NUR 305 Module 3 Short Paper example

Reviewed by Delia Ravenscroft, MSN, RN Information Management and Patient Care Technologies Southern New Hampshire University Full sample paper Free custom sample in 24 to 48h

This NUR 305 Module 3 short paper is reproduced whole: a pediatric clinic nurse examines what happens to a 16-year-old's confidential care when the patient portal is shared with a parent, how federal rules on releasing results sharpen the problem, and which privacy and security controls nurses can use or request. The clinic and patient are a composite; the sources are real.

What this page holds

Read one complete NUR 305 Module 3 short paper on privacy and security in patient portals, focused on adolescent confidentiality and proxy access, with the title page, headings and reference list done to APA 7, plus a note in the margin beside each part. Searches like "nur 305 module 3 assignment", "nur305 module 3 short paper" and "nur 305 module 3 example" land here.

The NUR 305 Module 3 example, in full

1

Who Is Reading the Message? Adolescent Confidentiality, Proxy Access and the Patient Portal

[Student Name]

Southern New Hampshire University

NUR 305: Information Management and Patient Care Technologies

Module Three Short Paper

[Instructor Name]

[Date]

The organization, setting and figures below are a composite written as a model document. No real employer, client, colleague or patient is described.

What this page is doingThe title asks the question at the center of the paper and then names the three elements it will connect. A question-led title works well for a privacy paper because the issue is uncertainty about who actually sees the information.
2

Who Is Reading the Message? Adolescent Confidentiality, Proxy Access and the Patient Portal

A 16-year-old patient at a composite suburban pediatric practice asked the nurse, during a visit for a sports physical, whether she could be tested for a sexually transmitted infection without her parents knowing. The nurse explained that the state allowed minors to consent to that testing and that the clinician would keep the conversation confidential. Three days later, the result posted to the patient portal automatically. The portal account had been created by the patient's mother when the patient was nine, the mother still held the password, and the result notification went to the mother's email address. The patient learned that her mother knew when her mother confronted her that evening.

No individual in this case broke a rule deliberately. The nurse gave accurate information about consent, the clinician ordered the test appropriately, and the portal released the result as it was configured to do. The breach arose from the design of the system and from assumptions about who was using the account. This paper analyzes that breach as a privacy and security problem, reviews the evidence on shared portal access for adolescents, and identifies technical controls and nursing practices that could have prevented it.

What this page is doingThe case is told concretely and without blame, which keeps attention on the system. Stating that each person acted correctly while the patient's confidentiality was still breached is the insight that makes this a technology paper rather than an ethics lecture.
3

Privacy Principles in Play

Three related ideas apply. Privacy is the patient's right to control who has access to information about her. Confidentiality is the duty of clinicians and organizations to protect information shared in a care relationship. Security refers to the administrative, physical and technical safeguards that protect electronic information from unauthorized access. In this case, the adolescent's privacy was violated because the confidentiality promised in the visit depended on a security design that did not distinguish between the patient and her parent.

Adolescent privacy is complicated by the fact that parents generally have the right to access a minor's health information, with important exceptions. Most states allow minors to consent to certain services, such as testing and treatment for sexually transmitted infections, contraception or some mental health care, and in many of those situations the minor controls who can see the related records. The federal privacy rule generally defers to state law on this point. The result is that a single adolescent record may contain some information that parents can see and some that they cannot, a distinction that paper charts could manage by placing documents in separate folders but that electronic portals often fail to represent.

What this page is doingThe three core concepts are defined briefly and then used to explain the case, which shows understanding rather than memorization. The paragraph on state consent laws is accurate at the level of general pattern and avoids claiming any one state's rules as universal.
4

Why the Problem Has Grown

Two developments have made adolescent portal privacy more urgent. The first is how often portal accounts are shared. In a study of adolescent patient portal accounts at an academic pediatric health system, Ip et al. (2021) used message content to estimate how often accounts registered to adolescents were actually being used by parents or guardians, and found that guardian access to adolescent accounts was common. That finding means that even an account created for the adolescent cannot be assumed to be private.

The second development is the release of results without delay. Federal rules implementing the 21st Century Cures Act restrict practices that unreasonably delay a patient's electronic access to their health information, which led many health systems to release test results to portals as soon as they are finalized, often before a clinician has discussed them with the patient. Adolescent health organizations warned that immediate release, combined with parental proxy access, could expose confidential information and discourage young people from seeking care, and they called for systems able to segment sensitive information and protect adolescent confidentiality within the rules (Carlson et al., 2021).

Neither concern is new. More than a decade earlier, informatics researchers designing personally controlled health records for pediatric patients described the need to shift access controls as children grow, giving adolescents increasing control over parts of their records while preserving appropriate parental access to others (Bourgeois et al., 2008). The technical challenge was recognized long before the current rules raised its stakes.

