HCR 264 Module 7 Case Study Paper: A HIPAA Resolution Agreement Example

Reviewed by Emmett Rockwell, MBA Arizona State University Updated October 2026

This HCR 264 Module 7 sample is the Case Study Paper that ends Regulatory Essentials of Compliance Program Design and is the last writing assignment for ASU Health Care Compliance and Regulations students in this course. In ASU HCR 264 this closing paper is a case study of about three pages of an organization under a current HIPAA resolution agreement, with proposed corrective actions. The composite student studies Ambry Genetics, a California genetic testing laboratory that agreed in September 2026 to pay $700,000 and follow a two-year corrective action plan after a phishing attack on one employee's email account exposed information on 225,370 people. The paper explains the Security Rule gaps OCR identified, a missing risk analysis, weak access termination and shared user identities, and proposes a plan to close each.

CourseHCR 264 Regulatory Essentials of Compliance Program Design
ModuleModule 7
Paper typeCase study paper
LengthAbout 691 words, 5 pages
FormatAPA 7 student paper
SchoolArizona State University
ProgramBS in Health Care Compliance and Regulations
UpdatedOctober 2026

Free sample paper for HCR 264 Module 7

1

One Phishing Email, Three Security Rule Gaps: A Case Study of the Ambry Genetics Resolution Agreement

Student Name

BS in Health Care Compliance and Regulations, Arizona State University

HCR 264: Regulatory Essentials of Compliance Program Design

Instructor Name

Month Day, Year

What this page is doingThe title names the cause of the breach, the number of violations OCR identified and the organization.
2

One Phishing Email, Three Security Rule Gaps: A Case Study of the Ambry Genetics Resolution Agreement

The Organization and the Breach

Ambry Genetics is a genetic testing laboratory that handles some of the most sensitive health information there is: test results that can reveal inherited disease risk for patients and their relatives. In January 2020, Ambry discovered that an employee's email account had been compromised through a phishing attack. The information in the account, which may have been taken by the attacker, included names, addresses, dates of birth, some Social Security and driver's license numbers, financial details, diagnoses, laboratory results, medications and treatment information for 225,370 individuals. Ambry reported the breach to the HHS Office for Civil Rights (OCR) in March 2020 (Nixon Peabody, 2026).

The Resolution Agreement

On September 17, 2026, OCR announced that Ambry had agreed to pay $700,000 and implement a corrective action plan that OCR will monitor for two years (U.S. Department of Health and Human Services [HHS], 2026). A resolution agreement is a settlement: the organization does not admit liability, but it pays and accepts federal monitoring. OCR said its investigation found potential violations in three areas of the HIPAA Security Rule.

Potential violationSecurity Rule standard
No accurate and thorough risk analysis of risks to electronic protected health informationRisk analysis standard, § 164.308(a)(1)(ii)(A) of 45 C.F.R.
No procedures to end a workforce member's access when employment or the need for access endsTermination procedures, 45 C.F.R. § 164.308(a)(3)(ii)(C)
No unique names or numbers to identify and track users in systems holding ePHIUnique user identification, 45 C.F.R. § 164.312(a)(2)(i)
What this page is doingMatching each finding to its regulation shows that the case is about specific, checkable requirements, not general carelessness.
3

Analysis

The phishing email was the trigger, but OCR's findings describe an organization that could not have known how exposed it was. Without a risk analysis, Ambry had no inventory of where electronic health information lived, including in staff email, and no ranking of the threats to it. OCR's director called the lack of a compliant risk analysis one of the most common compliance failures it sees (HHS, 2026), and the agency has made risk analysis a focus of its enforcement. The other two gaps made any intrusion harder to contain and investigate. When former employees keep access, or several people share one login, an organization cannot say who touched which records, which is the first question after a breach. For a laboratory whose data concern families as well as patients, those gaps matter more than usual.

Proposed Corrective Action Plan

The plan below follows the elements OCR typically requires in its corrective action plans and adds the specific steps Ambry's gaps call for.

ActionOwnerEvidence of completionTimeline
Enterprise risk analysis covering every system, including email, that holds ePHISecurity officer with outside assessorWritten risk analysis submitted to OCRMonths 1-4
Risk management plan ranking each risk and the control chosenSecurity officerApproved plan with datesMonths 4-6
Access termination procedure tied to the human resources system, removing access the same dayIT and human resourcesMonthly report of terminations and access removedMonth 3, then monthly
Unique user IDs for every person, with shared accounts retiredITSystem account inventoryMonth 3
Multifactor authentication and phishing-resistant email filteringITConfiguration reportMonth 4
Role-based Security Rule training with phishing simulationsPrivacy and security officersTraining records and simulation resultsMonth 6, then annually
Internal audit of the plan's controlsCompliance officerAudit report to the boardMonth 12 and 24

Lessons for Other Organizations

The case shows that a breach investigation looks well beyond the breach. OCR asked whether Ambry had done the basic work the Security Rule requires before anything went wrong. Any covered entity can ask the same questions of itself today: when was the last enterprise-wide risk analysis, does access end the day an employee leaves and can every action in our systems be traced to one person?

