DNP/715 Week 7: Privacy, Security and Ethical Use of Data, sample paper

Reviewed by Lenora Whitcombe, MSN, RN · University of Phoenix

This page holds a complete DNP/715 Week 7 sample paper on privacy, security and the ethical use of data, in true APA form. A DNP-prepared nurse leader in a regional health system addresses two events: a ransomware attack that forced nine days of paper downtime, and a care management algorithm that may repeat a documented racial bias. She draws on national data on breaches and ransomware and on a study of algorithmic bias, and proposes nursing-led safeguards.

1

Nine Days on Paper and a Risk Score That Undercounted Black Patients: Privacy, Security and Ethical Use of Data in a Regional Health System, With a Nurse Leader's Response to Each

[Student Name]

University of Phoenix

DNP/715: Information Systems and Health Care Delivery Technology

Week 7 Assignment

[Instructor Name]

[Date]

The health system and events are composites written for a model paper.

What this part is doingThe title pairs a security event with an ethics problem. The reader expects each to be treated as a threat to patients.
2

I am the director of nursing informatics at a four-hospital regional health system. This year, two events brought data ethics from policy manuals into daily practice. In March, a ransomware attack encrypted our electronic record, forcing nine days of paper documentation. In June, our population health department proposed using a vendor algorithm to select patients for care management. This paper addresses both as nursing concerns.

The Scale of the Threat

Liu et al. (2015) examined breaches of protected health information reported to federal regulators from 2010 to 2013 and found that breaches affected millions of patient records, with theft the most common cause and hacking a growing share. Neprash et al. (2022) counted ransomware incidents at American care providers over six years and found the annual total climbing from 43 to 91, with nearly 42 million patients' information exposed. Almost half of attacks disrupted care, most often through system downtime, and some led to cancellations and ambulance diversion. Attacks increasingly affected large organizations and were less often restored from backups.

Our Downtime

During our nine days on paper, medication administration relied on printed lists from the day before the attack, laboratory results arrived by phone and fax, and nurses could not see prior notes. We had two medication errors reaching patients, one a duplicate dose because two paper records existed. Nurses worked overtime to transcribe paper records back into the system once it returned.

Security as Patient Safety

Ransomware is often framed as an information technology problem. Our experience, and the finding that nearly half of attacks disrupt care (Neprash et al., 2022), shows it is a patient safety problem. Nursing must be part of planning for it.

The attackers wanted money; the harm fell on a patient who got her anticoagulant twice because two paper charts existed.

What this part is doingNational data on the threat precede the local event, so the reader sees that the downtime was part of a pattern, not bad luck.
3

Nursing-Led Downtime Readiness

Proposals include: automated downtime reports of medications, allergies and recent results printed or saved to secure local devices every four hours; a single paper medication administration record per patient with a clear owner; quarterly downtime drills on each unit; and a reconciliation plan for returning to electronic records that assigns clerical staff, not nurses, to transcription.

Clinical Leadership During Downtime

During our downtime, charge nurses improvised communication with pharmacy and laboratory. A written downtime command structure, with a nursing lead for each hospital, would have reduced confusion. Security planning should name clinical leaders, not only technical ones.

Everyday Security Behaviors

Many attacks begin with phishing emails. Nurses, who make up the largest share of the workforce, are frequent targets. Brief, scenario-based training, simulated phishing tests with feedback rather than punishment and easy reporting of suspicious emails can reduce risk. Shared logins and passwords taped to workstations, still common on busy units, must end.

The Algorithm Question

Obermeyer et al. (2019) studied a widely used commercial algorithm that assigned risk scores to select patients for care management and found that Black patients assigned a given score carried a noticeably heavier burden of uncontrolled illness than White patients assigned that same score. Had the scores reflected illness rather than spending, the share of Black patients flagged for extra support would have risen from under a fifth to nearly half. The bias came from what the model was trained to forecast, which was spending rather than sickness, and because unequal access meant less was spent on Black patients with the same needs.

Applying the Lesson

Our vendor's algorithm also predicts future cost. Before adopting it, I asked our analysts to compare, among patients the algorithm would select, the number of chronic conditions and measures of control, such as A1c and blood pressure, by race. Among patients with the same score, Black patients had more chronic conditions and worse control, consistent with Obermeyer et al. (2019).

Recommendation on the Algorithm

We should not use a cost-based score to allocate care management. Alternatives include selecting patients by measures of illness, such as number of uncontrolled chronic conditions, or adjusting the algorithm's target, with an equity audit before and after adoption. Nurse care managers, who know patients' needs, should review selections.

