| Course | HIM 400 Communication and Technologies II |
|---|---|
| Module | Module 3 |
| Paper type | undergraduate paper on extracting health data with queries and data requests |
| Length | About 1,090 words, 6 pages |
| Format | APA 7 student paper |
| School | Southern New Hampshire University |
| Program | BS Health Information Management |
| Updated | September 2026 |
Free sample paper for HIM 400 Module 3
Two Requests, One Registry: Extracting Diabetes Data at Cold Brook Health
[Student Name]
Southern New Hampshire University
HIM 400: Communication and Technologies II
Module Three Short Paper
[Instructor Name]
[Date]
The organization, setting and figures below are a composite written as a model document. No real employer, client, colleague or patient is described.
Two Requests, One Registry: Extracting Diabetes Data at Cold Brook Health
In the same week, Cold Brook Health's informatics team received two requests for diabetes data. The nurse care managers asked for a list of adults whose diabetes is poorly controlled so they can call them before winter. A research group at a state university asked for registry data to study how travel distance affects diabetes control in rural Maine. Both requests draw on the relational registry designed in Module Two, but they differ in purpose, recipient and legal basis. This paper shows how each is specified, extracted, checked and released.
Turning a Request Into a Specification
"Patients with high A1c" is not a query. Before writing any code, the analyst met with the care manager lead and wrote a specification that states every rule. The population is patients aged 18 to 75 on the last day of the measurement period who meet the registry's diabetes definition and were seen by a Cold Brook primary care clinician during the prior twelve months. The measure is the most recent HbA1c in that twelve-month window. A patient is flagged if that value is above 9.0% or if no HbA1c was done at all, because an untested patient is as much at risk as a poorly controlled one. Patients enrolled in hospice or receiving palliative care are excluded, and the list must show each patient's practice, care manager, phone number, latest value and date.
These rules mirror the structure of the national quality measure for poor HbA1c control, which helps the team compare its list with the rates it reports. Writing them down also exposed a disagreement: the care managers had assumed a fifteen-month look-back, so their own counts had never matched the quality report.
Writing the Query
The query works in steps. A first step selects registry patients in the age range with a qualifying visit. A second step finds each patient's latest HbA1c in the window by ranking results by collection date within each patient and keeping the first. A third step removes patients with a hospice or palliative care code. The final step joins practice, care manager and contact fields and applies the flag. Table 1 summarizes each clause and what it does.
Table 1. Query Clauses for the Outreach List
| Clause | Example logic | Purpose |
|---|---|---|
| SELECT | patient_id, mrn, practice_name, phone, a1c_value, a1c_date | Returns only the fields care managers need |
| FROM and JOIN | PATIENT joined to ENCOUNTER, LAB_RESULT and ATTRIBUTION on patient_id | Links the tables through their keys |
| WHERE | age 18 to 75; visit in the last 12 months; loinc_code in the HbA1c list | Applies inclusion rules |
| Window function | ROW_NUMBER() OVER (PARTITION BY patient_id ORDER BY collected_date DESC) | Keeps each patient's latest result |
| NOT EXISTS | no hospice or palliative care code in the period | Applies exclusions |
| CASE | flag when a1c_value > 9.0 or a1c_value IS NULL | Marks poor control or no test |
Note. Logic written by the author for Cold Brook Health's registry schema.
Validating the Output
The first run returned 1,902 patients, 28% of the 6,794 in the denominator. Before release, the analyst compared a random sample of 50 flagged patients with their full charts. Eleven had an HbA1c recorded somewhere the query could not see: six in scanned outside lab reports, three typed into visit notes and two sent to the old workbook but never entered in the record.
Published studies found the same problem at larger scale. Parsons et al. (2012) compared quality measures calculated from electronic record data with manual chart review in primary care practices and found that electronic measures often underestimated performance, largely because the needed information was documented in places the reporting query did not capture. Kern et al. (2013) reached a similar conclusion at a federally qualified health center, where agreement between electronic and manual measurement varied widely across measures. For Cold Brook, the lesson is that a flagged patient is a candidate for outreach, not a verdict, so the list now includes a column noting whether an outside result is pending entry.
Releasing the Outreach List
The outreach list supports treatment and care coordination by Cold Brook's own staff, so identifiable data may be used. HIPAA's minimum necessary standard exempts disclosures to providers for treatment, but Cold Brook's role-based access policy follows the same principle, so it still shapes the output: the list contains the fields needed to call and schedule patients and nothing more, so diagnoses beyond diabetes, insurance details and addresses are left out. The list is posted to the care management folder, which only care managers can open, and replaced each month instead of emailed.
Answering the Research Request
The university request is different. Research is not treatment, and the investigators are outside the organization. HIPAA offers several paths: patient authorization, a waiver from an institutional review board, fully de-identified data or a limited data set released under a data use agreement. The study needs dates of HbA1c tests and the patient's town to estimate travel distance, and de-identification under the Safe Harbor method would remove both, since it strips dates other than year and most geographic units smaller than a state. A limited data set may keep dates and town or ZIP code while removing direct identifiers such as names, phone numbers, street addresses and record numbers.
The analyst therefore prepared a limited data set containing a study identifier, age, sex, town, ZIP code, test dates, HbA1c values and visit counts. The release waits until the university signs a data use agreement promising not to re-identify or contact patients, to use the data only for the approved study and to report any breach.