Conclusion

Ambry's resolution agreement turns one phishing email into a two-year obligation to rebuild security fundamentals. A corrective plan that starts with a real risk analysis, then fixes access termination and user identity, answers each of OCR's findings and leaves the organization better able to detect the next attack.

References

Nixon Peabody. (2026, September 21). HIPAA settlement reminds organizations to focus on security. https://www.nixonpeabody.com/insights/articles/2026/09/21/hipaa-settlement-reminds-organizations-to-focus-on-security

Security standards: Administrative safeguards, 45 C.F.R. § 164.308 (2024).

Security standards: Technical safeguards, 45 C.F.R. § 164.312 (2024).

U.S. Department of Health and Human Services. (2026, September 17). HHS' Office for Civil Rights settles HIPAA investigation of Ambry Genetics phishing attack affecting 225,000 individuals [Press release]. https://www.hhs.gov/press-room/hhs-office-civil-rights-settles-hipaa-investigation-ambry-genetics-phishing-attack-affecting-225000-individuals.html

HCR 264 Module 7 instructions, in plain terms

HCR 264 closes with Writing Assignment 4, due at the end of Week 7, the module on protected health information, HIPAA and HITECH. What the syllabus wants is a case study of about three APA pages on of an organization with a current resolution agreement, together with proposed corrective action plans. Resolution agreements are the settlements HHS's Office for Civil Rights reaches after HIPAA investigations; OCR posts each one with a press release and, usually, the full agreement, which lists the corrective action plan the organization must follow. The word current matters, so pick an agreement still in its monitoring period, typically two or three years from the announcement date. A good case study explains the organization, what happened, what OCR found, what the agreement requires and what you would add. With it, all four of the course's writing assignments are done.

Inside the HCR 264 Module 7 example

The sample opens with the organization and the breach, written from public sources, then explains what a resolution agreement is and what this one requires. A table matches each of OCR's three findings to the exact Security Rule standard, which makes the legal basis checkable. The analysis section argues that the phishing email was only the trigger and that the real problem was missing fundamentals, citing OCR's own statement about risk analysis. The corrective action plan appears as a table with an owner, evidence of completion and a timeline for each step, because that is how organizations actually report to OCR. A short lessons section turns the case into three questions any covered entity could ask, and the closing paragraph matches each step of the plan to a finding.

Reading the HCR 264 Module 7 grading rubric

The final paper is scored on a Canvas rubric within the course's 300 writing points. A case study earns its marks by choosing an agreement that is genuinely current, describing the organization and the incident accurately, explaining OCR's findings with reference to the specific HIPAA standards, analyzing why the failures happened and proposing a corrective plan whose steps match the findings, with owners and timelines. It loses marks when the case is old or outside its monitoring period, when the paper only retells the press release, when the HIPAA rule is described in general terms, when the plan is generic training and policy language and when the three-page limit is exceeded. Readers also check that the paper treats the agreement as a settlement, not a court finding.

HCR 264 Module 7 help with common mistakes

Start with OCR's list of resolution agreements and pick one announced within the last year or two. Read the press release and, if it is posted, the agreement itself, which spells out the corrective action plan. Look up each Security Rule or Privacy Rule standard OCR cites so you can explain it precisely. Write the corrective plan as a table with owners and evidence, since that is how real plans are tracked. Add at least one step OCR did not require but your analysis supports. Keep to three pages by letting tables carry the detail. If the agreement you want is not posted in full, the desk can help you find a case with a public plan.

Write yours, or have the desk draft it

This paper is an original model document written by our desk, not a submitted student paper and not an official Arizona State University document. Read it for the moves, then write your own to the instructions in your classroom. If you want one built to your exact prompt and rubric, the first custom sample is free and arrives in 24 to 48 hours.

More HCR 264 and BS in Health Care Compliance and Regulations sample papers

HCR 264 Module 7 questions, answered

Where can I find a free HCR 264 Module 7 sample paper?

This page reproduces a whole case study of the 2026 Ambry Genetics HIPAA resolution agreement.

What is a HIPAA resolution agreement?

A settlement with HHS's Office for Civil Rights in which an organization pays an amount and follows a monitored corrective action plan, without admitting liability.

What counts as a current resolution agreement for HCR 264?

One still in its monitoring period, usually two or three years after OCR announces it.

What does a HIPAA corrective action plan usually require?

A risk analysis, a risk management plan, updated policies, workforce training and reports to OCR during monitoring.

What did OCR find in the Ambry Genetics case?

No thorough risk analysis, no procedures to end access when it was no longer needed and no unique user identification.