Fundamentals of Nursing · Safety and Security
Security: Privacy and Informatics
On this page 9 sections
In 30 seconds
Patients share some of the most sensitive information a person can reveal: symptoms, diagnoses, test results, medications, and life details they may not even discuss with family. That information is essential to care — but it is also vulnerable. This topic covers the three ideas that protect it — Privacy The patient's right to control who knows their health information Full entry →, Confidentiality The professional duty to protect information shared during care Full entry →, and Security The technical, physical, and administrative safeguards that protect information Full entry → — and the computer systems, collectively called informatics, through which most health information now flows.
The three ideas are related but distinct. Privacy is the patient's right to decide who may know their health information. Confidentiality is the professional duty to keep that information protected once it has been shared in the course of care. Security is the set of technical, physical, and administrative safeguards — passwords, locked screens, encrypted networks, audit trails — that make confidentiality actually work. Informatics is the field of using information technology to collect, store, retrieve, and use health data: the electronic health record (EHR Electronic health record — the digital legal record of care Full entry →), computerized provider order entry (CPOE Computerized provider order entry — orders entered directly into the system Full entry →), barcode medication administration, telehealth, and patient portals.
In the United States, the Health Insurance Portability and Accountability Act (HIPAA US law setting privacy and security standards for health information Full entry →) is the central legal framework governing health information privacy and security. Other countries have their own laws (for example, the EU's General Data Protection Regulation), and facilities often adopt policies stricter than the legal minimum. Because nurses document, retrieve, and discuss patient information every shift, understanding what is protected, who may see it, and how to protect it is a core part of safe nursing practice.
Why this matters
- Trust: Patients will not share honestly with the care team if they believe their information could be exposed. Privacy is the foundation of a therapeutic relationship.
- Legal and ethical: Breaching confidentiality can carry penalties for both individuals and organizations, and confidentiality is a standing commitment in nursing codes of ethics.
- Safety: Accurate, current, accessible information prevents errors — but insecure systems create new risks: data breaches, identity theft, and wrong-patient documentation.
- Professional behavior: "Chart stalking" (opening records out of curiosity), discussing patients in hallways, and sharing passwords are all privacy violations, and audit trails can detect them.
- Exams: Privacy, security, and informatics concepts appear regularly on nursing licensure exams, usually as "what should the nurse do" scenarios.
The college version
Core Concepts
Privacy, confidentiality, and security are three different things
Remember the relationship this way: privacy is the promise (the patient's right to control access), confidentiality is the duty (the professional's obligation to protect information disclosed during care), and security is the lock (the safeguards that keep information from being accessed, altered, lost, or stolen).
PHI and the HIPAA framework
Protected health information (PHI) is any information — in any form, paper, electronic, or spoken — that relates to a person's health, treatment, or payment and that can identify the person (name, birth date, medical record number, and so on). Almost everything a nurse documents is PHI.
HIPAA (a US law) has two rules that matter most in practice:
- The Privacy Rule sets standards for how PHI may be used and disclosed. It gives patients rights: to access their own records, request corrections, receive a notice of privacy practices, and receive an accounting of certain disclosures. It also establishes the Minimum necessary Using only the smallest amount of information needed for the task Full entry → standard — use or disclose only the smallest amount of information needed for the task.
- The Security Rule requires safeguards for electronic PHI: unique user IDs, audit controls (logs of who viewed what), transmission security (encryption), and contingency plans.
HIPAA applies to covered entities — health plans, healthcare clearinghouses, and providers who transmit health information electronically — plus their business associates (for example, billing or transcription companies) through contracts. It does not apply to everyone who happens to hold health information, and it is not the only privacy law that exists. Nurses should follow the stricter of the law, the professional code, and facility policy.
Informatics: the systems nurses use every day
- Electronic health record (EHR): the legal record of care. It supports continuity — information travels with the patient across shifts, units, and facilities — and makes information searchable and analyzable.
- Computerized provider order entry (CPOE): providers enter orders directly into the system instead of writing them by hand, which removes transcription errors and can trigger decision support (allergy warnings, dose checks).
