| Course | D190 Introduction to Healthcare IT Systems |
|---|---|
| Task | Task 1 |
| Paper type | Privacy breach response plan |
| Length | About 1,200 words, 6 pages |
| Format | APA 7 |
| School | Western Governors University (WGU) |
| Program | BS Health Information Management |
| Updated | September 2026 |
Free sample paper for D190 Task 1
Sixty-Four Addresses in the CC Line: Determining the Scope of and Responding to a Misdirected Group Email at a Composite Outpatient Recovery Clinic
Student Name
Leavitt School of Health, Western Governors University
D190: Introduction to Healthcare IT Systems, Task 1
Course Instructor
Month Day, Year
Sixty-Four Addresses in the CC Line: Determining the Scope of and Responding to a Misdirected Group Email at a Composite Outpatient Recovery Clinic
The Incident
Clearwater Behavioral Health is a composite outpatient clinic that provides counseling and medication treatment for opioid use disorder. It runs a weekly family recovery support group. On a Tuesday afternoon, the peer support coordinator sent a reminder that the group would meet in a different room. The subject line read "Opioid Recovery Family Group moved to Room B," and the coordinator entered all 64 recipients in the CC field rather than the BCC field. Every recipient could therefore see every other recipient's email address, and many addresses contain full names. Within an hour, one recipient replied to all asking to be removed from the list. The next morning a patient called the clinic manager, upset that her neighbor now knew she was in treatment. The manager notified the privacy officer, who opened an incident file.
Why This Involves Protected Health Information
An email address alone is not usually health information. Here, however, each address appears in a message whose subject line and sender identify it as belonging to a participant in an opioid recovery group at a treatment clinic. Linking an individual's identity to the fact that they or their family member receives substance use disorder treatment makes the disclosure protected health information under HIPAA. It also involves records protected by 42 CFR Part 2, the federal rule that gives substance use disorder treatment records stronger confidentiality protection, because the clinic is a federally assisted treatment program and the email reveals that specific people are in its program.
Determining the Scope
Before deciding whether the incident is a reportable breach, the privacy officer must establish exactly what was disclosed, to whom and how far it may have spread. The plan uses six steps.
First, preserve the evidence. The sent message, the recipient list and the reply-all message are saved to the incident file, and the email administrator exports the message logs before automatic deletion. Second, classify every recipient. The HIM department matches each address to the clinic's records to determine how many belong to current or former patients, how many to family members, and whether any address was entered incorrectly and belongs to someone with no connection to the clinic. The match found 41 patients and 23 family members; one patient's address had been mistyped and delivered the message to an unknown external account. Third, determine what each recipient saw: the names and addresses of all 64 recipients and the subject line linking them to opioid treatment. No clinical notes or attachments were included. Fourth, check for further spread by asking the email administrator whether the message was forwarded from within the clinic's system and by reviewing replies. Fifth, check whether this was an isolated event by auditing the coordinator's sent messages for the past 90 days; two earlier reminders had been sent correctly with BCC. Sixth, interview the coordinator to understand how the error occurred.
Risk Assessment
Under the HIPAA Breach Notification Rule, an impermissible use or disclosure of protected health information counts as a breach by default; the organization can rebut that presumption only by documenting a risk assessment concluding that the chance of compromise is low. HHS lists at least four factors that such an assessment has to weigh (U.S. Department of Health and Human Services [HHS], n.d.).
What the information was and how much of it: names and email addresses linked to opioid use disorder treatment. Although no clinical detail was disclosed, the fact of treatment is among the most sensitive information a person has, with risks to employment, relationships and legal matters. The unauthorized recipients: other patients and family members, who are not covered entities and have no legal duty to keep the information confidential, plus one unknown external account. Whether anyone in fact opened and read it: yes, as shown by the reply-all message and the patient's call about her neighbor. The extent of mitigation: the clinic can ask recipients to delete the message, but it cannot confirm deletion or prevent recipients from remembering what they saw.
Taken together, the factors do not support a finding of low probability of compromise. The incident is a reportable breach.
Notification
Individuals. The 41 patients whose participation was disclosed must be told in writing, promptly and never more than 60 days after the clinic learned of the breach (HHS, n.d.). The clinic will send letters by first-class mail within 10 days. Each letter will describe what happened in plain language, what information was involved, what the clinic is doing and what the individual can do, and will give a contact for questions. Because the family members' addresses also revealed that a relative is in treatment, the letters will go to each affected patient, and the clinic will contact family members through the patient's preferred method rather than by email.
HHS. Because fewer than 500 individuals were affected, the clinic will record the incident in its breach log and file it with HHS through the online breach portal within 60 days after the calendar year ends. A breach affecting 500 or more residents of a state would also require notice to prominent media outlets, which does not apply here.
Part 2 and state law. A 2024 final rule revising 42 CFR Part 2 applied the HIPAA breach notification requirements to breaches of Part 2 records, aligning the two rules (HHS, 2024). The clinic's privacy officer will also check the state's breach notification and health privacy laws, which may set shorter deadlines or require notice to the state attorney general.
