CIS 450 Module 6 Legal and Ethical Issues in Health Data Example

Reviewed by Douglas Renshaw, MBA Aspen University Updated September 2026

This CIS 450 Module 6 sample paper examines legal and ethical issues in two composite decisions at a health system: sharing a de-identified data set with a technology company and adopting a commercial algorithm to select patients for care management. Aspen University's Informatics in Healthcare course, which addresses the legal and ethical implications of informatics, is the course behind it. HIPAA's two de-identification methods under 45 C.F.R. § 164.514 are explained, then challenged by evidence that 99.98% of Americans could be singled out using fifteen ordinary demographic details. An algorithm that predicted costs rather than illness, underestimating Black patients' needs, shows how bias enters. An issues table, the system's decisions, governance, consent models, security, research versus commercial use, patient communication and post-deployment monitoring complete the paper.

CourseCIS 450 Informatics in Healthcare
ModuleModule 6
Paper typeHealth data ethics paper
LengthAbout 1,013 words, 6 pages
FormatAPA 7 student paper
SchoolAspen University
ProgramHealth Care Administration
UpdatedSeptember 2026

Free sample paper for CIS 450 Module 6

1

Data, Consent and Fairness: Legal and Ethical Issues in Sharing and Using Health Data

Student Name

Health Care Administration Program, Aspen University

CIS 450: Informatics in Healthcare

Instructor Name

Month Day, Year

What this page is doingThe title names the three concerns the paper weighs. APA 7 student title page.
2

Data, Consent and Fairness: Legal and Ethical Issues in Sharing and Using Health Data

Health data have value beyond individual care: research, quality improvement, product development and prediction. Using them raises legal questions about privacy and ethical questions about consent, fairness and trust. This paper examines two decisions at a composite health system: whether to share a de-identified data set with a technology company, and whether to adopt a commercial algorithm to identify patients for care management.

Decision One: Sharing Data

A technology company offered to build a readmission prediction tool if the health system provided five years of de-identified patient records, in exchange for a discount on the finished product. Leaders asked whether this was legal, whether it was ethical and what safeguards were needed.

HIPAA De-Identification

Under the HIPAA Privacy Rule, 45 C.F.R. § 164.514, health information is considered de-identified, and outside the rule's protections, if either the safe harbor method is followed, removing 18 specified identifiers with no actual knowledge that the remaining information could identify someone, or a qualified expert concludes that identifying anyone from what remains is highly unlikely (U.S. Department of Health and Human Services, 2012). Properly de-identified data may be shared without patient authorization.

The Re-Identification Problem

Legal de-identification is not the same as anonymity. A modeling study concluded that fifteen ordinary demographic details would be enough to pick out almost every American in a data set, even one sampled heavily (Rocher et al., 2019). Rich clinical data sets combined with other data sources can therefore expose individuals even when names are removed.

What this page is doingContrasting legal de-identification with real-world re-identification risk shows why legal compliance alone does not settle the ethical question.
3

Ethical Questions in Sharing

Beyond legality, the system considered whether patients would reasonably expect their data to be shared with a company for profit, whether the benefits would return to patients and whether sharing would erode trust. Patients often accept research use for public benefit but object to commercial use without their knowledge.

Decision Two: A Risk Algorithm

A vendor offered an algorithm that ranks patients by predicted future health needs to select them for a care management program. Before adopting it, the health system's data team asked how it was built and whether it performed fairly across groups.

Algorithmic Bias

Algorithms can embed bias. Obermeyer and colleagues examined a popular commercial tool and showed that it scored Black patients as healthier than equally sick White patients; the tool forecast spending rather than sickness, and because less had historically been spent on Black patients, fixing the problem would have more than doubled their share of extra care (Obermeyer et al., 2019). The choice of what an algorithm predicts is an ethical choice.

Issues at a Glance

The table summarizes the issues.

IssueLegal dimensionEthical dimensionSafeguard
De-identificationSafe harbor or expert determinationRe-identification riskExpert review; data use agreement barring re-identification
Commercial usePermitted for de-identified dataPatient expectations and trustTransparency; community input
Benefit sharingContract termsFair return to patientsTool available to the system; public reporting
Algorithm biasCivil rights and anti-discrimination lawFairness across groupsAudit performance by race and other factors
TransparencyFew specific requirementsRespect for personsPublic notice of data uses

The System's Data Decision

The health system agreed to share data only under expert-determined de-identification, a data use agreement forbidding re-identification and linkage with other data sets, limits on retention and a commitment that the tool would be tested for fairness. It also posted a public notice describing the partnership and created a patient advisory group to review future data-sharing proposals.

The System's Algorithm Decision

The data team tested the vendor's algorithm on local data and found that Black and White patients given identical scores differed in illness burden, with Black patients carrying more chronic conditions. The system declined to use the algorithm as offered and asked the vendor to retrain it on a measure of illness rather than cost. Until then, care managers used a clinical criteria list reviewed for equity.

Governance

Both decisions led the system to create a data governance committee with clinical, legal, ethics, informatics and patient members. The committee reviews proposals for secondary data use and algorithm adoption against criteria for privacy, benefit, fairness and transparency, and it can require audits after deployment.

Consent Models

Some ethicists argue for broader consent, such as asking patients at registration whether their de-identified data may be used for research or product development. Others worry that consent forms are rarely read. The system chose transparency and governance, with an opt-out process for patients who do not want their data included in commercial partnerships.

Security as an Ethical Duty

Even properly governed data sets can be stolen. The data use agreement required the company to meet security standards, notify the health system of any breach and destroy the data at the end of the project. Security is an ethical obligation as well as a legal one, since patients bear the harm when data escape.

