Three Years of Falls and a Spreadsheet With Names: Privacy, Security, and Data Governance for the Secondary Use of Nursing Data
Student Name
Master of Science in Nursing Program, Aspen University
N537: Health Care Informatics
Instructor Name
Month Day, Year
Three Years of Falls and a Spreadsheet With Names: Privacy, Security, and Data Governance for the Secondary Use of Nursing Data
Electronic health records hold years of nursing data that could answer important questions about quality and safety. Using those data for purposes other than the care of the individual patient, called secondary use, raises questions of privacy, security, and governance. This paper analyzes a composite request from a nurse researcher for fall data from a hospital's record, applies federal privacy rules and security principles, and describes the data governance decisions needed to answer the request responsibly.
The Request
A doctorally prepared nurse at a composite 300-bed hospital plans to study whether falls increased after the hospital changed its nurse staffing model. She asks the informatics team for a spreadsheet of every inpatient fall over three years, with patient names, medical record numbers, dates of birth, admission and fall dates and times, units, fall risk scores, medications, and the nurses assigned. She says the project is quality improvement and should not need review, and she wants the file emailed to her personal account so she can work from home.
Privacy: What the Rules Require
Federal privacy rules allow use of protected health information without patient authorization for treatment, payment, and health care operations, which include quality improvement activities. Research, defined as a systematic investigation designed to contribute to generalizable knowledge, is treated differently: using identifiable information for research generally requires patient authorization or a waiver approved by an institutional review board or privacy board. Whether the nurse's project is quality improvement or research therefore matters. A study comparing outcomes before and after a staffing change, intended for publication, is likely research and should be reviewed by the institutional review board, which can decide whether a waiver of authorization is appropriate.
The minimum necessary standard applies to most uses: only the information needed for the purpose should be disclosed. The nurse's question does not require names, medical record numbers, or full dates of birth. Two options fit better. A de-identified data set removes the identifiers specified in the rules, such as names, record numbers, and most dates. A limited data set may retain dates and some geographic information, which the study needs for timing, but excludes direct identifiers and requires a data use agreement that restricts how the data may be used and prohibits re-identification. The question can be answered without knowing who fell; the request should be reshaped to fit the question, not the other way around.
The Nurses in the Data
The request also includes the names of assigned nurses. Staff identities are not protected health information, but including them raises ethical and employment concerns: nurses might fear that research data will be used for discipline, which could discourage honest reporting of falls in the future. Unless the study requires individual nurse identities, which a staffing-model comparison does not, nurse identifiers should be replaced with unit and shift.
Security: How the Data Move
Emailing the file to a personal account would move sensitive data outside the organization's control, where it could be exposed through a compromised account or lost device. Security safeguards should include storing the data set on an encrypted, access-controlled research server, granting access only to approved study team members, logging access, and prohibiting downloads to personal devices. Even a limited data set carries a risk of re-identification when dates and units are combined with outside information, so it deserves the same protection as identifiable data.
Governance: Who Decides and What the Data Mean
Data governance is the set of decisions, roles, and processes that determine how an organization's data are managed and used. Rosenbaum (2010) describes data stewardship as a responsibility that extends beyond legal compliance to the ethical management of data on behalf of the people they describe, and argues that stewardship entities should balance the value of data access against the protection of those individuals. In practice, the hospital needs a data governance committee that includes nursing, informatics, privacy, and research representatives to review requests, a named data steward for nursing quality data, and written definitions of key measures.
Definitions matter for the study's validity. Hripcsak and Albers (2013) caution that electronic record data are complex, often inaccurate or missing, and reflect the processes of care as well as the patient's condition. A fall recorded in the incident reporting system may not appear in the nursing flowsheet, and a change in the staffing model may have coincided with a change in how falls were documented. The data steward should provide the researcher with the definition used, the source systems, and known data quality problems, so that an apparent increase in falls is not an artifact of documentation. A shared data quality vocabulary helps here: the steward can report whether fall records conform to expected formats and value ranges, whether the fields the study needs are complete across all three years, and whether values are plausible, for example whether falls are recorded at times when the patient was documented as off the unit (Kahn et al., 2016). Reporting these checks with the data set lets the researcher describe the data's limits honestly in the eventual publication.
A Responsible Response
The informatics team should thank the researcher for a valuable question and explain the path forward: take the protocol to the review board first, request a limited data set with a data use agreement or a de-identified set if dates can be shifted, replace nurse names with unit and shift, work on the secure research server, and meet with the data steward to understand the fall definitions and sources. This response supports the research while protecting patients, staff, and the organization.
Conclusion
A single request for fall data shows how privacy, security, and governance work together. Privacy rules determine whether the use is permitted and how much information may be shared; security controls determine how the data are protected; and governance determines who decides, what the data mean, and whether the answer will be valid. Nurse leaders and informaticists who understand all three can make the organization's data useful without betraying the trust of the people it describes.
References
Hripcsak, G., & Albers, D. J. (2013). Next-generation phenotyping of electronic health records. Journal of the American Medical Informatics Association, 20(1), 117-121. https://doi.org/10.1136/amiajnl-2012-001145
Kahn, M. G., Callahan, T. J., Barnard, J., Bauck, A. E., Brown, J., Davidson, B. N., Estiri, H., Goerg, C., Holve, E., Johnson, S. G., Liaw, S.-T., Hamilton-Lopez, M., Meeker, D., Ong, T. C., Ryan, P., Shang, N., Weiskopf, N. G., Weng, C., Zozus, M. N., & Schilling, L. (2016). A harmonized data quality assessment terminology and framework for the secondary use of electronic health record data. eGEMs, 4(1), Article 18. https://doi.org/10.13063/2327-9214.1244
Rosenbaum, S. (2010). Data governance and stewardship: Designing data stewardship entities and advancing data access. Health Services Research, 45(5, Pt. 2), 1442-1455. https://doi.org/10.1111/j.1475-6773.2010.01140.x
How this N 537 Module 6 example is structured
N537's later middle modules commonly cover privacy, security and data governance. Aspen does not publish module deliverables, so check your classroom for the exact prompt. This example applies each concept to one data request, explains the rules and safeguards accurately, adds governance roles and data validity and closes with a constructive response.
N537 Module 6 questions, answered
What does N537 Module 6 usually ask for?
The module commonly covers privacy, security and data governance, often asking you to apply them to a data use or breach scenario in health care. Aspen does not publish module deliverables, so your classroom's instructions govern.
What is the difference between a de-identified and a limited data set?
A de-identified data set removes specified identifiers, including names, record numbers and most dates. A limited data set removes direct identifiers but may keep dates and some geographic data, and it requires a data use agreement that restricts use and prohibits re-identification.
What is data governance?
The decisions, roles and processes that determine how an organization's data are defined, managed, protected and used, including who approves requests, who stewards each data domain and how data quality is monitored.
Write yours, or have the desk draft it
This paper is an original model document written by our desk, not a submitted student paper and not an official Aspen University document. Read it for the moves, then write your own to the instructions in your classroom. If you want one built to your exact prompt and rubric, the first custom sample is free and arrives in 24 to 48 hours.