HLTH 5443 Module 4 Privacy, Security and Compliance Analysis Example

Reviewed by Cornelius Ravenhill, MBA · American College of Education · Updated

This HLTH 5443 Module 4 example works out the privacy, security and compliance requirements for a smart inhaler pilot with adolescents, set in APA 7. Its intended course is American College of Education HLTH 5443, Technology, Leadership, and Health Informatics, the HLTH5443 course offered in ACE's health and wellness M.Ed. It maps who holds the data, explains why the vendor must sign a HIPAA business associate agreement, why nurses' notes fall under student privacy law and how the FTC's Health Breach Notification Rule covers apps outside HIPAA. Grundy's finding that 19 of 24 medicines apps shared user data drives contract limits. Parental consent with teen assent, administrative, physical and technical safeguards and five written protocols complete the analysis.

CourseHLTH 5443 Technology, Leadership, and Health Informatics
ModuleModule 4
Paper typePrivacy, security and compliance analysis
Length1,180 words, about 4 pages plus title and reference pages
FormatAPA 7 student paper
SchoolAmerican College of Education
ProgramM.Ed. in Health and Wellness Education
UpdatedSeptember 2026

Free sample paper for HLTH 5443 Module 4

1

Whose Data Is a Puff? Privacy, Security and Compliance Requirements for a Smart Inhaler Pilot With Adolescents

Student Name

American College of Education

HLTH5443: Technology, Leadership, and Health Informatics

Module 4 Assignment

Instructor Name

October 26, 2026

What this page is doingThe title asks the ownership question in the plainest terms, then names the three domains analyzed and the population, so the grader sees a compliance analysis tied to one tool. The APA 7 title page carries the course line and module assignment.
2

Introduction

The earlier papers in this series weighed smart inhaler sensors for teenagers with persistent asthma in a composite county school health program, planned how the program would use the data and addressed access and literacy barriers. Every part of that plan handles sensitive information about minors: when they use medicine, how often they struggle to breathe and, in some app versions, where they are when symptoms occur. This paper identifies which privacy laws apply to the data at each point, examines the risks that go beyond legal requirements and sets out the safeguards and protocols the program will adopt before the pilot begins.

3

Mapping the Data and Its Holders

Compliance starts with knowing who holds what. Three parties will hold pilot data. The vendor holds all sensor records, account details and any location data on its servers. The county health department's school health program, through its care coordinator, views the vendor's dashboard and stores monthly exports. School nurses, who are district employees in most county schools, view dashboard data for their own students and record related notes in the school health record. The student and family hold the app on their phones. Each holder may fall under a different legal regime, and the same fact, a spike in rescue use, may be governed by different rules depending on where it sits.

4

HIPAA and the Vendor

The Health Insurance Portability and Accountability Act and its privacy and security rules apply to covered entities, such as health care providers that bill electronically and health plans, and to their business associates, which handle protected health information on their behalf (Health Insurance Portability and Accountability Act, 1996). The county health department's clinical programs are a covered component of the county, and the school health program operates under its policies. When the program contracts with the vendor to collect and store students' inhaler data for care management, the vendor acts as a business associate. The program therefore must sign a business associate agreement requiring the vendor to use the data only for the contracted purposes, protect them with appropriate safeguards, report breaches and return or destroy data at the end of the contract. Without such an agreement, the program should not proceed.

5

FERPA and School Nurses

Information that school nurses record in the school health record is generally part of the education record governed by student privacy law, not by HIPAA, a distinction explained in federal joint guidance (U.S. Department of Health and Human Services & U.S. Department of Education, 2019). This matters because the rules for disclosure differ. Notes a nurse writes after reviewing a student's dashboard alert become education records that parents may inspect and that the school generally cannot disclose to outside parties without written consent. The program's consent form must therefore cover both flows: the county program's sharing of sensor data with the school nurse and the nurse's sharing of relevant school information back to the program.

