Chapter 4 Part I — Foundations of Nursing Informatics
Ethics, Law, Privacy, Confidentiality, and Informatics Governance
The ethical, legal, privacy, and governance structures that shape what healthcare information systems may do and what they should do.
Chapter Orientation
Digital health makes information powerful because it can be copied, linked, searched, analyzed, transmitted, and reused at scale. Those same properties create risk. A bedside conversation may affect one encounter; a poorly governed data feed can expose thousands of records. An algorithm can standardize decisions across an enterprise, including its mistakes.
The informatics nurse does not replace privacy officers, attorneys, compliance teams, or cybersecurity professionals. The informatics role is to understand enough of these domains to recognize risk, translate consequences into clinical workflow, and ensure that governance decisions can actually be implemented in the system.
This chapter separates several ideas that are commonly blurred together: privacy, confidentiality, security, ethics, legality, and governance. They overlap, but they are not synonyms.
Learning Objectives
By the end of this chapter, you should be able to:
- Distinguish privacy, confidentiality, security, ethics, law, and governance.
- Explain core HIPAA concepts relevant to informatics workflow and system design.
- Describe the special handling implications of 42 CFR Part 2 for substance use disorder records.
- Explain information blocking and the tension between access and protection.
- Apply ethical reasoning to secondary use, AI, surveillance, and data sharing.
- Describe practical data-governance structures and decision rights.
- Identify when an informatics issue requires escalation to privacy, compliance, legal, or security experts.
Lesson 4.1 — Privacy, Confidentiality, Security, Ethics, and Law Are Different Questions
-
Privacy concerns the person’s interests and rights in how information about them is collected, used, accessed, and shared. Privacy asks whether an organization should have or use information for a particular purpose and what choices or protections the person has.
-
Confidentiality concerns the obligations of people and organizations that receive sensitive information. A nurse who learns a diagnosis through care has a duty not to disclose it improperly. Confidentiality is relational: the information is entrusted within a professional or organizational context.
-
Security concerns safeguards that protect information and systems from unauthorized access, alteration, loss, or disruption. Access control, encryption, backups, logging, patching, and network protections are security mechanisms. A system can be secure yet still support an ethically questionable use of data; security does not answer whether the use is appropriate.
-
Law establishes enforceable requirements, but legality is not the whole ethical analysis. A data use may be legally permissible and still create unnecessary surveillance, inequity, or loss of trust. Conversely, a desirable clinical use may require legal or consent mechanisms that are not yet in place.
-
Governance determines who gets to make these decisions and how they are reviewed. Good governance defines decision rights, standards, escalation paths, documentation, monitoring, and accountability. Without governance, ethics and compliance are handled inconsistently at the project level.
| Question | Primary concept |
|---|---|
| Should we collect this information at all? | Privacy / ethics |
| Who may see it? | Confidentiality / privacy / access governance |
| How do we prevent unauthorized access? | Security |
| Is the use permitted by applicable law and regulation? | Legal/compliance |
| Who decides and documents the rule? | Governance |
Clinical Example
Clinical Example — Employee Access to Their Own Record
An employee who is also a patient asks a coworker with EHR access to open the chart and print a result. The information belongs to the employee as a patient, but the coworker’s workforce access is governed by organizational policy and role-based authorization. Patient access rights and employee system permissions are not the same pathway. Informatics should help ensure the EHR supports appropriate patient access without encouraging staff to bypass governed workflows.
NI-BC Connection: Foundations of Practice — legal issues; security, privacy, confidentiality; ethical practice.
Retrieval Checkpoint
Retrieval Checkpoint
- How does privacy differ from security?
- Give an example of a use that could be secure but ethically questionable.
- Why does a patient’s right to information not automatically authorize any employee to access it through workforce credentials?
- What does governance add beyond legal compliance?
Lesson 4.2 — HIPAA in Informatics Practice: Think in Workflows, Not Acronyms
-
HIPAA is operationalized through workflows and system controls. The Privacy Rule, Security Rule, and Breach Notification Rule affect how organizations use and disclose protected health information, control access, safeguard electronic PHI, and respond to incidents. Informatics work turns those obligations into roles, access models, audit trails, disclosure workflows, interface controls, and user behavior.
-
HIPAA’s minimum-necessary standard is a design consideration, but it has important exceptions. The Privacy Rule generally requires reasonable limits on uses, disclosures, and requests for PHI when the standard applies, while disclosures to or requests by a health care provider for treatment are among the exceptions. Internally, covered entities still establish role-based access policies based on workforce duties. Informatics teams should therefore avoid treating “minimum necessary” as a blanket rule for every clinical exchange while still designing access that reflects legitimate job functions and does not encourage unsafe workarounds.
