HCIS 352 Week 5 Healthcare Information Data Compliance Example

Reviewed by Lenora Whitcombe, MSN, RN · University of Phoenix · Updated

This HCIS 352 Week 5 example addresses health information data compliance for technology that grew quickly without it, and the full paper is set in APA 7 style below. University of Phoenix HCIS 352 finishes with this week, and in this HCIS/352 week students in health IT and health administration connect the systems they have studied with the rules that govern the data inside them. The sample follows a composite behavioral health clinic that began video visits in 2020 using consumer apps allowed under federal enforcement discretion, then found itself out of step when that discretion ended. It reviews what HIPAA requires for telehealth platforms, business associate agreements, recordings and chat logs, how patients' rights of access and information blocking rules apply to telehealth data, and what retention and disposal policies should say. The paper closes with a compliance inventory and an annual audit cycle.

CourseHCIS 352 Foundations of it in the Health Care Environment (HCIS/352)
Week5
Paper typeData compliance review
Lengthabout 1,003 words, 4 double-spaced pages plus title page and references
FormatAPA 7 student paper
SchoolUniversity of Phoenix
ProgramBS in Health Administration
UpdatedSeptember 2026

Free sample paper for HCIS 352 Week 5

1

After the Emergency Rules Ended: Bringing a Behavioral Health Clinic's Telehealth Video, Chat and Recording Practices Into Data Compliance

[Student Name]

University of Phoenix

HCIS/352: Foundations of it in the Health Care Environment

Week 5 Assignment

[Instructor Name]

[Date]

The clinic, its practices and its changes are composites written for a model paper; legal requirements come from the sources listed.

What this part is doingThe title names the event that created the compliance gap, which frames the paper as bringing a fast-grown practice back into line.
2

In March 2020, a composite outpatient behavioral health clinic with 14 therapists and two psychiatric nurse practitioners moved almost overnight to video visits. Therapists used whichever popular video and messaging apps their clients could manage. Some recorded sessions, with consent, so supervisors could review trainees' work. Clients texted therapists' personal phones to reschedule. The arrangement kept care going through the pandemic. Three years later, the clinic's new compliance officer asked a simple question: where is all of this data, and are we allowed to keep it this way? This paper answers her question.

What the Emergency Rules Allowed

During the COVID-19 public health emergency, federal regulators said they would not penalize providers who used everyday video chat tools for telehealth in good faith, even without business associate agreements. That enforcement discretion ended in May 2023, after a transition period, and providers were expected to use platforms that meet HIPAA's requirements (U.S. Department of Health and Human Services, 2023). The clinic had never gone back to check.

Live Video

Telehealth platforms that transmit and store protected health information for the clinic are business associates and must sign a business associate agreement and meet the Security Rule's safeguards. The clinic's therapists used three different consumer apps, none under an agreement. The fix is to adopt a single telehealth platform, sign an agreement, configure waiting rooms and access controls and retire the consumer apps for clinical use.

Recordings

Session recordings are among the most sensitive data a behavioral health clinic holds. The review found 340 recordings stored in a consumer cloud folder shared by supervisors, some more than two years old. A recording kept for training but never deleted becomes a store of intimate conversations that serves no current purpose and carries risk every day it exists. The fix is a recording policy: record only for defined supervision purposes with written consent, store recordings only in the approved platform, restrict access to the supervisor and trainee, and delete them within 60 days of review.

What this part is doingEach data type is examined for what exists, what the rules require and what must change, which is the structure of a gap analysis.
3

Chat and Text Messages

Scheduling texts to personal phones mixed protected health information with personal devices. The clinic will move client messaging to the patient portal and the telehealth platform's messaging feature, and therapists will stop using personal numbers for client contact. Old messages on personal phones will be deleted after any clinically relevant content is summarized in the record, and therapists will confirm the deletion in writing to the compliance officer.

Scheduling and Other Data

The online scheduling tool, reminder texting service and a transcription feature therapists tried briefly all handled client data. Each vendor must either sign a business associate agreement or be removed.

Patient Access and Information Blocking

Clients may obtain the records in their designated record set, and federal policy now expects electronic health information to be shared with patients without unreasonable barriers. Rosenbloom et al. (2019) explained that three federal laws, HIPAA, HITECH and the 21st Century Cures Act, each push toward letting patients get their records electronically without charge, while noting inconsistencies in how the laws define what information is included. The clinic's policy will state which telehealth data, such as visit notes and messages that inform care, belong to the record and are available to clients, and which, such as supervision recordings deleted after review, do not.

Additional Protections for Behavioral Health

Psychotherapy notes kept separately by a therapist have special protection under HIPAA and are generally excluded from the right of access. State laws may add consent requirements for mental health information. The clinic's attorney will review its policies against state law.

What this part is doingBehavioral health's extra protections are noted because they change what a general HIPAA analysis would conclude.
4

Training and Accountability

Policies change nothing unless therapists know them. Every clinician will complete a 30-minute training on the new platform, recording and messaging rules, and each will sign an attestation that personal phones no longer hold client messages. Supervisors will confirm that recordings are deleted after review. The clinic director will hear quarterly from the compliance officer on training completion and any incidents, and a missed deletion or a personal-phone message will be handled first as a coaching conversation, then as a policy violation if it repeats.

Retention and Disposal

The clinic will adopt a retention schedule: clinical records kept for the period state law requires, supervision recordings for 60 days, scheduling messages for one year. Disposal will be documented, and vendors will certify deletion when contracts end.