6

When HIPAA Does Not Apply

Some data may fall outside both laws. If a student downloads the vendor's consumer app independently, outside the program, the vendor holds those data as an ordinary consumer company. For that situation, a federal consumer protection rule requires vendors of personal health records and related apps that are not covered by HIPAA to notify users and the Commission after a breach of identifiable health information, including an unauthorized disclosure (Health Breach Notification Rule, 2024). Beyond breach notification, consumer health apps are governed mainly by their own privacy policies and by state laws that vary. The gap matters because app data sharing is common. Grundy et al. (2019) found that 19 of 24 medicines-related apps they analyzed shared user data with other entities, including companies providing analytics and advertising, and that some companies in the network could aggregate and potentially re-identify users. The program should confirm, in writing, that data collected through the pilot will not be shared for advertising or analytics beyond the contract, and should turn off optional features, such as location tracking, that are not needed.

7

Consent From Parents and Teens

Because participants are minors, parents or guardians must generally give consent for enrollment and data sharing. Adolescents deserve a meaningful voice as well, both ethically and practically, since teenagers who feel watched may remove the sensor. The program will obtain written parental permission and the student's own assent, using plain-language forms in English and Spanish that explain what the sensor records, who sees it, how long it is kept and how to withdraw. Students will be able to choose whether their data are shared with their parents through the app, within limits set by the program's safety protocol: if data suggest a serious risk, such as very frequent nighttime rescue use, the nurse will contact the family regardless. The forms will state this limit clearly so that no one is surprised.

8

Security Safeguards

Security protects data from unauthorized access, and it has three dimensions. Administrative safeguards include a written security policy for the pilot, a risk assessment before launch, role-based access that limits dashboard accounts to the care coordinator and nurses for their own schools, training for every user and a procedure for closing accounts when staff leave. Physical safeguards include keeping exports on the county's secure network rather than personal devices and securing any school tablets used for syncing. Technical safeguards include unique logins with two-step verification, automatic timeouts, encryption of data in transit and at rest, which the business associate agreement will require of the vendor, and audit logs showing who viewed which records. Sensors and phones lost by students will be deactivated and unlinked from accounts promptly.

9

Protocols and Compliance Monitoring

Written protocols translate these requirements into daily practice. The program will adopt an enrollment protocol covering consent, assent, device setup and privacy explanations; a data access protocol defining who may see what; an alert response protocol linking dashboard flags to nurse actions and documentation; a breach response protocol naming who investigates, who notifies families and regulators and within what time; and an end-of-pilot protocol for data return or destruction. Compliance will be monitored by a quarterly review of access logs, a check that consent forms are on file for every enrolled student and an annual review of the vendor's security attestations. The county's privacy officer will approve the protocols before enrollment begins, and the district's counsel will review the parts involving school records.

10

Conclusion

A smart inhaler pilot with adolescents sits at the intersection of health privacy law, student privacy law and consumer technology rules. HIPAA governs the program's relationship with the vendor through a business associate agreement; student privacy law governs what school nurses record; the FTC's breach rule and contract terms fill gaps for data outside HIPAA; and consent from parents and assent from teens respect both law and autonomy. Administrative, physical and technical safeguards, written protocols and regular monitoring put these requirements into practice. Module 5 will build them into the program's plan for rolling out the technology and training its users.

11

References

Grundy, Q., Chiu, K., Held, F., Continella, A., Bero, L., & Holz, R. (2019). Data sharing practices of medicines related apps and the mobile ecosystem: Traffic, content, and network analysis. BMJ, 364, l920. https://doi.org/10.1136/bmj.l920

Health Breach Notification Rule, 16 C.F.R. pt. 318 (2024).

Health Insurance Portability and Accountability Act of 1996, Pub. L. No. 104-191, 110 Stat. 1936 (1996).