Re-identification Risk
Removing names does not make rural data anonymous. In a town of 900 residents, a 43-year-old woman with type 1 diabetes may be the only one. El Emam et al. (2011) reviewed published re-identification attacks on health data and found that most successful attacks involved data that had not been de-identified to existing standards, and that re-identification rates were low when those standards were followed, although the evidence base was small. Their findings support the safeguards Cold Brook chose: the agreement forbids re-identification, ages above 89 are grouped and town counts below 11 patients are combined with a neighboring town before release.
Conclusion
The two requests used the same tables but produced two different releases. The outreach list is identifiable, limited to what care managers need and validated against charts. The research file is a limited data set with small counts combined and an agreement in place. In both cases the most important work happened before the query ran: turning a request into written rules and deciding who may see what.
References
El Emam, K., Jonker, E., Arbuckle, L., & Malin, B. (2011). A systematic review of re-identification attacks on health data. PLoS ONE, 6(12), Article e28071. https://doi.org/10.1371/journal.pone.0028071
Kern, L. M., Malhotra, S., BarrĂ³n, Y., Quaresimo, J., Dhopeshwarkar, R., Pichardo, M., Edwards, A. M., & Kaushal, R. (2013). Accuracy of electronically reported "meaningful use" clinical quality measures: A cross-sectional study. Annals of Internal Medicine, 158(2), 77-83. https://doi.org/10.7326/0003-4819-158-2-201301150-00001
Parsons, A., McCullough, C., Wang, J., & Shih, S. (2012). Validity of electronic health record-derived quality measurement for performance monitoring. Journal of the American Medical Informatics Association, 19(4), 604-609. https://doi.org/10.1136/amiajnl-2011-000557
What the HIM 400 Module 3 instructions ask for
The HIM 400 data extraction assignment usually asks you to explain how data are pulled from a health information system for a specific request and how privacy rules shape what is released. Plan four to five pages in APA 7 with at least three scholarly sources and a table or figure. Start by turning the request into a written specification with population, measure, time window, exclusions and output fields. Then describe the query logic step by step, explain how you checked the results against source records and state which HIPAA path governs the release. Some versions add a knowledge activity with real queries, so keep clause names accurate and consistent with your course's software. Show your output counts too.
How this HIM 400 Module 3 data extraction short paper example is built
Cold Brook Health receives two requests in one week: care managers want adults with an HbA1c above 9%, and a university wants registry data for a travel distance study. The paper writes a specification that uncovers a mismatched look-back period, explains a query in a clause table and validates 50 flagged patients against charts, finding 11 with results the query missed, a pattern Parsons and colleagues and Kern and colleagues also report. The outreach list follows the minimum necessary standard, while the research request becomes a limited data set under a data use agreement, with El Emam and colleagues informing safeguards for small rural towns. A four-sentence conclusion contrasts the two releases.
Where the HIM 400 Module 3 rubric puts the points
HIM 400 extraction papers are usually graded on a clear specification, accurate query logic, validation of results, correct application of privacy rules, sound use of sources and APA 7 mechanics. Top papers show that the analyst clarified the request before writing code, state the denominator and time window, and admit what the query cannot see. Graders also reward writers who match the release path to the recipient: identifiable data for internal care, a limited data set or de-identified file for outside research. Mentioning practical safeguards such as small-cell suppression shows a mature understanding of privacy beyond simply removing names from a file. Validation counts earn credit as well.
HIM 400 Module 3 help: the mistakes that cost points
Data extraction papers lose points when they describe a query vaguely, skip exclusions or the look-back period, release more fields than the purpose needs or treat removing names as full de-identification. Another frequent gap is confusing a limited data set with de-identified data. If your course provides a specific data set, schema or SQL exercise, send it with the prompt so the sample uses those tables and field names. A custom version can extract data for another measure, such as blood pressure control or cancer screening, following the same path from request and specification to query, validation and release shown here.
Get HIM 400 Module 3 written to your instructions
Forward the HIM 400 Module 3 prompt and any schema or data set your course uses. The paper will write a clear specification, explain the query clause by clause, validate the output against records and match the release to the right privacy path, returned within 24 to 48 hours with the first request free. The paper above is an original model document written by our desk, not a submitted student paper and not an official Southern New Hampshire University document.
More HIM 400 papers and related BS Health Information Management samples
- HIM 400 Module 1 Discussion: Why Health Technology Projects Fail
- HIM 400 Module 2 Database Structures Short Paper: A Relational Design for a Diabetes Registry
- HIM 350 Module 1 Discussion: How Technology Changed Care Conversations After 2020
- HIM 215 Module 5 CPT and HCPCS Short Paper: Outpatient Coding, Office Visit Levels and Modifiers
- HIM 360 Module 2 Complex Diagnosis Short Paper: Neoplasms, Poisonings, Adverse Effects and Underdosing
- HIM 200 Module 6 Privacy and Security Short Paper: HIPAA, Breaches and Practical Safeguards
HIM 400 Module 3 questions, answered
Where can I find a free HIM 400 Module 3 Data Extraction Short Paper sample?
This page holds the entire HIM 400 Module 3 paper: an HbA1c query built clause by clause, two data requests and the minimum necessary rule applied.
Why write a specification before a query?
It fixes the population, time window, exclusions and output in writing so the result matches what the requester actually needs.
What is a limited data set?
Health data with direct identifiers removed that may keep dates and town or ZIP code, released only under a data use agreement.
Does the minimum necessary rule apply to internal lists?
HIPAA exempts treatment disclosures to providers, but role-based access policies still limit staff to what their job needs, so outreach lists should carry only needed fields.
Why do electronic quality measures miss some care?
Queries read structured fields, so results documented in scanned reports or free text are often invisible to them.