Security Settings on the New Platform

Choosing a compliant platform is only the start; it must be configured well. The clinic will require multifactor login for clinicians, lock virtual waiting rooms so only invited clients enter, disable local downloading of recordings, set automatic logout after inactivity and turn on audit logging. Clients will join through links sent from the portal rather than by email or text. These settings put the Security Rule's technical safeguards into practice on the tool therapists use every day.

A Compliance Inventory

The compliance officer will maintain an inventory listing each system that holds client data, its vendor, whether a business associate agreement is signed, what data it holds, its retention rule and its owner. The inventory is the backbone of the program because the clinic cannot protect data it does not know it has.

Annual Audit Cycle

Each year the compliance officer will update the inventory, check a sample of recordings and messages for policy compliance, review access logs on the telehealth platform, confirm business associate agreements and report results to the clinic director. The Security Rule's requirement for ongoing risk analysis and review of safeguards (U.S. Department of Health and Human Services, 2022) will be met through this cycle.

Conclusion

Telehealth kept the clinic open in a crisis, but it scattered sensitive data across consumer apps, personal phones and shared folders. With the emergency rules ended, the clinic must bring each data type under agreements, access controls, clear retention and deletion, patient access policies and an annual audit, so that remote care can continue on a compliant footing.

5

References

Rosenbloom, S. T., Smith, J. R. L., Bowen, R., Burns, J., Riplinger, L., & Payne, T. H. (2019). Updating HIPAA for the electronic medical record era. Journal of the American Medical Informatics Association, 26(10), 1115-1119. https://doi.org/10.1093/jamia/ocz090

U.S. Department of Health and Human Services. (2022). Summary of the HIPAA security rule. https://www.hhs.gov/hipaa/for-professionals/security/laws-regulations/index.html

U.S. Department of Health and Human Services. (2023). HIPAA and telehealth. https://www.hhs.gov/hipaa/for-professionals/special-topics/telehealth/index.html

What the HCIS 352 Week 5 instructions ask

HCIS 352 Week 5 usually asks students to explain data compliance requirements for health information and how organizations meet them. Prompts may cover HIPAA's privacy and security requirements, patient access, data retention and disposal, business associate agreements, audit and monitoring, telehealth and emerging technologies, and state laws that add protections. Some sections provide a scenario, such as telemedicine or cloud storage; others ask for a general compliance program overview. Around three pages with legal and professional sources is common. Strong answers state requirements accurately, show where an organization falls short, translate rules into specific policies and controls and set up ongoing monitoring rather than treating compliance as a one-time project.

How this HCIS 352 Week 5 example is built

The paper opens with the clinic's pandemic-era setup: therapists using popular consumer video and messaging apps, some sessions recorded for supervision, chat messages on personal phones. It explains that federal enforcement discretion allowed this during the public health emergency and ended in 2023. The review then takes each data type in turn: live video, recordings, chat logs and scheduling data, stating what HIPAA requires and where the clinic falls short. A section on patient rights explains how access requests and information blocking rules reach telehealth data, drawing on an informatics analysis of how HIPAA, HITECH and the Cures Act interact. Retention and disposal policies follow. A compliance inventory and an annual audit cycle close the paper.

HCIS 352 Week 5 grading rubric: where the points go

Compliance papers are usually graded on accuracy and practicality. Faculty look for correct statements of requirements, including what changed when temporary rules ended, a clear gap analysis for the scenario and specific policies and controls to close each gap. Attention to patient rights, business associates, retention and ongoing monitoring earns credit. Use of official guidance and scholarly analysis strengthens the paper. Organized coverage, by data type or requirement, helps graders follow. Writing and citations make up the rest. Papers that describe HIPAA in general without applying it, or that stop at recommendations with no plan to check whether they are followed, usually rank below papers with a monitored compliance program.

HCIS 352 Week 5 help: mistakes to avoid

A frequent mistake in HCIS 352 Week 5 is assuming that any video tool is fine for telehealth because it was allowed in 2020. The enforcement discretion ended, so current requirements apply, including business associate agreements. Another error is forgetting data created as a side effect, such as recordings, chat messages and automatic transcripts, which are often the biggest compliance gaps. Students also skip retention and disposal, which determine how long risk lasts. Address patient access and information blocking where telehealth data become part of the record. Behavioral health often carries additional state protections, so mention them. Finally, include auditing, because a policy nobody checks is not compliance.

Related HCIS 352 sample papers

Other HCIS 352 week samples

More BS in Health Administration sample papers

HCIS 352 Week 5 questions, answered

What does HCIS/352 Week 5 usually ask for?

Many sections ask students to explain data compliance requirements for health information, such as HIPAA privacy and security, patient access, retention and business associates, often applied to a scenario like telehealth.

Where can I find a free HCIS 352 Week 5 sample paper?

The telehealth data compliance review above is the free HCIS 352 Week 5 sample, with notes on each requirement. A custom compliance paper for your own scenario is free the first time.

Can therapists still use any video app for telehealth?

No; the federal enforcement discretion that allowed many consumer apps during the COVID-19 public health emergency ended in 2023, so providers must use platforms that meet HIPAA requirements, including a business associate agreement.

Are telehealth session recordings part of the medical record?

If an organization keeps them and uses them to make decisions about patients, they can become part of the designated record set, which affects patients' access rights and retention.

What is a designated record set?

Under HIPAA, the group of records a covered entity uses to make decisions about individuals, including medical and billing records, which patients generally have a right to access.

Write yours, or have the desk draft it

This paper is an original model document written by our desk, not a submitted student paper and not an official University of Phoenix document. Read it for the moves, then write your own to the instructions in your classroom. If you want one built to your exact prompt and rubric, the first custom sample is free and arrives in 24 to 48 hours.