U.S. Department of Health and Human Services & U.S. Department of Education. (2019). Joint guidance on the application of the Family Educational Rights and Privacy Act (FERPA) and the Health Insurance Portability and Accountability Act of 1996 (HIPAA) to student health records. https://studentprivacy.ed.gov/resources/joint-guidance-application-ferpa-and-hipaa-student-health-records

The HLTH 5443 Module 4 assignment instructions

Module 4 of HLTH 5443 usually asks you to analyze the privacy, security and compliance issues raised by a health technology. Prompts commonly expect you to identify which laws and regulations apply, explain what they require, examine risks beyond legal minimums and describe the safeguards, policies and protocols an organization should adopt. Map the data first: who collects it, who stores it and who sees it, since different rules may apply to each. Include consent, especially for minors or other protected groups. Stay with the technology and setting from earlier modules. Check Canvas for whether you should cite the regulations directly and whether a protocol or policy excerpt should be attached.

How this HLTH 5443 Module 4 example is built

The example maps three holders of inhaler data, the vendor, the county program and school nurses, and then applies the relevant rules to each: HIPAA and a business associate agreement for the vendor, student privacy law for nurses' records and the FTC breach rule for data outside HIPAA. Evidence on app data sharing shapes contract terms. Sections address consent and assent for minors, the three kinds of security safeguards and five written protocols with compliance monitoring, and the conclusion links them to the rollout plan in Module 5. Throughout, the paper distinguishes legal requirements from good practice, so readers can see which safeguards are mandatory and which are chosen for the students' benefit.

Reading the HLTH 5443 Module 4 rubric

Graders typically reward accurate identification of which rules apply to which data, rather than a general statement that HIPAA covers everything. Explaining gaps, such as consumer apps outside HIPAA, shows depth. Consent for minors and respect for their autonomy are often expected in education settings. Safeguards should be concrete and organized, and protocols should turn requirements into practice. Recognizing when to involve a privacy officer or counsel shows professional judgment. APA 7 legal citations for statutes, rules and guidance complete a strong paper. Separating what the law requires from what good practice adds, and explaining the program's choices on each, shows mature compliance thinking.

Common HLTH 5443 Module 4 mistakes, and how to avoid them

Compliance papers intimidate many students because the rules overlap. If you are unsure whether HIPAA, FERPA or consumer rules apply to your technology, how to handle consent for minors or which safeguards to describe, we can help. Tell us the technology, the organization and who will hold the data, and paste in the instructions. The Module 4 paper we return will match each data flow to the rules that govern it, explain the gaps between those rules and finish with safeguards and written protocols your organization could put in place before launch. We cite statutes and guidance in proper APA 7 legal form, and we flag any point where your own state's law or your organization's counsel should have the final word.

Write yours, or have the desk draft it

This paper is an original model document written by our desk, not a submitted student paper and not an official American College of Education document. Read it for the moves, then write your own to the instructions in your classroom. If you want one built to your exact prompt and rubric, the first custom sample is free and arrives in 24 to 48 hours.

More HLTH 5443 and M.Ed. in Health and Wellness Education sample papers

HLTH 5443 Module 4 questions, answered

What does HLTH5443 Module 4 usually ask for?

The fourth HLTH5443 module typically asks you to identify the privacy, security and compliance requirements that apply to a health technology and to describe the safeguards and protocols an organization should adopt.

When is an app vendor a HIPAA business associate?

When it creates, receives, maintains or transmits protected health information on behalf of a covered entity, such as a health department program that contracts with it for care management.

Which rules cover health apps outside HIPAA?

The FTC's Health Breach Notification Rule requires many non-HIPAA health apps to report breaches, and state laws and the app's own privacy policy also apply.

Where can I find a free HLTH 5443 Module 4 sample paper?

This page holds a whole Module 4 compliance paper on a smart inhaler pilot with teens, covering HIPAA, business associate agreements, FERPA, the FTC breach rule, consent, app data sharing and safeguards.

What are administrative, physical and technical safeguards?

Administrative safeguards are policies, training and access rules; physical safeguards protect devices and locations; technical safeguards include logins, encryption and audit logs.