-
Auditability matters because healthcare access is distributed. EHRs allow thousands of legitimate users to access sensitive information for different reasons. Logging does not prevent every inappropriate access, but it creates accountability and supports investigation. Informaticists should understand what events are logged, how long logs are retained, and whether workflows bypass auditable systems.
-
Business associate relationships matter when data leave the organization. A vendor that creates, receives, maintains, or transmits PHI on behalf of a covered entity may require a Business Associate Agreement depending on the relationship and service. Informatics teams should not treat procurement paperwork as separate from technical design; the architecture determines where data flow and which vendors touch them.
-
Current HIPAA requirements must be verified rather than remembered from old training. Privacy and security rules evolve through rulemaking and court decisions. As of September 2026, the existing HIPAA Security Rule remains in effect while HHS’s Security Rule modernization remains a proposed rule. Informatics documentation should distinguish current requirements, final rules with compliance dates, guidance, and proposals rather than treating them as interchangeable.
AI in Practice
AI in Practice — “HIPAA-Compliant AI” Is Not a Product Label You Can Accept at Face Value
Determine the exact service, contract, configuration, data retention, enabled features, subprocessors, and BAA coverage. A vendor may offer some HIPAA-eligible products while other features are outside the BAA. The correct question is not “Is this company HIPAA compliant?” but “Is this specific workflow, using this specific service configuration, covered and governed appropriately?”
[!CAUTION] Regulatory Currency
Do not operationalize a proposed rule as though it were final. Track proposed changes separately, identify likely implementation impact, and update controls only when legal/compliance leadership confirms the applicable requirement.
NI-BC Connection: Foundations of Practice — HIPAA, security/privacy/confidentiality, policy and procedures.
Retrieval Checkpoint
Retrieval Checkpoint
- Why should minimum necessary be considered during system design?
- What does audit logging contribute that access control alone cannot?
- How can technical architecture affect business-associate analysis?
- What questions should you ask before allowing PHI into an AI service?
- Why must proposed regulations be clearly separated from final requirements?
Lesson 4.3 — Sensitive Data, 42 CFR Part 2, Consent, and Context
-
Some information has additional legal or ethical sensitivity beyond ordinary clinical data. Substance use disorder treatment records subject to 42 CFR Part 2 are a major U.S. example. Other sensitive categories may be affected by state law, organizational policy, age, reproductive health context, genetic information, behavioral health, or legal circumstances. Informatics cannot assume one universal access rule is sufficient.
-
The 2024 Part 2 Final Rule aligned several aspects of Part 2 more closely with HIPAA while preserving important protections. Compliance with the updated rule was required by February 16, 2026. The changes affect consent, treatment/payment/operations uses, breach notification, patient rights, and restrictions on use of Part 2 records in legal proceedings. The practical informatics challenge is ensuring consent, segmentation, redisclosure, and workflow rules are reflected correctly in systems and exchange processes.
-
Consent is not a checkbox if the system cannot operationalize its scope. A consent may authorize specific purposes, recipients, categories, or time periods. If downstream systems cannot represent or honor those distinctions, the organization has a governance and technical problem. Capturing consent without enforcing it creates false assurance.
-
Data segmentation remains difficult because clinical information is intertwined. A note can contain substance use information, mental health information, medications, social context, and general medical history. Segmenting at document, field, or encounter level can be technically and clinically complicated. Over-segmentation may hide information needed for safe care; under-segmentation may expose protected information.
Clinical Example
Clinical Example — Behavioral Health Interface
A health system sends encounter summaries to an external care-management vendor. The interface was originally designed for general medical encounters. When behavioral-health services are added, the informatics team must determine whether the feed contains Part 2-protected data, whether the recipient and purpose are authorized, how consent is represented, and what happens when one document mixes protected and non-protected information. “The interface already exists” does not answer any of those questions.
NI-BC Connection: Foundations of Practice — legal issues, privacy/confidentiality, policy review.
Retrieval Checkpoint
Retrieval Checkpoint
- Why can sensitive-data rules vary within the same patient record?
- What changed conceptually in the 2024 Part 2 Final Rule?
- Why is capturing consent insufficient if systems cannot enforce its scope?
- What clinical risk can arise from over-segmenting sensitive information?