- Barcode medication administration (BCMA): scanning the patient's wristband and the medication packaging verifies the "rights" of medication administration before the drug is given.
- Clinical decision support: alerts, reminders, and evidence links embedded in the record that flag problems such as allergies or drug interactions.
- Patient portals: patients can view parts of their own record, message the care team, and manage appointments, which supports engagement and self-management.
- Telehealth: care delivered at a distance, which extends access but adds privacy considerations for video and data transmission.
Informatics brings benefits and new risks. Data-entry errors, alert fatigue (so many warnings that clinicians start ignoring them), wrong-patient selection from a drop-down list, and security breaches are all real. Technology assists — it does not replace the nurse's verification and judgment.
Security measures in everyday practice
- Authentication: unique user IDs and strong passwords. Passwords are never shared, never written on sticky notes, and never borrowed.
- Automatic lock: workstations time out after inactivity. Locking the screen before stepping away, even for a moment, is a habit.
- Positioning: monitors are turned away from hallways, waiting areas, and doors so casual passersby cannot read them.
- Physical safeguards: identification badges, locked offices and supply areas, and restricted areas.
- Encryption: data is scrambled so it is unreadable if intercepted.
- Audit trails: the system records who opened which record and when. This is how unauthorized viewing is detected — and why "just looking" is a documented, discoverable act.
- Breach Unauthorized acquisition, access, use, or disclosure of PHI Full entry → response: a breach is any unauthorized acquisition, access, use, or disclosure of PHI. Suspected breaches are reported promptly per facility policy — never concealed.
The nurse's role: protecting information at the bedside
- Verify before revealing. Before releasing any information — to a caller, a visitor, or even another staff member — confirm the person's identity and their need to know. Do not confirm or deny a patient's presence to a caller without following the facility's verification process.
- Keep conversations private. Discuss patient matters in private spaces, in low voices. Be mindful of hallways, elevators, and waiting rooms.
- Protect the screen and paper. Log off or lock workstations, position monitors away from public view, and do not leave printed reports with identifiers lying around.
- Share the minimum. Give only the information needed, to people involved in the patient's care. Family members generally receive information only with the patient's permission; a patient can also restrict all sharing ("confidential" status).
- Document professionally. The record is a legal document: accurate, objective, timely. Never write negative opinions about patients or colleagues.
How It Works: Handling a Request for Information
- Stop and identify the requester. Who is asking — a patient, a family member, a colleague, a caller? What do they claim to need?
- Check authorization. Does the patient have capacity and has the patient authorized sharing with this person? Is the requester actually involved in the patient's care? Facility policy defines the process.
- Apply minimum necessary. Share only the smallest amount of information that accomplishes the legitimate purpose.
- Choose a safe channel. Private conversation, secure messaging, the patient portal — not a hallway, not an unsecured text, not a public voicemail.
- Document the interaction if required (per facility policy, e.g., for certain disclosures).
- If anything is uncertain, decline and escalate. "I'll check with the charge nurse / privacy officer" is a complete, professional answer.
Common Confusions
| Do Not Confuse | With | Difference |
|---|---|---|
| Privacy | Confidentiality | Privacy is the patient's right to control information; confidentiality is the professional's duty to protect it |
| Confidentiality | Security | Confidentiality is the obligation; security is the locks, passwords, and policies that fulfill it |
| "HIPAA applies to anyone with health information" | HIPAA applies to covered entities and their business associates | People outside those categories are not bound by HIPAA, though other laws, ethics codes, and policies still apply |
| "Family can always get information" | Family access requires the patient's permission (or legal authority) | The patient decides who receives their information; a patient can restrict all sharing |
| "If it's in the EHR, it's fine to look" | Viewing requires a work-related need | Curiosity viewing ("chart stalking") is a violation even though the system technically allows access |
| "The EHR is always accurate" | The EHR contains human-entered data | Errors still occur; nurses verify identity and information and correct the record properly |

Eli explains
The same idea, in plain words
Explain it like I’m 10
Your health information is like a locked diary. Only the people who need to read it to help you — your nurse, your doctor, your pharmacist — may open it, and only the pages they need. The hospital uses passwords, locked screens, and a log of who opens the diary, and if someone peeks who should not have, the hospital has to tell you. Everyone who touches the diary promises to keep it secret.
