| Course | HIM 400 Communication and Technologies II |
|---|---|
| Module | Module 6 |
| Paper type | undergraduate paper applying data sharing and information blocking rules |
| Length | About 1,100 words, 6 pages |
| Format | APA 7 student paper |
| School | Southern New Hampshire University |
| Program | BS Health Information Management |
| Updated | September 2026 |
Free sample paper for HIM 400 Module 6
Permitted, Required or Blocked? Three Data Sharing Decisions at Cold Brook Health
[Student Name]
Southern New Hampshire University
HIM 400: Communication and Technologies II
Module Six Short Paper
[Instructor Name]
[Date]
The organization, setting and figures below are a composite written as a model document. No real employer, client, colleague or patient is described.
Permitted, Required or Blocked? Three Data Sharing Decisions at Cold Brook Health
For most of the history of health information management, the safest answer to a request for records was to slow down. HIPAA permitted many disclosures but required few, so delay rarely broke a rule. That changed once Congress, through the 21st Century Cures Act, turned interference with sharing into a violation. At Cold Brook Health, three situations from the past month show how the rules now interact. This paper explains the frameworks, applies them to each case and recommends changes to Cold Brook's policies.
Two Frameworks
HIPAA's Privacy Rule sets when protected health information may be used or disclosed. Sharing to treat a patient, obtain payment or run the organization is allowed without the patient's authorization, and individuals may obtain copies of their own records, which a covered entity must usually supply within 30 days of the request. The information blocking regulations, written by the federal health IT coordinator's office to carry out the Cures Act, work the other way. They bar conduct that an actor knows, or should know, will probably get in the way of electronic health information moving to those entitled to it, unless a law requires the conduct or it fits a defined exception. The rules apply to three groups of actors: health care providers, developers of certified health IT and health information networks or exchanges. For developers and networks, penalties can reach $1 million per violation, and since 2024 providers face disincentives through Medicare programs.
Why Exchange Matters
Sharing is not only a legal duty. Across the exchange evaluations reviewed by Menachemi et al. (2018), most reported benefits, such as fewer repeated tests and imaging studies and lower emergency department costs, although study quality varied. Adler-Milstein and Pfeifer (2017) surveyed leaders of exchange organizations and found that about half believed electronic record vendors routinely engaged in information blocking, and about a quarter believed hospitals and health systems did, often for competitive reasons. The rules exist because voluntary sharing had not been enough.
Case 1: The Seven-Day Hold
Cold Brook's portal releases lab results to patients seven days after they are finalized, so clinicians can call with abnormal results first. The policy is well meant, but a blanket delay for all results is likely to interfere with patients' access to their information, and no exception clearly covers it. The preventing harm exception needs a licensed clinician's judgment about a particular patient that releasing the information would put someone's life or physical safety at real risk, and separately a patient may ask for their own results to be held. Neither describes an automatic hold on every cholesterol panel.
The recommended fix is to release most results immediately, let patients choose in the portal whether they want certain results held until their clinician calls and allow a clinician to document an individualized harm determination for a specific result when justified. Clinicians should also be prepared for patients reading results first by writing brief interpretive comments on common tests.
Case 2: A Request Through the Exchange
A federally qualified health center that now treats a Cold Brook patient requested her records through the statewide exchange. The disclosure is for treatment, so HIPAA permits it without authorization, and refusing or slowing a routine treatment request could be information blocking. One part of her record is different. She received care in Cold Brook's opioid treatment program, whose records fall under a stricter federal regulation for addiction treatment programs, known as Part 2. Those records need her written consent. A 2024 federal rule now allows a single consent to cover future treatment, payment and operations disclosures, and she had signed one at intake.
The problem was technical: Cold Brook's exchange feed did not tag Part 2 records, so the analyst could not be sure whether they were flowing without the needed consent. Cold Brook should tag and segment Part 2 data in its record and exchange interface, confirm consent status before release and send the rest of the record promptly.
Case 3: A Patient's App
A patient asked to connect a consumer app to her record through Cold Brook's patient access interface. Certified record systems must now offer standard application programming interfaces based on HL7 FHIR. Mandel et al. (2016) described how the SMART on FHIR platform lets outside applications connect to many record systems through shared standards for data and authorization, and those standards underlie today's patient access interfaces. The compliance officer worried that the app's privacy policy allowed it to share data with advertisers.
Under the information blocking rules, Cold Brook may not refuse the connection because it dislikes the app's privacy terms, as long as the app meets security requirements. It may educate the patient in a fair, factual way about the app's practices. Once data reach the app, HIPAA generally no longer protects them, because the app is not a covered entity or a business associate. Cold Brook added a short notice to its portal explaining this, and the patient chose to connect.
Summary of Decisions
Table 1 summarizes the three cases.
Table 1. Three Data Sharing Decisions
| Case | HIPAA | Information blocking rules | Decision |
|---|---|---|---|
| Seven-day portal hold | Access right; no bar to release | Blanket delay likely interference | Release promptly; patient choice; individualized harm review |
| Exchange request | Treatment disclosure permitted | Refusal or delay could be blocking | Send promptly; confirm Part 2 consent; tag records |
| Patient app via API | Right of access applies | Cannot refuse over privacy terms | Connect; offer factual education |
Note. Prepared by the author for Cold Brook Health's policy review.
What Cold Brook Will Change
The analyst's recommendations went to the compliance committee as four policy changes. The portal release policy will be rewritten so that results post as soon as they are final, with a patient-controlled option to wait for a call and a documented clinician review for individual exceptions. The exchange interface will tag Part 2 data at the source so that consent can be checked automatically. The release of information team will receive a one-page guide that sorts common requests into permitted, required and exception categories. Finally, every refusal or delay of an electronic request will be logged with the exception relied on, so the organization can show its reasoning if a complaint reaches regulators.
