Fundamentals of Nursing · Safety and Security

Security: Privacy and Informatics

10 min read
Educational draft: describes general US privacy and security principles (HIPAA) at an introductory level. Privacy laws differ by country and jurisdiction, and facility policies are often stricter than the legal minimum — verify locally. This is not legal advice.
Want it in plain words first? Jump to Eli explains — the same idea, no jargon.
On this page 9 sections
  1. In 30 seconds
  2. Why this matters
  3. The college version
  4. Eli explains
  5. Worked example
  6. Key takeaway
  7. Check yourself
  8. Study tools
  9. Sources & references

In 30 seconds

Patients share some of the most sensitive information a person can reveal: symptoms, diagnoses, test results, medications, and life details they may not even discuss with family. That information is essential to care — but it is also vulnerable. This topic covers the three ideas that protect it — , , and — and the computer systems, collectively called informatics, through which most health information now flows.

The three ideas are related but distinct. Privacy is the patient's right to decide who may know their health information. Confidentiality is the professional duty to keep that information protected once it has been shared in the course of care. Security is the set of technical, physical, and administrative safeguards — passwords, locked screens, encrypted networks, audit trails — that make confidentiality actually work. Informatics is the field of using information technology to collect, store, retrieve, and use health data: the electronic health record (), computerized provider order entry (), barcode medication administration, telehealth, and patient portals.

In the United States, the Health Insurance Portability and Accountability Act () is the central legal framework governing health information privacy and security. Other countries have their own laws (for example, the EU's General Data Protection Regulation), and facilities often adopt policies stricter than the legal minimum. Because nurses document, retrieve, and discuss patient information every shift, understanding what is protected, who may see it, and how to protect it is a core part of safe nursing practice.

Why this matters

  • Trust: Patients will not share honestly with the care team if they believe their information could be exposed. Privacy is the foundation of a therapeutic relationship.
  • Legal and ethical: Breaching confidentiality can carry penalties for both individuals and organizations, and confidentiality is a standing commitment in nursing codes of ethics.
  • Safety: Accurate, current, accessible information prevents errors — but insecure systems create new risks: data breaches, identity theft, and wrong-patient documentation.
  • Professional behavior: "Chart stalking" (opening records out of curiosity), discussing patients in hallways, and sharing passwords are all privacy violations, and audit trails can detect them.
  • Exams: Privacy, security, and informatics concepts appear regularly on nursing licensure exams, usually as "what should the nurse do" scenarios.

The college version

Core Concepts

Privacy, confidentiality, and security are three different things

Remember the relationship this way: privacy is the promise (the patient's right to control access), confidentiality is the duty (the professional's obligation to protect information disclosed during care), and security is the lock (the safeguards that keep information from being accessed, altered, lost, or stolen).

PHI and the HIPAA framework

Protected health information (PHI) is any information — in any form, paper, electronic, or spoken — that relates to a person's health, treatment, or payment and that can identify the person (name, birth date, medical record number, and so on). Almost everything a nurse documents is PHI.

HIPAA (a US law) has two rules that matter most in practice:

  • The Privacy Rule sets standards for how PHI may be used and disclosed. It gives patients rights: to access their own records, request corrections, receive a notice of privacy practices, and receive an accounting of certain disclosures. It also establishes the standard — use or disclose only the smallest amount of information needed for the task.
  • The Security Rule requires safeguards for electronic PHI: unique user IDs, audit controls (logs of who viewed what), transmission security (encryption), and contingency plans.

HIPAA applies to covered entities — health plans, healthcare clearinghouses, and providers who transmit health information electronically — plus their business associates (for example, billing or transcription companies) through contracts. It does not apply to everyone who happens to hold health information, and it is not the only privacy law that exists. Nurses should follow the stricter of the law, the professional code, and facility policy.

