| Course | HLTH 5443 Technology, Leadership, and Health Informatics |
|---|---|
| Module | Module 4 |
| Paper type | Privacy, security and compliance analysis |
| Length | 1,180 words, about 4 pages plus title and reference pages |
| Format | APA 7 student paper |
| School | American College of Education |
| Program | M.Ed. in Health and Wellness Education |
| Updated | September 2026 |
Free sample paper for HLTH 5443 Module 4
Whose Data Is a Puff? Privacy, Security and Compliance Requirements for a Smart Inhaler Pilot With Adolescents
Student Name
American College of Education
HLTH5443: Technology, Leadership, and Health Informatics
Module 4 Assignment
Instructor Name
October 26, 2026
Introduction
The earlier papers in this series weighed smart inhaler sensors for teenagers with persistent asthma in a composite county school health program, planned how the program would use the data and addressed access and literacy barriers. Every part of that plan handles sensitive information about minors: when they use medicine, how often they struggle to breathe and, in some app versions, where they are when symptoms occur. This paper identifies which privacy laws apply to the data at each point, examines the risks that go beyond legal requirements and sets out the safeguards and protocols the program will adopt before the pilot begins.
Mapping the Data and Its Holders
Compliance starts with knowing who holds what. Three parties will hold pilot data. The vendor holds all sensor records, account details and any location data on its servers. The county health department's school health program, through its care coordinator, views the vendor's dashboard and stores monthly exports. School nurses, who are district employees in most county schools, view dashboard data for their own students and record related notes in the school health record. The student and family hold the app on their phones. Each holder may fall under a different legal regime, and the same fact, a spike in rescue use, may be governed by different rules depending on where it sits.
HIPAA and the Vendor
The Health Insurance Portability and Accountability Act and its privacy and security rules apply to covered entities, such as health care providers that bill electronically and health plans, and to their business associates, which handle protected health information on their behalf (Health Insurance Portability and Accountability Act, 1996). The county health department's clinical programs are a covered component of the county, and the school health program operates under its policies. When the program contracts with the vendor to collect and store students' inhaler data for care management, the vendor acts as a business associate. The program therefore must sign a business associate agreement requiring the vendor to use the data only for the contracted purposes, protect them with appropriate safeguards, report breaches and return or destroy data at the end of the contract. Without such an agreement, the program should not proceed.
FERPA and School Nurses
Information that school nurses record in the school health record is generally part of the education record governed by student privacy law, not by HIPAA, a distinction explained in federal joint guidance (U.S. Department of Health and Human Services & U.S. Department of Education, 2019). This matters because the rules for disclosure differ. Notes a nurse writes after reviewing a student's dashboard alert become education records that parents may inspect and that the school generally cannot disclose to outside parties without written consent. The program's consent form must therefore cover both flows: the county program's sharing of sensor data with the school nurse and the nurse's sharing of relevant school information back to the program.
When HIPAA Does Not Apply
Some data may fall outside both laws. If a student downloads the vendor's consumer app independently, outside the program, the vendor holds those data as an ordinary consumer company. For that situation, a federal consumer protection rule requires vendors of personal health records and related apps that are not covered by HIPAA to notify users and the Commission after a breach of identifiable health information, including an unauthorized disclosure (Health Breach Notification Rule, 2024). Beyond breach notification, consumer health apps are governed mainly by their own privacy policies and by state laws that vary. The gap matters because app data sharing is common. Grundy et al. (2019) found that 19 of 24 medicines-related apps they analyzed shared user data with other entities, including companies providing analytics and advertising, and that some companies in the network could aggregate and potentially re-identify users. The program should confirm, in writing, that data collected through the pilot will not be shared for advertising or analytics beyond the contract, and should turn off optional features, such as location tracking, that are not needed.
Consent From Parents and Teens
Because participants are minors, parents or guardians must generally give consent for enrollment and data sharing. Adolescents deserve a meaningful voice as well, both ethically and practically, since teenagers who feel watched may remove the sensor. The program will obtain written parental permission and the student's own assent, using plain-language forms in English and Spanish that explain what the sensor records, who sees it, how long it is kept and how to withdraw. Students will be able to choose whether their data are shared with their parents through the app, within limits set by the program's safety protocol: if data suggest a serious risk, such as very frequent nighttime rescue use, the nurse will contact the family regardless. The forms will state this limit clearly so that no one is surprised.
Security Safeguards
Security protects data from unauthorized access, and it has three dimensions. Administrative safeguards include a written security policy for the pilot, a risk assessment before launch, role-based access that limits dashboard accounts to the care coordinator and nurses for their own schools, training for every user and a procedure for closing accounts when staff leave. Physical safeguards include keeping exports on the county's secure network rather than personal devices and securing any school tablets used for syncing. Technical safeguards include unique logins with two-step verification, automatic timeouts, encryption of data in transit and at rest, which the business associate agreement will require of the vendor, and audit logs showing who viewed which records. Sensors and phones lost by students will be deactivated and unlinked from accounts promptly.
Protocols and Compliance Monitoring
Written protocols translate these requirements into daily practice. The program will adopt an enrollment protocol covering consent, assent, device setup and privacy explanations; a data access protocol defining who may see what; an alert response protocol linking dashboard flags to nurse actions and documentation; a breach response protocol naming who investigates, who notifies families and regulators and within what time; and an end-of-pilot protocol for data return or destruction. Compliance will be monitored by a quarterly review of access logs, a check that consent forms are on file for every enrolled student and an annual review of the vendor's security attestations. The county's privacy officer will approve the protocols before enrollment begins, and the district's counsel will review the parts involving school records.