Conclusion
The three cases share a lesson: HIPAA tells an organization what it may share, but the information blocking rules now expect it to share unless a specific reason applies. For health information management professionals, the safest answer is no longer delay. It is a policy that releases information promptly, applies exceptions case by case, protects specially regulated records through technical tagging and gives patients clear information about where their data will go.
References
Adler-Milstein, J., & Pfeifer, E. (2017). Information blocking: Is it occurring and what policy strategies can address it? Milbank Quarterly, 95(1), 117-135. https://doi.org/10.1111/1468-0009.12247
Mandel, J. C., Kreda, D. A., Mandl, K. D., Kohane, I. S., & Ramoni, R. B. (2016). SMART on FHIR: A standards-based, interoperable apps platform for electronic health records. Journal of the American Medical Informatics Association, 23(5), 899-908. https://doi.org/10.1093/jamia/ocv189
Menachemi, N., Rahurkar, S., Harle, C. A., & Vest, J. R. (2018). The benefits of health information exchange: An updated systematic review. Journal of the American Medical Informatics Association, 25(9), 1259-1265. https://doi.org/10.1093/jamia/ocy035
What the HIM 400 Module 6 instructions ask for
In the HIM 400 data sharing module, expect to describe how records move between organizations and which regulations shape that exchange, often by applying rules to cases. Plan four to five pages in APA 7 with at least three scholarly sources, and cite the regulations themselves by name. Explain HIPAA's permitted disclosures and right of access, then the information blocking rules, the actors they cover and the idea of exceptions. Apply both frameworks to each case, note any specially protected records such as substance use disorder treatment and recommend specific policy changes. A summary table that sorts each decision by framework helps graders follow your reasoning across several cases at once.
How this HIM 400 Module 6 data sharing short paper example is built
Three cases from Cold Brook Health drive the paper: a seven-day hold on portal lab results, a partner clinic's exchange request that touches Part 2 records and a patient's app connecting through a FHIR interface. Menachemi and colleagues show the benefits of exchange, and Adler-Milstein and Pfeifer show how common blocking had been. The hold is judged likely interference and replaced with patient choice and individualized harm review, the exchange request goes ahead once Part 2 consent is confirmed and the app is connected with factual education, drawing on Mandel and colleagues. A table sorts each case by HIPAA, blocking rules and decision, and four policy changes follow for the compliance committee.
Where the HIM 400 Module 6 rubric puts the points
Grading for this HIM 400 paper tends to follow accurate explanation of HIPAA and the information blocking rules, correct identification of actors and exceptions, sound application to each case, attention to specially protected records, practical recommendations and APA 7 mechanics. The best papers explain that HIPAA permits while the Cures Act rules require, and they apply the preventing harm exception precisely instead of treating any clinical concern as enough. Graders also reward writers who notice technical causes, such as untagged records, behind compliance problems. Recognizing that data leave HIPAA's protection once they reach a consumer app shows up-to-date understanding of patient access. Correct names of rules and agencies matter.
HIM 400 Module 6 help: the mistakes that cost points
Data sharing papers lose points when they treat HIPAA as the only rule, describe information blocking as optional, invent exceptions or claim an organization can refuse an app because of its privacy policy. Another frequent gap is overlooking substance use disorder records or state laws that add protections. If your course gives specific scenarios, such as a payer request, a public health report or a subpoena, send them with the prompt so the sample applies the right framework to each. Note your state if it matters, since some states add consent rules of their own. A custom paper can follow the same pattern of framework, case, exception and recommendation used for these Cold Brook cases.
Get HIM 400 Module 6 written to your instructions
Forward the HIM 400 Module 6 assignment and any cases your course supplies. The paper will explain HIPAA and the information blocking rules, apply both to each case with the correct exceptions, flag specially protected records and recommend policy changes, back to you in 24 to 48 hours, the first time at no charge. The paper above is an original model document written by our desk, not a submitted student paper and not an official Southern New Hampshire University document.
More HIM 400 papers and related BS Health Information Management samples
- HIM 400 Module 1 Discussion: Why Health Technology Projects Fail
- HIM 400 Module 2 Database Structures Short Paper: A Relational Design for a Diabetes Registry
- HIM 400 Module 3 Data Extraction Short Paper: Queries, Data Requests and the Minimum Necessary
- HIM 400 Module 4 Project One: Trends and Patterns in Diabetes Control
- HIM 400 Module 5 Data Mining Short Paper: Predicting Missed Appointments, Checked for Bias
- HIM 350 Module 7 Project Two: A Communication Technology Improvement Plan
- HIM 200 Module 5 Usability and Safety Short Paper: When Record Design Contributes to Harm
- HIM 220 Module 7 Project Two: A Data Quality Improvement Plan
- HIM 360 Module 2 Complex Diagnosis Short Paper: Neoplasms, Poisonings, Adverse Effects and Underdosing
HIM 400 Module 6 questions, answered
Where can I find a free HIM 400 Module 6 Data Sharing Short Paper sample?
The full HIM 400 Module 6 paper is here: a portal results hold, an exchange request and a patient app tested against HIPAA and information blocking rules.
What is information blocking?
A practice by a provider, certified health IT developer or exchange that is likely to interfere with access, exchange or use of electronic health information, unless required by law or covered by an exception.
Can a clinic hold lab results until the clinician calls?
A blanket hold is likely information blocking; a patient may request a delay, and a clinician may withhold a specific result after an individualized harm determination.
Does HIPAA protect data after a patient sends it to an app?
Generally not, because most consumer apps are neither covered entities nor business associates.
How are substance use disorder records treated in exchange?
Records from federally assisted programs fall under Part 2 and need patient consent, though one consent can now cover future treatment, payment and operations.