| Course | HIM 540 Health Information Governance |
|---|---|
| Module | Module 2 |
| Paper type | graduate paper applying information governance principles to a health system |
| Length | About 1,020 words, 6 pages |
| Format | APA 7 student paper |
| School | Southern New Hampshire University |
| Program | MS Health Information Management |
| Updated | September 2026 |
Free sample paper for HIM 540 Module 2
Principles With Owners: Testing Eight Governance Principles at Tidewater Crossing Health
[Student Name]
Southern New Hampshire University
HIM 540: Health Information Governance
Module Two Short Paper
[Instructor Name]
[Date]
The organization, setting and figures below are a composite written as a model document. No real employer, client, colleague or patient is described.
Principles With Owners: Testing Eight Governance Principles at Tidewater Crossing Health
Every organization agrees that information should be accurate, protected and available. Tidewater Crossing Health's merger shows how little that agreement means without structure. The four former hospitals keep records for different lengths of time, one has not destroyed a paper record since 1998, access rules differ by site and no one can say how many copies of patient data exist across the system. This paper applies a widely used set of governance principles to these problems and asks what each principle requires the system to do.
Where the Principles Come From
The principles grew out of records management practice and were adapted for health care by the American Health Information Management Association, which framed information governance as an organization-wide responsibility rather than a department's task (AHIMA, 2014). The adapted set includes eight principles: accountability, transparency, integrity, protection, compliance, availability, retention and disposition. Each describes an outcome rather than a method, which makes them flexible but also easy to endorse without acting on.
What Each Principle Requires
Accountability means a senior leader is responsible for governance and delegates duties to named people. Transparency means the organization's information practices are documented and open to those with a legitimate interest, including patients and regulators. Integrity means records are reliable and authentic, with a trustworthy trail of who created and changed them. Protection means information is safeguarded according to its sensitivity. Compliance means practices meet laws, regulations and the organization's own policies. Availability means information can be found and retrieved when and by whom it is needed. Retention means information is kept for as long as law and business need require. Disposition means information that is no longer needed is destroyed securely, unless a legal hold applies.
How Tidewater Crossing Measures Up
Table 1 compares each principle with the system's current state and proposes a first action.
Table 1. Governance Principles Applied to Tidewater Crossing Health
| Principle | Current gap | First action |
|---|---|---|
| Accountability | No executive owns information governance | Name the chief operating officer as executive sponsor |
| Transparency | Practices undocumented at two hospitals | Publish a system inventory of information types and owners |
| Integrity | Two record platforms; amendment processes differ | Adopt one amendment and late entry policy |
| Protection | Access rules differ by site | Adopt role-based access standards system-wide |
| Compliance | No crosswalk of state and federal record rules | Compile a legal requirements register with counsel |
| Availability | Clinicians cannot see records from other hospitals quickly | Prioritize shared record access for transfers |
| Retention | Three retention schedules | Adopt one schedule based on the legal register |
| Disposition | Paper records kept since 1998 at one site | Begin defensible destruction after legal hold review |
Note. Assessment by the author with the system's compliance officer.
Building the Legal Requirements Register
Several principles, especially compliance, retention and disposition, depend on knowing what the law requires, and the merged system has no single list. The compliance officer and health information director will build a legal requirements register with counsel, listing for each record type the federal and Virginia rules that apply: how long it must be kept, who may see it, how it must be protected and when it may be destroyed. Records of minors, for example, generally must be kept longer than adult records, and certain research, radiology and mammography records have their own rules. The register becomes the foundation for one retention schedule and for access standards, replacing three sets of assumptions with one documented basis.
Principles in Tension
The principles sometimes pull against each other. Availability argues for letting clinicians at every hospital see every patient's record, while protection argues for limiting access. Retention argues for keeping records long enough to meet legal duties, while disposition and protection argue for destroying them once those duties end, since information that no longer exists cannot be breached. Price and Cohen (2019) describe how the growing use of large health data sets strains traditional privacy protections, which sharpens the tension between keeping data for future value and limiting exposure. Holmgren and Adler-Milstein (2017) found that many hospitals still struggled to find and integrate outside information, a reminder that availability failures also harm patients. Governance exists partly to make these trade-offs deliberately, with documented reasons, rather than leaving each department to decide alone.
Why Principles Need Owners
A principle without an owner is a slogan. Rosenbaum (2010) argued that data stewardship requires entities with defined authority, transparent processes and accountability, which is the practical form the accountability principle must take. At Tidewater Crossing, each principle will be assigned to a named owner: the privacy officer for protection, the compliance officer for compliance, the health information director for integrity, retention and disposition and the chief information officer for availability. Each owner will report one or two measures to the governance council quarterly, such as the share of records past retention that have been destroyed or the time for a transfer team to view an outside record.
Where to Start
Not every principle can be addressed at once. The council will start with accountability, because every other action needs an owner, and with the legal requirements register, because retention, disposition and compliance depend on it. Protection and availability follow in the second quarter, since access standards must reconcile clinical needs across four hospitals. Integrity work on a single amendment policy can proceed in parallel, because it is largely within the health information department's control.
