Every order is original, expert-done, and screened for AI — full report on request.See how it works

Assignment questions
Health Information ManagementReportHealth information security

Dominion National data breach analysis

The brief says explicitly that the link is not enough. The distinguishing fact about this breach — how long it went undetected — is in the primary sources, not the summary.

Editorial process

Last reviewed · August 15, 2026

01

A template with named components — follow it

The instruction to go beyond the linked article is the assignment's real constraint, and it is checkable. Go to the primary sources: the HHS Office for Civil Rights breach portal lists reported breaches with the covered entity, the number of individuals affected and the type of breach, and the organisation's own notification letters state what was accessed and what was offered to those affected. State attorney general notifications frequently contain detail the national coverage omits. Those give you facts rather than a summary of facts, and the difference is visible immediately in a synopsis. Treat the template as a checklist rather than as a suggested structure. Assignments built on a supplied template are marked against its components, and a well-written analysis that omits one of them loses the marks allocated to it regardless of how good the rest is. List the components before you start writing and tick them off at the end.

The feature of this breach that makes it worth a case study is the timeline. Unauthorised access persisted for a long period before discovery, which shifts the analysis away from how the intrusion happened and toward why nothing noticed — and that is the more interesting question and the one with transferable lessons. Detection is a different control from prevention: monitoring, log review, alerting on anomalous access, and having someone whose job is to look. Structure the analysis around the required security safeguards rather than around a narrative, since the administrative, physical and technical categories give you a framework a marker can follow and let you say which category failed. Then address consequences at the levels that actually differ: regulatory penalty, litigation, notification cost, and the harm to individuals, which for dental and health records is long-lived because the data cannot be reissued the way a card number can.

Likely learning objectives

Inferred from the brief — check these against your own rubric.

  • 01
    Locate primary sources for a reported health data breach.
  • 02
    Distinguish preventive from detective security controls.
  • 03
    Organise an analysis around the safeguard categories.
  • 04
    Assess consequences at regulatory, financial and individual levels.
Assignment instructionsQuoted verbatim

Read the full question

Review every instruction before using the planning guidance that follows.

2.Dominion National https://healthitsecurity.com/news/the-10-biggest-healthcare-data-breaches-of-2019-so-far (Please use template attached) The submission should include these components: Introduction/Synopsis This should summarize key details of the events that occurred. Yes, students must include information beyond what is provided in the above link and note “Wikipedia” is not a reliable source (but is a good starting point to gather general information). The grader will be looking for additional references beyond the course textbook and the provided link. Using the course textbook, discuss one major concept that you feel the selected organization did not “master” which eventually lead to the breach. Be sure to substantiate your response with additional external sources (if necessary). 400-700 word count no cover page necessary Summarize the selected event. Be sure to complete a google search on the selected story. This makes the introduction/summary have a more complete feel by getting different angles. This is the best chance to utilize additional resources outside of the course textbook. Textbook Connection/Link This is where the author should justify they have read the course textbook by linking the story selected to one major them in the course textbook. It should be “one major concept that you feel the selected organization did not “master” which eventually lead to the breach.” Be specific cite the specific chapter and page numbers from the course textbook. Closing Share personal thoughts and very briefly summarize what has been stated. Create page break and insert the APA compliant “references” section
Course-wide instructions that accompany this question

You must proofread your paper. But do not strictly rely on your computer’s spell-checker and grammar-checker; failure to do so indicates a lack of effort on your part and you can expect your grade to suffer accordingly. Papers with numerous misspelled words and grammatical mistakes will be penalized. Read over your paper – in silence and then aloud – before handing it in and make corrections as necessary. Often it is advantageous to have a friend proofread your paper for obvious errors. Handwritten corrections are preferable to uncorrected mistakes. Use a standard 10 to 12 point (10 to 12 characters per inch) typeface. Smaller or compressed type and papers with small margins or single-spacing are hard to read. It is better to let your essay run over the recommended number of pages than to try to compress it into fewer pages. Likewise, large type, large margins, large indentations, triple-spacing, increased leading (space between lines), increased kerning (space between letters), and any other such attempts at “padding” to increase the length of a paper are unacceptable, wasteful of trees, and will not fool your professor. The paper must be neatly formatted, double-spaced with a one-inch margin on the top, bottom, and sides of each page. When submitting hard copy, be sure to use white paper and print out using dark ink. If it is hard to read your essay, it will also be hard to follow your argument.