Informatics: the systems nurses use every day

  • Electronic health record (EHR): the legal record of care. It supports continuity — information travels with the patient across shifts, units, and facilities — and makes information searchable and analyzable.
  • Computerized provider order entry (CPOE): providers enter orders directly into the system instead of writing them by hand, which removes transcription errors and can trigger decision support (allergy warnings, dose checks).
  • Barcode medication administration (BCMA): scanning the patient's wristband and the medication packaging verifies the "rights" of medication administration before the drug is given.
  • Clinical decision support: alerts, reminders, and evidence links embedded in the record that flag problems such as allergies or drug interactions.
  • Patient portals: patients can view parts of their own record, message the care team, and manage appointments, which supports engagement and self-management.
  • Telehealth: care delivered at a distance, which extends access but adds privacy considerations for video and data transmission.

Informatics brings benefits and new risks. Data-entry errors, alert fatigue (so many warnings that clinicians start ignoring them), wrong-patient selection from a drop-down list, and security breaches are all real. Technology assists — it does not replace the nurse's verification and judgment.

Security measures in everyday practice

  • Authentication: unique user IDs and strong passwords. Passwords are never shared, never written on sticky notes, and never borrowed.
  • Automatic lock: workstations time out after inactivity. Locking the screen before stepping away, even for a moment, is a habit.
  • Positioning: monitors are turned away from hallways, waiting areas, and doors so casual passersby cannot read them.
  • Physical safeguards: identification badges, locked offices and supply areas, and restricted areas.
  • Encryption: data is scrambled so it is unreadable if intercepted.
  • Audit trails: the system records who opened which record and when. This is how unauthorized viewing is detected — and why "just looking" is a documented, discoverable act.
  • response: a breach is any unauthorized acquisition, access, use, or disclosure of PHI. Suspected breaches are reported promptly per facility policy — never concealed.

The nurse's role: protecting information at the bedside

  • Verify before revealing. Before releasing any information — to a caller, a visitor, or even another staff member — confirm the person's identity and their need to know. Do not confirm or deny a patient's presence to a caller without following the facility's verification process.
  • Keep conversations private. Discuss patient matters in private spaces, in low voices. Be mindful of hallways, elevators, and waiting rooms.
  • Protect the screen and paper. Log off or lock workstations, position monitors away from public view, and do not leave printed reports with identifiers lying around.
  • Share the minimum. Give only the information needed, to people involved in the patient's care. Family members generally receive information only with the patient's permission; a patient can also restrict all sharing ("confidential" status).
  • Document professionally. The record is a legal document: accurate, objective, timely. Never write negative opinions about patients or colleagues.

How It Works: Handling a Request for Information

  1. Stop and identify the requester. Who is asking — a patient, a family member, a colleague, a caller? What do they claim to need?
  2. Check authorization. Does the patient have capacity and has the patient authorized sharing with this person? Is the requester actually involved in the patient's care? Facility policy defines the process.
  3. Apply minimum necessary. Share only the smallest amount of information that accomplishes the legitimate purpose.
  4. Choose a safe channel. Private conversation, secure messaging, the patient portal — not a hallway, not an unsecured text, not a public voicemail.
  5. Document the interaction if required (per facility policy, e.g., for certain disclosures).
  6. If anything is uncertain, decline and escalate. "I'll check with the charge nurse / privacy officer" is a complete, professional answer.

Common Confusions

Do Not ConfuseWithDifference
PrivacyConfidentialityPrivacy is the patient's right to control information; confidentiality is the professional's duty to protect it
ConfidentialitySecurityConfidentiality is the obligation; security is the locks, passwords, and policies that fulfill it
"HIPAA applies to anyone with health information"HIPAA applies to covered entities and their business associatesPeople outside those categories are not bound by HIPAA, though other laws, ethics codes, and policies still apply
"Family can always get information"Family access requires the patient's permission (or legal authority)The patient decides who receives their information; a patient can restrict all sharing
"If it's in the EHR, it's fine to look"Viewing requires a work-related needCuriosity viewing ("chart stalking") is a violation even though the system technically allows access
"The EHR is always accurate"The EHR contains human-entered dataErrors still occur; nurses verify identity and information and correct the record properly
Eli, the EliExplains learning guide

Eli explains

The same idea, in plain words

Explain it like I’m 10

Your health information is like a locked diary. Only the people who need to read it to help you — your nurse, your doctor, your pharmacist — may open it, and only the pages they need. The hospital uses passwords, locked screens, and a log of who opens the diary, and if someone peeks who should not have, the hospital has to tell you. Everyone who touches the diary promises to keep it secret.

