For one compromised billing mailbox at a composite practice, the HI575 Unit 7 plan orders containment, a four-factor assessment and notification decisions, each assigned to a named role and logged. Searches like "hi 575 unit 7 assignment example", "hi575 unit 7 sample" and "hi575 unit 7 example" land here.
What a finished HI575 Unit 7 incident response plan looks like
The document has two parts across seven pages. The first is the standing plan: an incident response team of five named roles, severity levels defined by data involved and operations affected, a contact sheet held on paper as well as online, and a decision log template. The second applies it to the mailbox. A timeline table runs from the email provider's sign-in alert on day nine to containment within two hours: sessions ended, password reset, the forwarding rule exported as evidence and then removed, external forwarding blocked across the domain. The assessment section counts [412] forwarded messages, identifies [96] carrying patient information and applies the four breach factors to them. Notification decisions follow, with the regulatory clock stated from the discovery date. The plan cites NIST SP 800-61 once, for its phase vocabulary, and names the revision used.
How a HI575 Unit 7 example is structured
The standing plan precedes the incident so a reader sees which decisions were made in advance and which were made under pressure. Roles come first because an incident without an owner stalls in its first hour. The applied section then moves in the order events demanded rather than the order a template lists: detect, contain, preserve, assess, decide, notify, review. Containment is written as specific actions with times, and evidence preservation sits beside it, since deleting the forwarding rule without exporting it would destroy what the assessment needs. The four-factor assessment is set out message category by message category rather than as one verdict. Notification decisions cite the discovery date as the start of the clock and record who decided. A short post-incident section names two changes, domain-wide forwarding blocks and alerts routed to a monitored queue, with the date each is verified.
Roles fixed before anything happens
Five incident roles, severity levels tied to data and operations, and a contact sheet kept on paper for the day email itself is the problem.
Nine days, then two hours
The provider's sign-in alert, the forwarding rule found, and a timed list of containment actions with the evidence exported before anything was deleted.
What the forwarded mail held
[412] messages sorted into remittance files, claim attachments, scheduling notes and ordinary correspondence, with the count of individuals in each group left in brackets.
Four factors, group by group
What kind of information each group held, the identity of the recipient, any sign the messages were opened, and what mitigation achieved, weighed separately for every category.
Clock, decisions and review
Notification timing counted from the discovery date, the privacy officer's recorded decisions, and two changes verified on stated dates afterward.
Where marks go in HI575 Unit 7
Plans that treat the incident as a technical fault and stop at the password reset forfeit the largest share, because the unit is usually asking what happened to the information, not only to the account. Assuming breach, or assuming no breach, without the four-factor assessment costs nearly as much; graders expect the reasoning written down for each group of messages. Evidence destroyed during containment is a quieter error with serious consequences, since a deleted forwarding rule cannot later show when it was created. Notification deadlines counted from the wrong date draw direct comments. Named roles and timestamps outscore narrative in most rubrics. A plan citing a framework without applying it reads as decoration, and one that describes attacker technique in detail strays outside what the assignment assesses. Missing post-incident changes leave the plan ending where it began.
Get a HI575 Unit 7 example written to your instructions
Incident prompts differ mostly in the event they describe. Pass along yours, with the Unit 7 instructions and the rubric, and a custom plan will order the response to that event, from containing it through deciding who must be told, with roles and times filled in. The first sample is free, and turnaround is 24-48h.
HI575 Unit 7 questions, answered
When does the breach notification clock start?
At discovery, which the rule treats as the first day the incident is known or would have been known with reasonable diligence. The example counts from the day the sign-in alert was read, and notes that nine unnoticed days could be argued either way. Stating the date chosen and the reason gives a grader something to check rather than an assumed deadline.
Does every incident involving patient data require notification?
No. The rule treats an impermissible use or disclosure as a breach by default, and only a written risk assessment finding little probability of compromise rebuts that presumption. The example applies that assessment to each message group and reaches different conclusions for remittance files and routine scheduling notes. What graders want to see is the reasoning recorded, whatever the conclusion turns out to be.
How much should the plan say about the attack itself?
Enough to explain the containment and the assessment, and no more. The example states that credentials were phished and a forwarding rule was added, because those facts decide what to remove and what was exposed. Step-by-step technique adds nothing an incident response grader looks for, and it drags the paper toward method when the rubric is scoring decisions.