Why Nurses Should Lead Here

Nurses are the largest group of record users, the most frequent documenters and often the first to see what happens when systems fail. They also know patients' needs in ways cost data cannot capture. These facts give nursing both the standing and the responsibility to shape security planning and algorithm governance.

Communicating With Patients

After the ransomware attack, patients whose data were exposed received letters. Several called our units confused and anxious. A plain-language script for nurses, explaining what happened, what data were involved and what patients could do, would have helped. Transparency after a breach is part of ethical data use.

Lessons From the Downtime Review

Our after-action review found that units with recent downtime drills recovered faster and had fewer errors. That finding, though from our own small sample, supports making drills routine rather than annual.

Privacy in Everyday Practice

Privacy also depends on daily behavior: viewing records only for care, avoiding curiosity lookups of colleagues or public figures and closing screens in shared spaces. Our system's access audits found 14 inappropriate views last year, most by staff checking on friends. Education and consistent consequences both matter, and nurse managers should review audit findings with staff in a way that teaches rather than only punishes. Clear examples of what counts as an inappropriate view help staff avoid mistakes made out of concern for a friend.

Monitoring After Adoption

Even a corrected algorithm can drift as populations and care patterns change. Any tool used to allocate care should be rechecked for equity at least annually, with results reported to the governance committee and published internally.

Ethical Principles Underneath

Both events involve justice and nonmaleficence. Security failures harm the patients who depend on accurate records. Biased algorithms withhold help from those who need it most. Nurses' ethical commitments to patients extend to how their data are protected and used.

Vendor Accountability

Contracts with algorithm vendors should require disclosure of what the model predicts, what data it uses and how it performs across racial and ethnic groups. Our current contract has none of these provisions. Adding them to future contracts gives the health system the standing to demand fixes.

Governance

I propose that a nurse sit on the health system's cybersecurity steering committee and its analytics governance committee, with authority to require equity audits for any algorithm used to allocate care.

Conclusion

A ransomware attack and a biased algorithm show that data security and data ethics are patient safety and justice issues. National evidence shows rising ransomware attacks that disrupt care, and a landmark study shows how cost-based algorithms can deny help to Black patients. Nursing-led downtime readiness, security practices, equity audits and a nursing voice in governance respond to both.

What this part is doingThe conclusion joins the two events under shared principles and responses. Every source cited in the paper appears in the reference list.
4

References

Liu, V., Musen, M. A., & Chou, T. (2015). Data breaches of protected health information in the United States. JAMA, 313(14), 1471-1473. https://doi.org/10.1001/jama.2015.2252

Neprash, H. T., McGlave, C. C., Cross, D. A., Virnig, B. A., Puskarich, M. A., Huling, J. D., Rozenshtein, A. Z., & Nikpay, S. S. (2022). Trends in ransomware attacks on US hospitals, clinics, and other health care delivery organizations, 2016-2021. JAMA Health Forum, 3(12), Article e224873. https://doi.org/10.1001/jamahealthforum.2022.4873

Obermeyer, Z., Powers, B., Vogeli, C., & Mullainathan, S. (2019). Dissecting racial bias in an algorithm used to manage the health of populations. Science, 366(6464), 447-453. https://doi.org/10.1126/science.aax2342

How this DNP 715 Week 7 example is structured

The DNP/715 Week 7 work usually turns to privacy, security and ethical use of data. This paper treats security and ethics as patient safety issues, analyzes two concrete events with evidence and proposes practical responses within nursing's influence. Students search this week as DNP 715 Week 7, DNP715 Wk 7 or DNP/715 Wk 7; all three are the same assignment.

DNP/715 Week 7 questions, answered

What does DNP/715 Week 7 usually ask for?

Many sections ask students to examine privacy, security and ethical issues in health data use, such as breaches, cybersecurity, consent and bias in algorithms.

How common are ransomware attacks on health care organizations?

A national analysis counted 374 attacks on U.S. care providers between 2016 and 2021, with the yearly number rising from 43 to 91; nearly 42 million patients' data were exposed, and almost half of the attacks disrupted care.

How can an algorithm be racially biased without using race?

If it predicts a proxy, such as health care costs, that differs by race because of unequal access to care, it will systematically underestimate the needs of groups who receive less care.

Write yours, or have the desk draft it

This paper is an original model document written by our desk, not a submitted student paper and not an official University of Phoenix document. Read it for the moves, then write your own to the instructions in your classroom. If you want one built to your exact prompt and rubric, the first custom sample is free and arrives in 24 to 48 hours.