| Course | HCR 264 Regulatory Essentials of Compliance Program Design |
|---|---|
| Module | Module 7 |
| Paper type | Case study paper |
| Length | About 691 words, 5 pages |
| Format | APA 7 student paper |
| School | Arizona State University |
| Program | BS in Health Care Compliance and Regulations |
| Updated | October 2026 |
Free sample paper for HCR 264 Module 7
One Phishing Email, Three Security Rule Gaps: A Case Study of the Ambry Genetics Resolution Agreement
Student Name
BS in Health Care Compliance and Regulations, Arizona State University
HCR 264: Regulatory Essentials of Compliance Program Design
Instructor Name
Month Day, Year
One Phishing Email, Three Security Rule Gaps: A Case Study of the Ambry Genetics Resolution Agreement
The Organization and the Breach
Ambry Genetics is a genetic testing laboratory that handles some of the most sensitive health information there is: test results that can reveal inherited disease risk for patients and their relatives. In January 2020, Ambry discovered that an employee's email account had been compromised through a phishing attack. The information in the account, which may have been taken by the attacker, included names, addresses, dates of birth, some Social Security and driver's license numbers, financial details, diagnoses, laboratory results, medications and treatment information for 225,370 individuals. Ambry reported the breach to the HHS Office for Civil Rights (OCR) in March 2020 (Nixon Peabody, 2026).
The Resolution Agreement
On September 17, 2026, OCR announced that Ambry had agreed to pay $700,000 and implement a corrective action plan that OCR will monitor for two years (U.S. Department of Health and Human Services [HHS], 2026). A resolution agreement is a settlement: the organization does not admit liability, but it pays and accepts federal monitoring. OCR said its investigation found potential violations in three areas of the HIPAA Security Rule.
| Potential violation | Security Rule standard |
|---|---|
| No accurate and thorough risk analysis of risks to electronic protected health information | Risk analysis standard, § 164.308(a)(1)(ii)(A) of 45 C.F.R. |
| No procedures to end a workforce member's access when employment or the need for access ends | Termination procedures, 45 C.F.R. § 164.308(a)(3)(ii)(C) |
| No unique names or numbers to identify and track users in systems holding ePHI | Unique user identification, 45 C.F.R. § 164.312(a)(2)(i) |
Analysis
The phishing email was the trigger, but OCR's findings describe an organization that could not have known how exposed it was. Without a risk analysis, Ambry had no inventory of where electronic health information lived, including in staff email, and no ranking of the threats to it. OCR's director called the lack of a compliant risk analysis one of the most common compliance failures it sees (HHS, 2026), and the agency has made risk analysis a focus of its enforcement. The other two gaps made any intrusion harder to contain and investigate. When former employees keep access, or several people share one login, an organization cannot say who touched which records, which is the first question after a breach. For a laboratory whose data concern families as well as patients, those gaps matter more than usual.
Proposed Corrective Action Plan
The plan below follows the elements OCR typically requires in its corrective action plans and adds the specific steps Ambry's gaps call for.
| Action | Owner | Evidence of completion | Timeline |
|---|---|---|---|
| Enterprise risk analysis covering every system, including email, that holds ePHI | Security officer with outside assessor | Written risk analysis submitted to OCR | Months 1-4 |
| Risk management plan ranking each risk and the control chosen | Security officer | Approved plan with dates | Months 4-6 |
| Access termination procedure tied to the human resources system, removing access the same day | IT and human resources | Monthly report of terminations and access removed | Month 3, then monthly |
| Unique user IDs for every person, with shared accounts retired | IT | System account inventory | Month 3 |
| Multifactor authentication and phishing-resistant email filtering | IT | Configuration report | Month 4 |
| Role-based Security Rule training with phishing simulations | Privacy and security officers | Training records and simulation results | Month 6, then annually |
| Internal audit of the plan's controls | Compliance officer | Audit report to the board | Month 12 and 24 |
Lessons for Other Organizations
The case shows that a breach investigation looks well beyond the breach. OCR asked whether Ambry had done the basic work the Security Rule requires before anything went wrong. Any covered entity can ask the same questions of itself today: when was the last enterprise-wide risk analysis, does access end the day an employee leaves and can every action in our systems be traced to one person?
Conclusion
Ambry's resolution agreement turns one phishing email into a two-year obligation to rebuild security fundamentals. A corrective plan that starts with a real risk analysis, then fixes access termination and user identity, answers each of OCR's findings and leaves the organization better able to detect the next attack.
References
Nixon Peabody. (2026, September 21). HIPAA settlement reminds organizations to focus on security. https://www.nixonpeabody.com/insights/articles/2026/09/21/hipaa-settlement-reminds-organizations-to-focus-on-security
Security standards: Administrative safeguards, 45 C.F.R. § 164.308 (2024).
