. Back inside 24 to 48 hours comes guidance with every requirement traced, every step owned, and a verification section, marked against your criteria by a reviewer before delivery. Rewrites cost nothing.

Keep going

Online now