02

Turn the brief into deliverables

  1. 01
    A synopsis built from primary sources.
  2. 02
    The timeline, including time to detection.
  3. 03
    An analysis organised by safeguard category.
  4. 04
    Consequences at regulatory, litigation and individual levels.
  5. 05
    Every component the supplied template names.
03

Synopsis, analysis, then what should have happened

01

Synopsis

Summarise what happened, when, and to how many.

02

The detection gap

Establish how long access persisted and why it was not noticed.

03

Safeguards analysis

Assess administrative, physical and technical controls.

04

Consequences

Set out regulatory, financial and individual harm.

05

What should have been in place

Recommend the controls that would have shortened detection.

04

Primary sources for a breach, not news summaries

Recommended databases

  • HHS OCR breach portal
  • HHS breach notification guidance
  • State attorney general notification archives
  • PubMed Central

Search sequence

  1. 1.
    Look the breach up in the OCR portal for the reported figures.
  2. 2.
    Find the organisation's own notification letter for what was accessed.
  3. 3.
    Check state notification archives for additional detail.
  4. 4.
    Read the security rule's safeguard categories before structuring the analysis.
05

Reference shortlist

These are authoritative starting points, not a ready-made bibliography. A qualified reviewer must confirm that each source fits the assignment and supports the claim beside which it is cited.

Nothing here is cleared for citation until you have read it.

  1. 01

    Breach Portal — Office for Civil Rights

    Office for Civil Rights, US Department of Health and Human Services · 2026

    The federal breach portal, which is the primary record of what was reported and how many individuals were affected.

  2. 02

    Breach Notification Rule

    Office for Civil Rights, U.S. Department of Health and Human Services · 2026

    The breach notification rule, which sets out what an organisation is obliged to do and by when.

  3. 03

    Health Insurance Portability and Accountability Act (HIPAA) Compliance

    StatPearls, NCBI Bookshelf · 2023

    Covers the privacy and security requirements the safeguard analysis is organised around.

  4. 04

    Privacy, Security, and HIPAA

    HealthIT.gov, Office of the National Coordinator · 2024

    Federal guidance on security controls, including the detective controls this case turns on.

06

Review before submission

Common mistakes

  • Paraphrasing the linked article and adding nothing.
  • Focusing on how the intrusion happened rather than why it went unnoticed.
  • Writing a narrative instead of a framework-organised analysis.
  • Treating breach harm as equivalent to credit-card fraud.

Submission checklist

  • Have you used sources beyond the supplied link?
  • Is the time-to-detection stated?
  • Is the analysis organised by safeguard category?
  • Does the template's every component appear?

Use this guide to plan and review your own work. Follow your institution's rules and read our academic-integrity policy.

Written by

Aaron Bishop

MA, Education

assignment interpretation and research-methods coaching across disciplines

Aaron leads the EssayCrackers editorial desk. He works on how assignment briefs are read — what a rubric is actually asking for, and where students most often answer a different question than the one set.

Reviewed by

Dr. Nathan Cole

PhD, Rhetoric & Composition

Argumentation and thesis development

Nathan teaches first-year composition and directs a university writing center. He reviews EssayCrackers guides for argumentative soundness and citation accuracy.

Want feedback on your plan before you draft?

Get help interpreting the brief, checking your evidence strategy, and strengthening your outline while keeping the work your own.

Get assignment guidance
Start your order