Worked example

The phone rings at the nurses' station. "Hi, this is Mr. Chen's brother. Is he still admitted? How is he doing?" Nurse Maya does not confirm or deny anything. She explains that she cannot give out information over the phone without verifying the caller's identity and Mr. Chen's permission, and she offers to check whether Mr. Chen has authorized sharing with family. Before walking away, she locks her workstation — her screen shows Mr. Chen's name and room — and she positions the monitor away from the hallway. Later, an off-duty colleague asks, "So what happened with that new admission?" Maya declines: her colleague is not involved in the patient's care, and curiosity is not a reason to access or discuss PHI. Each of these small actions applies privacy, confidentiality, security, and the minimum-necessary rule in real time.

Key takeaways

  • PHI is any identifiable health information in any form — paper, electronic, or spoken.
  • Privacy = patient's right; confidentiality = professional's duty; security = the safeguards that enforce both.
  • HIPAA Privacy Rule governs use and disclosure and grants patient rights (access, amendment, notice, accounting); HIPAA Security Rule governs safeguards for electronic PHI.
  • Minimum necessary: use only the information needed for the task.
  • Never share passwords; lock screens when leaving a workstation; verify identity before releasing information.
  • "Chart stalking" is a violation — records are opened only for work-related need, and audit trails track access.
  • Report suspected breaches immediately per facility policy; concealing a breach makes it worse.
  • HIPAA is US-specific. Other jurisdictions have different laws, and facility policy may be stricter than the legal minimum.

Check yourself

6 review questions from the chapter. Try each one, then open the answer.

  1. What are privacy, confidentiality, and security, and how do they differ?

    Show answer

    Privacy is the patient's right to control access to their health information; confidentiality is the professional duty to protect it; security is the technical, physical, and administrative safeguards that make protection possible.

  2. What information counts as PHI?

    Show answer

    Any identifiable health information in any form — name, birth date, medical record number, diagnosis, treatment, and payment information, whether spoken, written, or electronic.

  3. A caller asks whether a patient is admitted. What should the nurse do first?

    Show answer

    Do not confirm or deny. Verify the caller's identity and the patient's authorization following facility policy before releasing any information.

  4. What does "minimum necessary" mean, and when does it apply?

    Show answer

    Using only the smallest amount of information needed to accomplish the task; it applies to every use and disclosure of PHI.

  5. Why must a nurse lock the workstation before stepping away from it?

    Show answer

    To prevent unauthorized access by anyone passing by. Automatic locks exist for the same reason — leaving a screen open exposes PHI.

  6. What should a nurse do after discovering a possible breach of patient information?

    Show answer

    Report it immediately to the appropriate person (charge nurse, manager, or privacy officer) per facility policy — never ignore or conceal a breach.

Keep learning

Ready to build on this? Continue to the next lesson.

Study tools & related lessonsKey vocabulary · Related

Key vocabulary

Privacy
The patient's right to control who knows their health information
Confidentiality
The professional duty to protect information shared during care
Security
The technical, physical, and administrative safeguards that protect information
PHI (protected health information)
Identifiable health information in any form
HIPAA
US law setting privacy and security standards for health information
Minimum necessary
Using only the smallest amount of information needed for the task
EHR
Electronic health record — the digital legal record of care
CPOE
Computerized provider order entry — orders entered directly into the system
Audit trail
A system log of who accessed which record and when
Breach
Unauthorized acquisition, access, use, or disclosure of PHI
Covered entity
A provider, health plan, or clearinghouse that must comply with HIPAA

Sources & references

  1. openstax.org — Fundamentals Nursing

This lesson was adapted from the open educational references above; their licenses and attributions are preserved. See Copyright & Licensing.

Educational content only. It is not medical, legal or professional advice. Found an error? Tell us.