What the Health Information Profession Brings
Several principles fall squarely within health information management's expertise. Integrity rests on documentation standards, authentication and amendment processes. Retention and disposition require knowledge of legal requirements and of which records form the legal health record. Availability depends on indexing, record requests and patient access. The health information director is therefore well placed to coordinate the governance program, working with privacy, compliance and information technology leaders rather than leaving governance to technology alone.
Conclusion
Tidewater Crossing does not lack principles; it lacks people accountable for them. Applying the eight principles shows specific gaps, from three retention schedules to undocumented access rules, and assigning each principle an owner, a first action and a measure turns a statement of values into a program. The next milestone will design the governance structure that gives those owners authority.
References
American Health Information Management Association. (2014). Information governance principles for healthcare (IGPHC). AHIMA.
Holmgren, A. J., & Adler-Milstein, J. (2017). Health information exchange in US hospitals: The current landscape and a path to improved information sharing. Journal of Hospital Medicine, 12(3), 193-198. https://doi.org/10.12788/jhm.2704
Price, W. N., & Cohen, I. G. (2019). Privacy in the age of medical big data. Nature Medicine, 25(1), 37-43. https://doi.org/10.1038/s41591-018-0272-7
Rosenbaum, S. (2010). Data governance and stewardship: Designing data stewardship entities and advancing data access. Health Services Research, 45(5, Pt. 2), 1442-1455. https://doi.org/10.1111/j.1475-6773.2010.01140.x
What the HIM 540 Module 2 instructions ask for
This HIM 540 assignment moves governance principles from theory into a specific organization. A graduate response usually runs four or five pages, formatted in APA 7, with one table that applies every principle and research showing why the principles matter. Say where the principles come from and what each demands in everyday terms, then hold each against your case organization's practice and name a first action. Discuss where principles collide, such as openness against protection or keeping records against destroying them, and how a governance body settles those collisions. Close by giving each principle an owner and a measure, and describe what health information professionals contribute. Say which principle you would tackle first and why.
How this HIM 540 Module 2 principles short paper example is built
Tidewater Crossing Health keeps three retention schedules and paper records from 1998. The paper traces the eight principles to records management practice adapted by AHIMA, defines what each requires and applies them in a table with gaps and first actions, from naming an executive sponsor to beginning defensible destruction. Tensions between availability and protection and between retention and disposition are explained with Price and Cohen and Holmgren and Adler-Milstein. Rosenbaum's work on stewardship supports assigning each principle an owner and quarterly measures, and the health information director is positioned to coordinate the HIM 540 program. A legal requirements register built with counsel underpins retention and disposition, and a starting sequence puts accountability first.
Where the HIM 540 Module 2 rubric puts the points
Expect HIM 540 grading to reward an exact explanation of each principle, a candid comparison with the organization's current practice, first actions that could start next month, honest discussion of where principles conflict, owners and measures for every principle, a clear statement of the health information role, research used with care and APA 7 mechanics. The papers that score best show that principles gain force only through accountability and measurement. A table that lets a reader scan gaps and actions quickly earns credit, as does discussion of trade-offs that reads as judgment rather than a checklist. Treating legal holds as a firm limit on disposition shows attention to legal detail.
HIM 540 Module 2 help: the mistakes that cost points
Drafts on governance principles tend to falter when the principles are listed but never tested against the organization, when every principle is treated as equally urgent, when conflicts between them are ignored or when actions have no owner. Disposition discussions that forget legal holds also lose credit. If your instructor assigns a different model, such as a maturity scale or another body's data governance framework, pass along the prompt and readings, and the paper will use that model instead. Describing how your case organization actually keeps, shares and destroys records makes the analysis sharper. Our HIM 540 principles papers run from problem and sources through requirements, the table, tensions, owners and the profession's role.
Get HIM 540 Module 2 written to your instructions
Send the HIM 540 Module 2 prompt and details of your case organization's information practices. The paper will explain each principle, apply it in a table with gaps and first actions, address tensions, assign owners and measures and show the health information role, ready in 24 to 48 hours with the first sample free. The paper above is an original model document written by our desk, not a submitted student paper and not an official Southern New Hampshire University document.
More HIM 540 papers and related MS Health Information Management samples
- HIM 540 Module 1 Discussion: Information Governance Versus Data Governance
- HIM 530 Module 6 Third-Party Risk Short Paper: Business Associates and Vendor Oversight
- HIM 500 Module 10 Reflection: The Informatics Leader's Role
- HIM 520 Module 9 Final Project: The Leadership Plan for the System HIM Department
- HIM 510 Module 8 Trends Short Paper: Price Transparency, Prior Authorization and AI Coding
HIM 540 Module 2 questions, answered
Where can I find a free HIM 540 Module 2 Principles Short Paper sample?
This page carries the entire HIM 540 Module 2 paper: eight governance principles tested against a merged health system, with gaps and first actions.
What are the principles of information governance?
A common set includes accountability, transparency, integrity, protection, compliance, availability, retention and disposition.
Can governance principles conflict?
Yes. Availability can conflict with protection, and retention can conflict with disposition; governance makes these trade-offs deliberately.
What is defensible destruction?
Destroying information that has passed its retention period according to a documented schedule and process, after confirming no legal hold applies.
Who should own information governance?
A senior executive sponsor, with named owners for each principle and a council that coordinates across departments.