Conclusion
A smart inhaler pilot with adolescents sits at the intersection of health privacy law, student privacy law and consumer technology rules. HIPAA governs the program's relationship with the vendor through a business associate agreement; student privacy law governs what school nurses record; the FTC's breach rule and contract terms fill gaps for data outside HIPAA; and consent from parents and assent from teens respect both law and autonomy. Administrative, physical and technical safeguards, written protocols and regular monitoring put these requirements into practice. Module 5 will build them into the program's plan for rolling out the technology and training its users.
References
Grundy, Q., Chiu, K., Held, F., Continella, A., Bero, L., & Holz, R. (2019). Data sharing practices of medicines related apps and the mobile ecosystem: Traffic, content, and network analysis. BMJ, 364, l920. https://doi.org/10.1136/bmj.l920
Health Breach Notification Rule, 16 C.F.R. pt. 318 (2024).
Health Insurance Portability and Accountability Act of 1996, Pub. L. No. 104-191, 110 Stat. 1936 (1996).
U.S. Department of Health and Human Services & U.S. Department of Education. (2019). Joint guidance on the application of the Family Educational Rights and Privacy Act (FERPA) and the Health Insurance Portability and Accountability Act of 1996 (HIPAA) to student health records. https://studentprivacy.ed.gov/resources/joint-guidance-application-ferpa-and-hipaa-student-health-records
The HLTH 5443 Module 4 assignment instructions
Module 4 of HLTH 5443 usually asks you to analyze the privacy, security and compliance issues raised by a health technology. Prompts commonly expect you to identify which laws and regulations apply, explain what they require, examine risks beyond legal minimums and describe the safeguards, policies and protocols an organization should adopt. Map the data first: who collects it, who stores it and who sees it, since different rules may apply to each. Include consent, especially for minors or other protected groups. Stay with the technology and setting from earlier modules. Check Canvas for whether you should cite the regulations directly and whether a protocol or policy excerpt should be attached.
How this HLTH 5443 Module 4 example is built
The example maps three holders of inhaler data, the vendor, the county program and school nurses, and then applies the relevant rules to each: HIPAA and a business associate agreement for the vendor, student privacy law for nurses' records and the FTC breach rule for data outside HIPAA. Evidence on app data sharing shapes contract terms. Sections address consent and assent for minors, the three kinds of security safeguards and five written protocols with compliance monitoring, and the conclusion links them to the rollout plan in Module 5. Throughout, the paper distinguishes legal requirements from good practice, so readers can see which safeguards are mandatory and which are chosen for the students' benefit.
Reading the HLTH 5443 Module 4 rubric
Graders typically reward accurate identification of which rules apply to which data, rather than a general statement that HIPAA covers everything. Explaining gaps, such as consumer apps outside HIPAA, shows depth. Consent for minors and respect for their autonomy are often expected in education settings. Safeguards should be concrete and organized, and protocols should turn requirements into practice. Recognizing when to involve a privacy officer or counsel shows professional judgment. APA 7 legal citations for statutes, rules and guidance complete a strong paper. Separating what the law requires from what good practice adds, and explaining the program's choices on each, shows mature compliance thinking.
Common HLTH 5443 Module 4 mistakes, and how to avoid them
Compliance papers intimidate many students because the rules overlap. If you are unsure whether HIPAA, FERPA or consumer rules apply to your technology, how to handle consent for minors or which safeguards to describe, we can help. Tell us the technology, the organization and who will hold the data, and paste in the instructions. The Module 4 paper we return will match each data flow to the rules that govern it, explain the gaps between those rules and finish with safeguards and written protocols your organization could put in place before launch. We cite statutes and guidance in proper APA 7 legal form, and we flag any point where your own state's law or your organization's counsel should have the final word.
Write yours, or have the desk draft it
This paper is an original model document written by our desk, not a submitted student paper and not an official American College of Education document. Read it for the moves, then write your own to the instructions in your classroom. If you want one built to your exact prompt and rubric, the first custom sample is free and arrives in 24 to 48 hours.
More HLTH 5443 and M.Ed. in Health and Wellness Education sample papers
- HLTH 5443 Module 1: Technology Evaluation
- HLTH 5443 Module 2: Health Informatics Analysis
- HLTH 5443 Module 3: Access and Literacy Analysis
- HLTH 5443 Module 5: Adoption and Training Plan
- HLTH 5473 Module 1: School Community Assessment
- HLTH 5473 Module 4: Health Challenge Analysis
- HLTH 5423 Module 4: Comparing Education Approaches
- HLTH 5413 Module 2: Policy Influences Analysis
HLTH 5443 Module 4 questions, answered
What does HLTH5443 Module 4 usually ask for?
The fourth HLTH5443 module typically asks you to identify the privacy, security and compliance requirements that apply to a health technology and to describe the safeguards and protocols an organization should adopt.
When is an app vendor a HIPAA business associate?
When it creates, receives, maintains or transmits protected health information on behalf of a covered entity, such as a health department program that contracts with it for care management.
Which rules cover health apps outside HIPAA?
The FTC's Health Breach Notification Rule requires many non-HIPAA health apps to report breaches, and state laws and the app's own privacy policy also apply.
Where can I find a free HLTH 5443 Module 4 sample paper?
This page holds a whole Module 4 compliance paper on a smart inhaler pilot with teens, covering HIPAA, business associate agreements, FERPA, the FTC breach rule, consent, app data sharing and safeguards.
What are administrative, physical and technical safeguards?
Administrative safeguards are policies, training and access rules; physical safeguards protect devices and locations; technical safeguards include logins, encryption and audit logs.