Corrective Actions
Correcting the cause matters more than correcting the coordinator. The clinic will stop using ordinary email for group communications and move reminders to the patient portal or a messaging tool that sends each message individually. The email system will be configured to warn any sender who places more than five external addresses in the To or CC fields. Subject lines for patient communications will be neutral, such as "Thursday group update," so that no message reveals treatment in its first line. All staff will complete training on privacy for substance use disorder records within 30 days. Training is needed across the organization, not only for one employee: in focus groups with behavioral health providers from treatment organizations in 14 states, confusion about the rules for releasing substance use disorder information under HIPAA, Part 2 and state law was widespread (Kaiser et al., 2026). The coordinator will be counseled under the clinic's sanctions policy, which treats an unintentional first error differently from a deliberate disclosure. Finally, the privacy officer will audit group communications monthly for six months and report results to the compliance committee.
Conclusion
A single wrong field in an email turned a room change into a breach of highly sensitive information. By first determining scope with evidence, then applying the four-factor risk assessment, the clinic reached a defensible decision to notify, met its deadlines under HIPAA and Part 2, and changed the tools and habits that made the error possible.
References
Kaiser, M., Wei, M., Nookala, S. P., Cooper, R., Ariosto, D., Adams, C., Grando, A., Sadeghi, M., & Murcko, A. C. (2026). Beyond fax: Provider perspectives on data sharing in substance use disorder care. JAMIA Open, 9(4), ooag162. https://doi.org/10.1093/jamiaopen/ooag162
U.S. Department of Health and Human Services. (2024). Fact sheet 42 CFR Part 2 final rule. https://www.hhs.gov/hipaa/for-professionals/regulatory-initiatives/fact-sheet-42-cfr-part-2-final-rule/index.html
U.S. Department of Health and Human Services. (n.d.). Breach notification rule. Retrieved September 29, 2026, from https://www.hhs.gov/hipaa/for-professionals/breach-notification/index.html
What the D190 Task 1 instructions ask
The first D190 task asks you to respond to a privacy incident using federal rules. You will usually decide whether the information involved is protected health information, determine the scope of the disclosure, assess the risk of compromise under the Breach Notification Rule, describe the notifications required and their timing, and recommend corrective actions. The incident may be supplied or composite. Evaluators look for each step taken in the order the rule requires, the four risk factors applied to the facts rather than listed, notification deadlines stated correctly and corrections that fix the cause. Treating every disclosure as automatically reportable, or skipping the risk assessment, is a common error. Sensitive treatment information, such as substance use care, calls for particular care and should be recognized as such.
How this D190 Task 1 example is built
The plan opens with the incident told plainly: who sent what to whom and how it was discovered. The next section explains why the email addresses count as protected health information in this context. Scope is established before any decision, including how many recipients and patients were involved and whether the message was forwarded. The risk assessment walks through the nature of the information, the recipients, whether it was viewed and how far the risk was reduced. Notification lists each audience with its deadline and content. Corrective actions replace ordinary group email with a secure tool and retrain staff. The conclusion links the small mistake to its large consequence. Deadlines are listed beside each audience.
Where the D190 Task 1 rubric puts the marks
D190 Task 1 aspects are rated competent, approaching competence or not evident. A PHI aspect checks that the information is correctly identified as protected. A scope aspect rewards facts established before conclusions. A risk assessment aspect looks for the four factors applied to this incident. A notification aspect asks for the right audiences, timing and content. A corrective action aspect wants changes that prevent recurrence. Evaluators check regulatory details closely, such as the sixty-day limit and the threshold for notifying the media, and they expect the federal rule and guidance to be cited. Responses that treat the event as a process failure rather than an individual's fault tend to earn full credit.
D190 Task 1 help: what sends it back
Breach response papers come back most often because the risk assessment is skipped or reduced to a sentence. Apply each factor to the facts of the case. Second, notification timing is misstated. Check the deadlines for individuals, the federal regulator and the media. Third, the scope is assumed rather than determined. Say how the privacy officer confirmed who received the email. Fourth, corrective actions punish a person without fixing the process. Change the tool or workflow that allowed the error. Finally, remember the sensitivity of the information. Disclosing that someone receives addiction treatment carries real harm, and your plan should reflect that in its tone and its urgency.
Get a D190 Task 1 example written to your instructions
Send the task scenario and rubric aspects from your D190 course of study. We write a custom privacy breach response plan to those exact aspects, returned in 24-48h. The first custom sample is free.
More D190 papers
Other Health information sample papers
- C813 Task 1 Health Data Statistics and Ethics
- C801 Task 2 HIM Ethics Presentation
- C807 Task 2 Corporate Compliance Program
- C802 Task 2 HIM Needs Assessment and Vendor Plan
D190 Task 1 questions, answered
Is every impermissible disclosure a breach in D190?
Not automatically. The rule treats an unauthorized disclosure as a breach unless a written four-factor assessment shows the chance of compromise is low. The sample documents that assessment for the clinic's email.
When must individuals be notified in D190?
The rule allows no more than 60 days from discovery and expects faster action where possible. The sample schedules letters well inside that limit and lists what each must contain.
Why is an email address protected health information in D190?
Because it appears in a message that reveals the person receives treatment at a specific clinic. Combined with that context, the address identifies a patient and their care.
Is the D190 recovery clinic in the sample real?
No. Clearwater Behavioral Health and its patients are hypothetical. The Breach Notification Rule and federal guidance applied in the plan are real and cited. Its patients are not real people.
Where can I find a free D190 Task 1 sample paper?
You are on it: the D190 Task 1 privacy breach response plan appears in full above, with comments tied to the D190 rubric. A free first D190 draft built on your own Task 1 details is available once you send the instructions.