Worked example
The phone rings at the nurses' station. "Hi, this is Mr. Chen's brother. Is he still admitted? How is he doing?" Nurse Maya does not confirm or deny anything. She explains that she cannot give out information over the phone without verifying the caller's identity and Mr. Chen's permission, and she offers to check whether Mr. Chen has authorized sharing with family. Before walking away, she locks her workstation — her screen shows Mr. Chen's name and room — and she positions the monitor away from the hallway. Later, an off-duty colleague asks, "So what happened with that new admission?" Maya declines: her colleague is not involved in the patient's care, and curiosity is not a reason to access or discuss PHI. Each of these small actions applies privacy, confidentiality, security, and the minimum-necessary rule in real time.
Key takeaways
- PHI is any identifiable health information in any form — paper, electronic, or spoken.
- Privacy = patient's right; confidentiality = professional's duty; security = the safeguards that enforce both.
- HIPAA Privacy Rule governs use and disclosure and grants patient rights (access, amendment, notice, accounting); HIPAA Security Rule governs safeguards for electronic PHI.
- Minimum necessary: use only the information needed for the task.
- Never share passwords; lock screens when leaving a workstation; verify identity before releasing information.
- "Chart stalking" is a violation — records are opened only for work-related need, and audit trails track access.
- Report suspected breaches immediately per facility policy; concealing a breach makes it worse.
- HIPAA is US-specific. Other jurisdictions have different laws, and facility policy may be stricter than the legal minimum.
Check yourself
6 review questions from the chapter. Try each one, then open the answer.
What are privacy, confidentiality, and security, and how do they differ?
Show answer
Privacy is the patient's right to control access to their health information; confidentiality is the professional duty to protect it; security is the technical, physical, and administrative safeguards that make protection possible.
What information counts as PHI?
Show answer
Any identifiable health information in any form — name, birth date, medical record number, diagnosis, treatment, and payment information, whether spoken, written, or electronic.
A caller asks whether a patient is admitted. What should the nurse do first?
Show answer
Do not confirm or deny. Verify the caller's identity and the patient's authorization following facility policy before releasing any information.
What does "minimum necessary" mean, and when does it apply?
Show answer
Using only the smallest amount of information needed to accomplish the task; it applies to every use and disclosure of PHI.
Why must a nurse lock the workstation before stepping away from it?
Show answer
To prevent unauthorized access by anyone passing by. Automatic locks exist for the same reason — leaving a screen open exposes PHI.
What should a nurse do after discovering a possible breach of patient information?
Show answer
Report it immediately to the appropriate person (charge nurse, manager, or privacy officer) per facility policy — never ignore or conceal a breach.
Study tools & related lessonsKey vocabulary · Related
Key vocabulary
- Privacy
- The patient's right to control who knows their health information
- Confidentiality
- The professional duty to protect information shared during care
- Security
- The technical, physical, and administrative safeguards that protect information
- PHI (protected health information)
- Identifiable health information in any form
- HIPAA
- US law setting privacy and security standards for health information
- Minimum necessary
- Using only the smallest amount of information needed for the task
- EHR
- Electronic health record — the digital legal record of care
- CPOE
- Computerized provider order entry — orders entered directly into the system
- Audit trail
- A system log of who accessed which record and when
- Breach
- Unauthorized acquisition, access, use, or disclosure of PHI
- Covered entity
- A provider, health plan, or clearinghouse that must comply with HIPAA
Sources & references
This lesson was adapted from the open educational references above; their licenses and attributions are preserved. See Copyright & Licensing.
Educational content only. It is not medical, legal or professional advice. Found an error? Tell us.

