| Course | D911 Transforming Healthcare Through Technology |
|---|---|
| Task | Task 1 |
| Paper type | Health IT strategy evaluation |
| Length | About 1,100 words, 4 pages |
| Format | APA 7 |
| School | Western Governors University (WGU) |
| Program | Master of Healthcare Administration |
| Updated | September 2026 |
Free sample paper for D911 Task 1
Leaving the Basement Data Center: Evaluating a Composite Health System's Plan to Move Its EHR to Vendor-Hosted Cloud Service, With Cybersecurity and HIPAA Weighed Against Cost and Uptime
Student Name
Leavitt School of Health, Western Governors University
D911: Transforming Healthcare Through Technology, Task 1
Course Instructor
Month Day, Year
Leaving the Basement Data Center: Evaluating a Composite Health System's Plan to Move Its EHR to Vendor-Hosted Cloud Service, With Cybersecurity and HIPAA Weighed Against Cost and Uptime
The Decision
Northwoods Health, a composite health system, runs three hospitals and 30 clinics. Its electronic health record (EHR) runs on servers in the system's own data center, in the basement of its largest hospital. The hardware is due for replacement at an estimated cost of $6.8 million, and the system experienced four unplanned EHR outages last year totaling 19 hours. The EHR vendor offers a hosting service in which the vendor runs the system in its own cloud data centers. The chief information officer has proposed moving to the hosted service when the hardware contract ends. This paper evaluates that strategy against the system's goals for patient care, operational efficiency and regulatory compliance, gives particular attention to cybersecurity and recommends how leaders should proceed.
Evaluation Against Organizational Goals
Patient care. Clinicians need the EHR to be available every minute of every day. The vendor's hosting service offers redundant data centers in separate regions, round-the-clock monitoring and a contractual uptime commitment higher than Northwoods has achieved on its own. Fewer outages mean fewer delayed medication orders and fewer paper downtime workflows. The main new risk to availability is the network: once the EHR is hosted elsewhere, a broken internet connection at a hospital has the same effect as a server failure. The strategy therefore depends on redundant network connections from different carriers at every hospital.
Operational efficiency. Hosting replaces a large capital purchase every six to seven years with a predictable annual fee. Northwoods's finance team estimates the hosted service at $1.9 million a year, compared with $1.4 million a year in current data center operating costs plus about $1.0 million a year when the hardware refresh is spread over seven years. The financial case is modest rather than dramatic. The larger benefit is people: the system's small infrastructure team could shift from maintaining servers to supporting clinical applications, and software upgrades, which now take months of internal testing on local hardware, would be handled by the vendor.
Regulatory compliance. Moving the EHR does not move the system's HIPAA obligations. A cloud service provider that creates, receives, maintains or transmits electronic protected health information for a covered entity is a business associate, even if it only stores encrypted data, and the covered entity must have a business associate agreement with it and include the arrangement in its own security risk analysis (U.S. Department of Health and Human Services [HHS], n.d.). Northwoods will remain responsible for who in its workforce can access records, for reviewing audit logs and for notifying patients if a breach occurs, so the contract must require the vendor to report security incidents promptly and to support investigations.
Cybersecurity: Threats and Controls
Ransomware is the threat that matters most. From 2016 to 2021, ransomware attacks on U.S. health care delivery organizations more than doubled, exposed the protected health information of nearly 42 million patients and disrupted care in almost half of cases, most often through electronic system downtime (Neprash et al., 2022). The same study found that attacks increasingly affected large, multi-facility organizations and were less likely over time to be resolved by restoring from backups (Neprash et al., 2022). Northwoods, with a security team of three people, is poorly placed to defend a data center against that threat alone, and a large hosting vendor can afford continuous monitoring and specialized staff that the system cannot.
Hosting also concentrates risk. When one vendor serves hundreds of organizations, an attack on that vendor affects all of them at once. The 2024 cyberattack on Change Healthcare, a national claims processing company, showed how far such an event can reach: the Centers for Medicare & Medicaid Services distributed $3.3 billion in relief to providers whose revenue was disrupted, including $2.2 billion to hospitals (Neprash et al., 2025). That attack struck a clearinghouse rather than an EHR host, but the lesson applies: dependence on a single outside provider must be planned for, not assumed away.
The controls that follow from these threats are specific. The vendor should provide independent security attestations each year and permit Northwoods to review them. Multifactor authentication should be required for every user, and privileged access should be limited and logged. Backups should include copies that cannot be altered or deleted by an attacker, and Northwoods should keep its own read-only copy of essential patient information on local downtime computers in every hospital. Finally, the system's downtime procedures, which currently assume an outage of hours, should be rewritten and tested for an outage of days.
Workflow and Training
For most clinicians, the change should be nearly invisible, since they will use the same EHR through the same screens. The effects fall mainly on information technology staff, whose roles will shift from hardware to application support and vendor management, and on the downtime procedures described above. Staff will need training on new downtime workflows, and the IT team will need training in managing a vendor relationship with measurable service levels.
Recommendation
I recommend that Northwoods proceed with the move to vendor-hosted service, subject to six conditions written into the contract and project plan: a business associate agreement that requires notification of security incidents within 24 hours and cooperation with any investigation; annual independent security attestations; redundant network connections at every hospital before go-live; backup copies that cannot be altered by an attacker, plus local read-only downtime access to essential records; a joint incident response exercise with the vendor each year; and an exit plan guaranteeing the return of all data in a usable format if the contract ends. With these conditions, the move improves availability and security for a system that cannot match a large vendor's defenses on its own, while keeping the system's compliance obligations and its ability to keep caring for patients during an outage in its own hands.