Research Versus Commercial Use

The committee distinguished academic research, reviewed by an institutional review board under research rules, from commercial product development, which may not receive the same oversight. It decided that commercial uses would require committee review even when the data met de-identification standards.

Explaining Data Use to Patients

The public notice explained in plain language what data would be shared, with whom, for what purpose and with what protections, and how to opt out. A short version appeared in the portal. Patients who understand data use are more likely to trust the organization, even if they choose to opt out.

Monitoring After Deployment

Fairness is not settled at purchase. The committee required quarterly reports of any adopted algorithm's performance by race, ethnicity, sex, age and insurance, with a process to pause use if disparities appear. Algorithms can drift as populations and practices change.

Conclusion

Sharing de-identified data may be legal under HIPAA's standards, but evidence that most people can be re-identified from a handful of attributes and that algorithms can encode racial bias shows that legality is not enough. Safeguards, transparency, fairness audits and governance with patient voices help health systems use data responsibly and keep patients' trust.

References

Obermeyer, Z., Powers, B., Vogeli, C., & Mullainathan, S. (2019). Dissecting racial bias in an algorithm used to manage the health of populations. Science, 366(6464), 447-453. https://doi.org/10.1126/science.aax2342

Rocher, L., Hendrickx, J. M., & de Montjoye, Y.-A. (2019). Estimating the success of re-identifications in incomplete datasets using generative models. Nature Communications, 10, Article 3069. https://doi.org/10.1038/s41467-019-10933-3

U.S. Department of Health and Human Services. (2012). Guidance regarding methods for de-identification of protected health information in accordance with the Health Insurance Portability and Accountability Act (HIPAA) Privacy Rule 45 CFR § 164.514. https://www.hhs.gov/hipaa/for-professionals/special-topics/de-identification/index.html

CIS 450 Module 6 instructions, in plain terms

Legal and ethical implications appear in Aspen's CIS 450 catalog description, and since Aspen shows each module's prompt only in the classroom, data sharing and algorithm fairness were chosen for this sample. Such prompts often present a health data scenario and ask you to analyze it, identify legal requirements and ethical concerns, and recommend safeguards. Check whether your prompt supplies the scenario. Keep legal duties and ethical duties in separate columns, because they often part ways. Use evidence on re-identification or algorithmic bias to show why legal compliance may not be enough. Propose governance, not just one-time decisions. Name the specific regulation you rely on, and quote its two methods accurately.

Inside the CIS 450 Module 6 example

This sample holds about 1,020 words across nineteen headings, with a five-row issues table. It presents the data-sharing decision, explains de-identification and the re-identification problem, then raises ethical questions. The algorithm decision and bias evidence follow, then the issues table. The system's two decisions, governance and consent models come next. Security as an ethical duty, research versus commercial use, explaining data use to patients and monitoring after deployment close the body. A note beside the re-identification section explains why legal compliance alone does not settle the ethical question. Each decision section explains what the system did and why, so readers see principles turned into policy. Monitoring closes the paper.

CIS 450 Module 6 rubric: what earns full marks

Health data ethics papers are commonly assessed on accurate law, ethical reasoning, use of evidence and practical safeguards. The HIPAA de-identification standard is described accurately with its regulation cited. Ethical reasoning addresses consent, benefit sharing, fairness and trust. Evidence from studies on re-identification and algorithmic bias is cited in APA form. Safeguards include data use agreements, fairness audits, transparency and a governance committee with patient members. Graders also reward ongoing monitoring, since fairness and privacy risks change after a decision is made. Explaining data use to patients shows respect for persons beyond legal minimums. Distinguishing research from commercial use shows awareness of different oversight systems. Security is treated as an ethical duty, not only a technical one.

CIS 450 Module 6 help: mistakes that cost marks

Students often treat HIPAA compliance as the end of the analysis. Show why ethics may require more. Another frequent gap is discussing bias in general terms without explaining how it arises, such as choosing cost as a proxy for need. Some papers also skip governance. Recommend who decides and how decisions are reviewed. Keep the scenario specific. For help separating legal from ethical issues, a tutor can go through your scenario with you and sort each concern into the right column. Explain the difference between safe harbor and expert determination. Describe what a data use agreement should forbid. Recommend fairness audits both before and after deployment. Include how patients can learn about data use and opt out, and mention research oversight where it applies.

Write yours, or have the desk draft it

This paper is an original model document written by our desk, not a submitted student paper and not an official Aspen University document. Read it for the moves, then write your own to the instructions in your classroom. If you want one built to your exact prompt and rubric, the first custom sample is free and arrives in 24 to 48 hours.

More CIS 450 and Health Care Administration sample papers

CIS 450 Module 6 questions, answered

What does CIS 450 Module 6 usually ask for?

Aspen's CIS 450 description includes legal and ethical implications of health care informatics, so a paper on issues in health data use is a typical assignment. Check your classroom prompt.

What are HIPAA's two de-identification methods?

Safe harbor, removing 18 specified identifiers, and expert determination that re-identification risk is very small.

How can an algorithm be racially biased?

If it predicts a proxy such as health care costs, unequal access can make one group appear healthier than it is at the same score.

Where can I find a free CIS 450 Module 6 sample paper?

The health data ethics paper, with both decisions and the issues table, is shown above. It is the sixth CIS 450 sample.

Why is de-identified data not always anonymous in CIS 450 Module 6?

Combinations of a few demographic attributes can single out individuals; one model estimated nearly all Americans could be re-identified from 15 attributes.