Lesson 4.4 — Information Blocking, Access, and the Ethics of Friction
-
Information protection and information access are both safety concerns. Restricting information can protect privacy, but unnecessary barriers can delay care, frustrate patients, and interfere with continuity. U.S. information-blocking rules under the 21st Century Cures Act reflect a policy direction toward preventing practices that unreasonably interfere with access, exchange, or use of electronic health information when required conditions are met.
-
A technically possible exchange is not automatically appropriate, and a difficult exchange is not automatically prohibited. Informatics teams need to understand applicable exceptions, organizational policy, legal obligations, technical feasibility, security, and the requested purpose. Complex cases require legal/compliance interpretation rather than improvised bedside rules.
-
Friction can be protective or obstructive. Reauthentication for a high-risk action may be justified friction. Requiring multiple phone calls to obtain data that should be electronically available may be obstructive friction. Good system design distinguishes deliberate safety barriers from legacy inconvenience.
-
Patient access changes the audience for clinical information. Notes, results, and messages may be visible to patients more quickly and directly than in older models. Informatics design must support clarity, release workflows, proxy access, identity verification, and respectful documentation without treating patient access as an afterthought.
Informatics in Practice
Informatics in Practice — Do Not Solve Legal Ambiguity With Configuration Alone
When a team asks you to hide, release, segment, or block information for legal reasons, document the requested rule and obtain the appropriate legal/privacy interpretation before building it. Informatics translates an approved rule into the system; it should not silently become the source of law.
NI-BC Connection: Foundations of Practice — 21st Century Cures Act, legal issues, privacy, professional policy.
Retrieval Checkpoint
Retrieval Checkpoint
- Why can excessive information restriction create patient-safety risk?
- What is the difference between protective friction and obstructive friction?
- Why should informatics avoid inventing legal interpretations through configuration decisions?
- How does direct patient access change documentation and portal design?
Lesson 4.5 — Ethical Reasoning for Secondary Use, Surveillance, and AI
-
Secondary use means data are used for a purpose beyond the immediate care transaction that created them. Quality improvement, research, operations, workforce analytics, product development, and AI training can all involve secondary use. Some uses are beneficial and permissible; others may exceed patient expectations or create new risks. Ethical review asks whether the use is necessary, proportionate, transparent, and governed.
-
Scale changes the ethical stakes. A poorly worded note affects a chart. A biased rule embedded in a system can affect every patient screened by that system. An AI model trained on historical documentation can reproduce past documentation biases at high speed. Informatics governance must therefore consider not just whether an individual output is acceptable but what happens when the behavior is repeated across a population.
-
Surveillance can emerge from ordinary operational data. Badge data, login timestamps, message response times, device location, documentation cadence, and keystroke patterns can be used to improve operations or monitor employees. The same dataset can support legitimate safety analysis or invasive performance surveillance. Ethical use depends on purpose, proportionality, transparency, and governance.
-
Bias is not limited to an algorithm’s mathematics. Bias can enter through who receives care, who gets documented, which variables are available, how labels are defined, which outcomes are optimized, and how users act on recommendations. Fairness analysis therefore begins before model training and continues through workflow and monitoring.
-
Human oversight must be meaningful rather than ceremonial. If a clinician is expected to “review” hundreds of AI outputs under severe time pressure, the presence of a human does not guarantee safe oversight. Governance should define what the human can realistically detect, override, and escalate.
AI in Practice
AI in Practice — The Five Questions Before Reusing Data
Before using clinical or operational data with an AI system, ask: What is the purpose? What data are actually necessary? What environment will process them? Who may access the output? How will errors or harmful inferences be detected and corrected? If those answers are unclear, prompting technique is not the main problem; governance is.
NI-BC Connection: Foundations of Practice — ethical practices related to data informatics solutions.
Retrieval Checkpoint
Retrieval Checkpoint
- What makes secondary use ethically different from the original care use?
- How does scale change the risk of a biased digital rule?
- Give an example of operational data that could become employee surveillance data.
- Why is “human in the loop” insufficient unless the human has realistic capacity and authority?
- Where can bias enter before an algorithm is trained?
Lesson 4.6 — Data Governance and Decision Rights
-
Data governance is the organizational system for deciding what data mean, who is accountable for them, how they may be used, and how quality is maintained. It is not the same as database administration. Governance establishes definitions, ownership/stewardship, access principles, quality expectations, escalation paths, and approval processes.