Conclusion
Moving the EHR to vendor-hosted service is less a technology decision than a risk decision. Northwoods would trade the risks it manages poorly, aging hardware and a thin security team, for the risk of depending on one outside provider. The evaluation shows that trade is worthwhile only if the contract, the network and the downtime plan are built to survive the day the vendor is the one under attack.
References
Neprash, H. T., Beebe, T. J., Yost, G., & Carroll, C. (2025). Lessons from CMS relief funding after cyberattack on Change Healthcare. Health Affairs, 44(12), 1466-1472. https://doi.org/10.1377/hlthaff.2025.00990
Neprash, H. T., McGlave, C. C., Cross, D. A., Virnig, B. A., Puskarich, M. A., Huling, J. D., Rozenshtein, A. Z., & Nikpay, S. S. (2022). Trends in ransomware attacks on US hospitals, clinics, and other health care delivery organizations, 2016-2021. JAMA Health Forum, 3(12), e224873. https://doi.org/10.1001/jamahealthforum.2022.4873
U.S. Department of Health and Human Services. (n.d.). Guidance on HIPAA & cloud computing. Retrieved September 29, 2026, from https://www.hhs.gov/hipaa/for-professionals/special-topics/health-information-technology/cloud-computing/index.html
What the D911 Task 1 instructions ask
The first D911 task asks you to evaluate a health information technology strategy for an organization. Expect to describe the strategy and decision, evaluate it against organizational goals, analyze cybersecurity threats and controls, address legal and regulatory requirements, consider workflow and training effects and make a recommendation. The organization may be supplied or composite. Graders look for benefits and risks weighed together, cybersecurity analyzed with evidence rather than general warnings, HIPAA requirements described accurately and a recommendation with conditions that address the risks found. An evaluation that promotes the technology without examining its risks will fall short of the evaluation aspects. Consider costs over several years, not just the first.
How this D911 Task 1 example is built
The evaluation opens with the organization, its current system and the decision it faces. Each organizational goal gets its own paragraph, showing how the move helps and what new risks it adds. The cybersecurity section describes the main threat with national evidence, then explains how hosting strengthens some defenses while concentrating risk in one vendor. The legal section explains HIPAA duties that apply to the vendor relationship. Workflow effects are described for clinicians and for information technology staff separately, since the change affects them differently. The recommendation proceeds only under conditions, each tied to a risk found earlier. Sources include national studies of ransomware in health care and federal guidance on security.
Where the D911 Task 1 rubric puts the marks
D911 Task 1 aspects are scored competent, approaching competence or not evident. A strategy aspect checks that the technology and decision are described clearly. A goals aspect rewards evaluation against specific organizational aims. A cybersecurity aspect looks for threats and controls supported by evidence. A legal aspect asks for accurate regulatory requirements. A workflow aspect wants effects on staff and training. A recommendation aspect looks for a justified decision with conditions. Graders notice when risks shape the recommendation, and they expect current research and federal guidance to be cited where security and law are discussed. Conditions tied to each risk show that the recommendation is considered.
D911 Task 1 help: what sends it back
Technology evaluations come back most often when they read like vendor brochures. Weigh the risks as carefully as the benefits. Second, cybersecurity is described in general terms. Name the main threat, show evidence of its scale and describe specific controls. Third, legal requirements are misstated. Explain what a business associate agreement requires and what the organization still owns. Fourth, workflow effects are skipped. Say who will notice the change and what training they need. Finally, attach conditions to the recommendation, since leaders need to know what must be true before they sign. Consider the cost of doing nothing, since aging hardware and thin staffing carry risks of their own. Describe the exit plan if the vendor relationship ends. Cite current evidence, because threats and federal guidance change quickly, and older sources can mislead leaders.
Get a D911 Task 1 example written to your instructions
Send the task instructions and rubric aspects from your D911 course of study. We write a custom health IT strategy evaluation to those exact aspects, returned in 24-48h. The first custom sample is free.
Other Healthcare admin sample papers
- AFT2 Task 2 Sentinel Event Root Cause Analysis
- D776 Task 1 Sociopolitical Drivers Analysis
- D548 Task 1 Hospital Emergency Response Plan
- AFT2 Task 1 Compliance Audit Action Plan
D911 Task 1 questions, answered
Must D911 cover cloud hosting?
No. Choose a technology strategy your instructions allow. The sample uses vendor-hosted EHR service because it raises clear questions about cost, uptime, security and law. Explain the decision the organization faces.
What is a business associate agreement in D911?
A contract HIPAA requires when a vendor handles protected health information for a covered organization. It sets out how the vendor must safeguard data and report breaches.
How should D911 Task 1 treat cybersecurity?
Name the main threat, support it with evidence and describe controls. The sample explains how hosting strengthens some defenses while concentrating risk in one vendor. Tie each control to a specific threat.
Is the D911 health system real?
No. Northwoods Health is hypothetical. The research on ransomware attacks against hospitals and the federal security guidance cited are real. Use your course scenario and current evidence for your own evaluation of the strategy.
Where can I find a free D911 Task 1 sample paper?
The cloud hosting evaluation is printed in full above with reviewer notes. Describe the D911 strategy you must assess, and your first custom paper is written free.