Security standards: Technical safeguards, 45 C.F.R. § 164.312 (2024).
U.S. Department of Health and Human Services. (2026, September 17). HHS' Office for Civil Rights settles HIPAA investigation of Ambry Genetics phishing attack affecting 225,000 individuals [Press release]. https://www.hhs.gov/press-room/hhs-office-civil-rights-settles-hipaa-investigation-ambry-genetics-phishing-attack-affecting-225000-individuals.html
HCR 264 Module 7 instructions, in plain terms
HCR 264 closes with Writing Assignment 4, due at the end of Week 7, the module on protected health information, HIPAA and HITECH. What the syllabus wants is a case study of about three APA pages on of an organization with a current resolution agreement, together with proposed corrective action plans. Resolution agreements are the settlements HHS's Office for Civil Rights reaches after HIPAA investigations; OCR posts each one with a press release and, usually, the full agreement, which lists the corrective action plan the organization must follow. The word current matters, so pick an agreement still in its monitoring period, typically two or three years from the announcement date. A good case study explains the organization, what happened, what OCR found, what the agreement requires and what you would add. With it, all four of the course's writing assignments are done.
Inside the HCR 264 Module 7 example
The sample opens with the organization and the breach, written from public sources, then explains what a resolution agreement is and what this one requires. A table matches each of OCR's three findings to the exact Security Rule standard, which makes the legal basis checkable. The analysis section argues that the phishing email was only the trigger and that the real problem was missing fundamentals, citing OCR's own statement about risk analysis. The corrective action plan appears as a table with an owner, evidence of completion and a timeline for each step, because that is how organizations actually report to OCR. A short lessons section turns the case into three questions any covered entity could ask, and the closing paragraph matches each step of the plan to a finding.
Reading the HCR 264 Module 7 grading rubric
The final paper is scored on a Canvas rubric within the course's 300 writing points. A case study earns its marks by choosing an agreement that is genuinely current, describing the organization and the incident accurately, explaining OCR's findings with reference to the specific HIPAA standards, analyzing why the failures happened and proposing a corrective plan whose steps match the findings, with owners and timelines. It loses marks when the case is old or outside its monitoring period, when the paper only retells the press release, when the HIPAA rule is described in general terms, when the plan is generic training and policy language and when the three-page limit is exceeded. Readers also check that the paper treats the agreement as a settlement, not a court finding.
HCR 264 Module 7 help with common mistakes
Start with OCR's list of resolution agreements and pick one announced within the last year or two. Read the press release and, if it is posted, the agreement itself, which spells out the corrective action plan. Look up each Security Rule or Privacy Rule standard OCR cites so you can explain it precisely. Write the corrective plan as a table with owners and evidence, since that is how real plans are tracked. Add at least one step OCR did not require but your analysis supports. Keep to three pages by letting tables carry the detail. If the agreement you want is not posted in full, the desk can help you find a case with a public plan.
Write yours, or have the desk draft it
This paper is an original model document written by our desk, not a submitted student paper and not an official Arizona State University document. Read it for the moves, then write your own to the instructions in your classroom. If you want one built to your exact prompt and rubric, the first custom sample is free and arrives in 24 to 48 hours.
More HCR 264 and BS in Health Care Compliance and Regulations sample papers
- HCR 264 Module 1: Short Topical Paper: Element 5, Enforcing Standards
- HCR 264 Module 3: Problem Solving Paper: An OIG Case Analysis
- HCR 264 Module 5: Root Cause Analysis: OSHA Incident Report and Five Whys
- HCR 363 Module 7: Assignment 7: Auditing, Monitoring and Mitigation Planning
- HCR 350 Module 4: Paper 4: Integrating Research Compliance Into the Corporate Compliance Program
- HCR 262 Module 1: Writing Assignment 1: Licensure Scenario and Work Plan
HCR 264 Module 7 questions, answered
Where can I find a free HCR 264 Module 7 sample paper?
This page reproduces a whole case study of the 2026 Ambry Genetics HIPAA resolution agreement.
What is a HIPAA resolution agreement?
A settlement with HHS's Office for Civil Rights in which an organization pays an amount and follows a monitored corrective action plan, without admitting liability.
What counts as a current resolution agreement for HCR 264?
One still in its monitoring period, usually two or three years after OCR announces it.
What does a HIPAA corrective action plan usually require?
A risk analysis, a risk management plan, updated policies, workforce training and reports to OCR during monitoring.
What did OCR find in the Ambry Genetics case?
No thorough risk analysis, no procedures to end access when it was no longer needed and no unique user identification.