-
Ownership is often a poor word for shared clinical data; stewardship is more useful. No single department “owns” a blood pressure value in the ordinary sense. Clinical operations may define workflow, informatics may define representation, analytics may use the value, IT may host the systems, and compliance may constrain disclosure. A steward is accountable for maintaining meaning and appropriate use without implying exclusive control.
-
Decision rights should be explicit. Who can approve a new assessment? Who can change a clinical term? Who authorizes a data feed? Who decides whether an enterprise definition may have local exceptions? When these rules are unclear, governance happens through escalation, persistence, or whoever controls configuration access.
-
Good governance is proportionate. Requiring a committee vote for every display preference paralyzes the organization; allowing high-risk data changes through informal tickets creates inconsistency. Mature governance tiers decisions by risk, scope, reversibility, and impact.
Figure
Figure 4.1 — A Practical Data-Governance Decision Model
Visual structure: Request → classify by data sensitivity/scope/risk → identify steward → technical/privacy/security review as needed → decision authority → implementation → audit/monitoring.
Alt text: Governance pathway routing data requests based on sensitivity and risk to appropriate stewards and reviewers before implementation.
NI-BC Connection: Foundations of Practice — policy/procedure relevance, ethical practice; System Design Lifecycle — change governance.
Retrieval Checkpoint
Retrieval Checkpoint
- How does data governance differ from database administration?
- Why can stewardship be more useful than ownership for clinical data?
- What happens when decision rights are not explicit?
- How should governance intensity change with risk and scope?
Chapter Case Study — The AI Policy Assistant
A health system wants to deploy an enterprise AI assistant that allows employees to ask questions about clinical and operational policies. The vendor can index policy documents and generate conversational answers with citations. Leadership wants the assistant available to all employees within three months.
The initial design indexes the entire document repository. During review, informatics discovers that the repository contains draft policies, retired procedures, committee minutes, human-resources documents, and several documents that reference patient cases. Some documents have inconsistent effective dates. The vendor offers a healthcare enterprise contract and says its product can support HIPAA-compliant use under specified configurations, but one optional web-browsing feature is outside the organization’s approved configuration.
Nursing leaders are enthusiastic because staff often cannot find policies during care. Compliance is concerned that the model could answer from retired content. Security asks whether prompts and outputs are logged. Human resources does not want personnel documents available to clinical staff. The project sponsor argues that access controls will make the system too complex and delay launch.
Analyze the case
- Identify the privacy, confidentiality, security, legal/compliance, ethical, and governance questions separately.
- What data-governance work must occur before model quality can even be evaluated?
- Which content should be excluded, segmented, or remediated before indexing?
- What would meaningful human oversight look like for this use case?
- What should be logged, and who should be able to review logs?
- How would you test whether the assistant cites current authoritative policy rather than plausible but outdated text?
- What decision rights should be established for adding, retiring, and updating source documents after go-live?
Chapter Synthesis
- Privacy, confidentiality, security, legality, ethics, and governance answer different questions. Mature informatics practice knows when each lens is required.
- HIPAA becomes real through architecture and workflow. Access controls, auditability, vendor relationships, and data flows are where policy turns into system behavior.
- Sensitive information may require more granular rules. Part 2 illustrates why one access model cannot always govern the entire record.
- Access and protection must be balanced deliberately. Unnecessary barriers can be harmful, while uncontrolled exchange can violate trust and law.
- Scale magnifies ethical consequences. Secondary use, surveillance, and AI require governance because digital actions repeat rapidly across people and populations.
- Governance creates decision discipline. It defines who decides, what evidence is required, and how high-risk changes are monitored.
Key Terminology
- Privacy
- Individual interests and rights concerning collection, access, use, and disclosure of information.
- Confidentiality
- Duty to protect information entrusted within a professional or organizational relationship.
- Security
- Administrative, physical, and technical safeguards that protect information and systems.
- Protected health information (PHI)
- Individually identifiable health information protected under HIPAA when held or transmitted by covered entities or business associates, subject to regulatory definitions and exceptions.
- Business Associate Agreement (BAA)
- Contractual arrangement required in applicable HIPAA business-associate relationships defining permitted uses and safeguards for PHI.
- 42 CFR Part 2
- Federal regulations protecting confidentiality of certain substance use disorder patient records.
- Information blocking
- Practices by covered actors that are likely to interfere with access, exchange, or use of electronic health information and meet applicable regulatory conditions, subject to exceptions.
- Secondary use
- Use of data for a purpose beyond the immediate transaction or care process that created them.
- Data stewardship
- Accountability for the quality, meaning, access, and appropriate use of data within governance structures.