What this page is doingThe evidence section explains why the case is not a one-time accident: shared accounts are common, and immediate release removes the clinician's chance to intervene. Pairing a recent measurement study with a professional statement and an earlier design paper shows the issue has been recognized for years.
5

Controls That Could Have Prevented the Breach

Technical controls are the first line of protection. A well-configured portal gives the adolescent and each parent separate accounts rather than a shared login, with proxy access for parents that excludes results and notes flagged as confidential. The record can allow clinicians to mark an order or a note as sensitive so that it is withheld from proxy views and notifications. Many systems also allow the adolescent account to be reset at a certain age, commonly around 12 or 13, so that the adolescent must set a new password and the clinic can confirm who holds it. Audit logs can show when and from where an account was accessed, which helps identify shared use.

Nursing practices matter as much as system settings. In this case, the nurse could have asked, before the test was ordered, who has access to the patient's portal and where result notifications are sent. If the answer was the parent, the clinician could have used a confidential result flag, chosen to deliver the result by phone to the adolescent's own number, or helped the adolescent set up her own account during the visit. Clinics can build this question into the intake for every confidential visit so that it does not depend on one nurse remembering it.

What this page is doingThe controls are divided into technical and practice measures, and each is tied to what went wrong in the case. That structure answers the rubric's likely request for recommendations and shows that security is a mix of configuration and human workflow.
6

The Nurse's Responsibilities

Nurses often promise confidentiality at the bedside or in the exam room, and that promise is only as good as the systems behind it. Three responsibilities follow. First, nurses should know how their organization's portal handles proxy access and sensitive results, rather than assuming that the electronic record respects what was said in the visit. Second, nurses should ask the access question whenever confidential services are provided to an adolescent and document the plan for communicating results. Third, when a breach occurs, the nurse should report it through the organization's privacy process, both to support the patient and to help the organization fix the configuration that allowed it. Informatics nurses can then carry those reports into decisions about portal settings and training.

Conclusion

The breach in this case came from a gap between a confidential conversation and a system that could not tell a teenager from her mother. Shared portal accounts are common, and immediate release of results has removed the time clinicians once had to intervene. Separate adolescent and proxy accounts, sensitive result flags, age-based account resets and a routine question about who holds the login can close most of that gap. Protecting adolescent confidentiality in the portal is part of the nurse's duty to keep the promises made in the room.

References

Bourgeois, F. C., Taylor, P. L., Emans, S. J., Nigrin, D. J., & Mandl, K. D. (2008). Whose personal control? Creating private, personally controlled health records for pediatric and adolescent patients. Journal of the American Medical Informatics Association, 15(6), 737-743. https://doi.org/10.1197/jamia.M2865

Carlson, J., Goldstein, R., Hoover, K., & Tyson, N. (2021). NASPAG/SAHM statement: The 21st Century Cures Act and adolescent confidentiality. Journal of Adolescent Health, 68(2), 426-428. https://doi.org/10.1016/j.jadohealth.2020.10.020

Ip, W., Yang, S., Parker, J., Powell, A., Xie, J., Morse, K., Aikens, R. C., Lee, J., Gill, M., Vundavalli, S., Huang, Y., Huang, J., Chen, J. H., Hoffman, J., Kuelbs, C., & Pageler, N. (2021). Assessment of prevalence of adolescent patient portal account access by guardians. JAMA Network Open, 4(9), Article e2124733. https://doi.org/10.1001/jamanetworkopen.2021.24733

How this NUR 305 Module 3 example is structured

The paper is built around a single realistic breach of confidence, then widened to the systems that allowed it. After the opening case, a section sets out the privacy principles in play, including the difference between privacy, confidentiality and security, and what federal and state rules generally allow for adolescents. The evidence section shows how common shared portal access is and why the release of results without delay has raised the stakes. The paper then separates technical controls, such as separate proxy accounts and confidential result flags, from nursing practices such as confirming who holds the login. It ends with the nurse's specific responsibilities.

Get NUR 305 Module 3 written to your instructions

Upload the NUR 305 Module 3 instructions and rubric and the privacy, security or confidentiality issue your section assigned. The desk sends back a paper written to that brief within 24 to 48 hours, free for your first request. The paper above is an original model document written by our desk, not a submitted student paper and not an official Southern New Hampshire University document.

NUR 305 Module 3 questions, answered

What does NUR 305 Module 3 usually focus on?

Around this point the course commonly turns to privacy, confidentiality and security of health information: federal privacy rules, how electronic systems protect data, and the nurse's responsibilities. Expect to analyze a privacy concern, real or realistic, that involves a technology nurses use. Your classroom prompt defines the scope.

What is the difference between privacy, confidentiality and security?

Privacy is a person's right to control who has access to information about them. Confidentiality is the duty of those who receive the information to protect it. Security refers to the administrative, physical and technical safeguards that keep electronic information from being accessed, changed or lost without authorization.

Can a NUR 305 privacy paper discuss state law?

Yes, and for adolescent care it usually must, because states differ on which services minors can consent to on their own and who may see those records. Describe the general pattern, name the source you used, and note that your own state's rules decide the details in practice.