- Decision rights
- Explicit authority to make or approve specified organizational decisions.
NI-BC Chapter Mapping
| Domain | Blueprint area | Lessons | Depth |
|---|---|---|---|
| I. Foundations | Regulatory, reimbursement, accreditation context | 4.2–4.4 | Reinforced |
| I. Foundations | Legal issues | 4.1–4.4 | Applied |
| I. Foundations | HIPAA, security, privacy, confidentiality, Cures Act | 4.2–4.4 | Applied |
| I. Foundations | Ethical practices related to data solutions | 4.1, 4.5 | Applied |
| I. Foundations | Crafting/reviewing policies | 4.6 | Applied |
| II. Lifecycle | Basic change governance | 4.6 | Introduced |
Chapter Quiz
Answer each question, then select “Check answer” to reveal feedback. For Select All That Apply items, choose every correct option before checking. Expand “Why?” after checking to read the rationale.
Which statement best distinguishes privacy from security?
Why?
Privacy concerns appropriate collection, use, access, and disclosure; security concerns safeguards against unauthorized access, alteration, loss, or disruption.
A vendor states its AI platform is “HIPAA compliant.” What is the best next step?
Why?
HIPAA suitability depends on the specific service, agreement, configuration, data handling, enabled features, and workflow. A vendor-wide marketing claim is insufficient.
Which are relevant to minimum-necessary system design?Select all that apply
Why?
Minimum-necessary design considers role, job function, information needed, legitimate exceptions, and the risk of unsafe workarounds from over-restriction. Convenience alone does not justify broad access.
What is the strongest reason to preserve audit logs even when role-based access is implemented?
Why?
Access controls determine what credentials are allowed to do; logs help establish what those credentials actually did and support accountability and investigation.
Which statement about 42 CFR Part 2 is most accurate in 2026?
Why?
The 2024 Part 2 Final Rule aligned several provisions more closely with HIPAA while retaining Part 2 protections; compliance with the updated rule was required February 16, 2026.
Which questions belong in ethical review of secondary data use?Select all that apply
Why?
Ethical secondary-use review considers necessity, proportionality, access, harmful inference, transparency, and governance. Mere availability of data does not make a use appropriate.
An employee productivity dashboard uses badge location and message response times. Which concern is most directly implicated beyond technical security?
Why?
Badge location and response-time data can become workforce surveillance even when collected through technically secure systems; proportionality and purpose therefore matter.
Which is the best example of meaningful human oversight for an AI system?
Why?
Oversight is meaningful only when a qualified person has sufficient time, information, authority, and escalation pathways to evaluate consequential outputs.
Effective data governance should define:Select all that apply
Why?
Governance should define stewardship, meaning, access, decision authority, quality expectations, and escalation rather than leaving these implicit.
A leader asks informatics to hide certain records because of a legal concern. What is the best response?
Why?
Informatics should implement an approved legal/privacy interpretation, not silently create legal policy through configuration. —
References and Further Reading
- American Nurses Association. (2025). Code of Ethics for Nurses. ANA. https://www.nursingworld.org/nurses-books/Code-of-ethics-2025/
- American Nurses Association. (2022). Nursing Informatics: Scope and Standards of Practice (3rd ed.). ANA. https://www.nursingworld.org/nurses-books/nursing-informatics-scope-and-standards-of-practi/
- U.S. Department of Health and Human Services, Office for Civil Rights. HIPAA for Professionals. https://www.hhs.gov/hipaa/for-professionals/
- U.S. Department of Health and Human Services, Office for Civil Rights. Minimum Necessary Requirement. https://www.hhs.gov/hipaa/for-professionals/privacy/guidance/minimum-necessary-requirement/
- U.S. Department of Health and Human Services. (2024). Confidentiality of Substance Use Disorder (SUD) Patient Records: Final Rule. Compliance date February 16, 2026. https://www.hhs.gov/hipaa/part-2/
- Assistant Secretary for Technology Policy / Office of the National Coordinator for Health Information Technology. Information Blocking. https://healthit.gov/information-blocking
- Assistant Secretary for Technology Policy / Office of the National Coordinator for Health Information Technology. Information Blocking Exceptions. https://healthit.gov/resources/information-blocking-exceptions/
- Autio, C., Schwartz, R., Dunietz, J., Jain, S., Stanley, M., Tabassi, E., Hall, P., & Roberts, K. (2024). Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile (NIST AI 600-1). National Institute of Standards and Technology. https://doi.org/10.6028/NIST.AI.600-1