HLTH 6443 Module 4 Data Use and Security Protocols Example

Reviewed by Cornelius Ravenhill, MBA · American College of Education · Updated

This HLTH 6443 Module 4 example writes data use and security protocols for a county's closed-loop community referral network, formatted in APA 7 with a section on families' rights. It belongs to American College of Education HLTH 6443, Systems, Policy, and Leadership in Health Informatics, the HLTH6443 class in ACE's Ed.S. in Public Health Education. Eight protocols, account access, role-based viewing, consent verification and data entry, secure messaging and devices, retention, audits, incident response and data requests, are arranged under the six functions of the NIST Cybersecurity Framework 2.0. Sittig and Singh's sociotechnical model supports monthly audits, and Cartier's study of early adopters supports written data-use agreements with community agencies.

CourseHLTH 6443 Systems, Policy, and Leadership in Health Informatics
ModuleModule 4
Paper typeProtocol set
Length1,280 words, about 5 pages plus title and reference pages
FormatAPA 7 student paper
SchoolAmerican College of Education
ProgramEd.S. in Public Health Education
UpdatedSeptember 2026

Free sample paper for HLTH 6443 Module 4

1

Who May Open a Referral, and What Happens When Someone Should Not Have: Data Use and Security Protocols for a County Referral Network

Student Name

American College of Education

HLTH6443: Systems, Policy, and Leadership in Health Informatics

Module 4 Assignment

Instructor Name

June 22, 2026

What this page is doingThe title poses the two questions every protocol set must answer, who is allowed in and what happens after a mistake, then names the system, which tells the grader the paper covers prevention and response.
2

Introduction

Module 2 set the rules for the referral platform in a composite western Michigan county, including one written consent used by everyone and minimum security rules for all 64 agencies, and Module 3 planned how users will be trained. Rules and training need written procedures that tell staff exactly what to do. This paper presents eight protocols for data use and security. They are organized by the six functions in version 2.0 of NIST's Cybersecurity Framework, govern, identify, protect, detect, respond and recover, which gives a structure recognized across sectors and suited to a network that includes organizations with no security staff of their own (National Institute of Standards and Technology, 2024).

3

Govern and Identify

The framework's govern function sets roles, policy and oversight, and its identify function asks an organization to know its assets and risks. The network's privacy and data governance committee, established in Module 2, owns all eight protocols, reviews them yearly and approves exceptions in writing. The platform coordinator maintains an inventory of what the platform holds, including family names, contact details, need categories, consent records, referral notes and outcomes, and a list of every participating organization, its users and their roles. A risk review each spring asks which data would cause the most harm if exposed and which participants are most vulnerable, starting with agencies that share computers or rely on volunteers.

What this page is doingGrouping the protocols under a recognized framework's functions shows the reader the set is complete, covering prevention, detection and response rather than only passwords.
4

Protocol 1: Account Access

Every user has an individual account; shared logins are prohibited. An agency director requests an account for a staff member by form, confirming the person's role and completion of training. Accounts use multifactor authentication. When a staff member leaves or changes roles, the director notifies the coordinator within one business day and access is removed the same day. The coordinator reviews all accounts quarterly and disables any unused for 90 days, a necessary step in a network where a third of receiving staff turn over each year.

5

Protocol 2: Role-Based Viewing

Users see only what their role requires. Referring staff see referrals they sent and their outcomes. Receiving staff see referrals sent to their agency, with the family's contact details, the type of need and a free-text note limited to 300 characters. Administrators see their agency's referrals and aggregate reports. No agency can search the platform for a family it has not received a referral for. The health department's reporting analyst sees de-identified data only.

6

Protocol 3: Consent Verification and Data Entry

Before sending a referral, the referring user confirms that a signed consent is on file for the specific agency and records its date; the platform blocks referrals without a consent record. For school referrals, the consent must be signed by a parent. Referral notes contain only what the receiving agency needs to act: for example, household size and the date by which a utility shutoff will occur, but not diagnoses, immigration status, criminal history or details of abuse. If a family revokes consent, the referring user records the revocation, open referrals close automatically and the receiving agency is notified that no further contact should occur.

7

Protocol 4: Secure Communication, Devices and Sessions

Information about a family is exchanged inside the platform, never by personal email or text. Text messages to families say only that a referral was sent or accepted and give the agency's name and phone number. Users access the platform only on devices with screen locks, may not download referral lists and are logged out automatically after 15 minutes of inactivity. On shared computers, such as those at small pantries, users must log out after each session, and the job aid posted beside the computer reminds them.

8

Protocol 5: Retention

Closed referrals remain visible to users for 12 months to allow follow-up and then are archived, accessible only to the coordinator for audit or legal needs. Consent forms are kept for the longer of the consent's term or the state's records retention period. De-identified data used for reports are kept indefinitely.

9

Protocol 6: Detecting Misuse

The platform logs every view and change. Monthly, the coordinator runs audit reports that flag unusual activity, such as a user viewing many referrals outside business hours, a user viewing referrals after being reported as departed or repeated failed logins. Any flagged pattern is reviewed with the agency director within five business days. The point of auditing is not to catch staff out but to find problems while they are small. Monitoring the system in use is one of the dimensions that sociotechnical analysis treats as essential to safe health information technology (Sittig & Singh, 2010).

10

Protocol 7: Incident Response and Recovery

Any user who suspects that family information was seen or sent by someone who should not have it, such as a referral sent to the wrong agency or a lost laptop with an open session, reports it to the coordinator the same day using a short form. The coordinator contains the incident, for example by disabling an account or recalling a referral, and notifies the privacy officer. The privacy officer determines, with the county attorney, whether breach notification laws apply; for covered participants, the HIPAA breach notification rule requires that affected people be told promptly, with a 60-day outer limit counted from when the breach comes to light. Families affected by any incident are told what happened and what is being done, whether or not the law requires notice. After each incident, the committee reviews what went wrong and changes protocols or training if needed. Recovery planning includes the vendor's backup and restoration commitments, tested once a year.

11

Families' Rights Within the Protocols

Protocols usually speak to staff, but families have rights in the system too, and the network will write them down. A family may ask any participating organization what information about them is in the platform, and the coordinator will provide a plain-language summary within 30 days. A family may ask to correct an error, such as a wrong phone number or a need recorded incorrectly, and the referring organization will fix it or explain why it cannot. A family may withdraw consent at any time, as Protocol 3 describes, and may ask that future referrals not be made. Complaints about how information was handled go to the privacy officer, who responds in writing. Each family receives a one-page notice of these rights with the consent form, in the family's own language. Stating these rights plainly is itself a trust-building measure, since many families have had reason to doubt what happens to information they give agencies.

12

Protocol 8: Requests to Use Platform Data

Agencies, the health department and outside researchers may ask to use platform data for reports, grants or evaluation. Requests go to the governance committee in writing, stating the purpose, the data needed and how they will be protected. Routine reports use de-identified counts, with any cell smaller than 11 suppressed. Requests involving identifiable data require a data-use agreement and, for research, review by an institutional review board. Early adopters of similar platforms found that clear agreements about data sharing were part of what allowed partnerships with community organizations to work (Cartier et al., 2020).

13

Conclusion

These protocols translate rules into daily practice. Organized by the NIST functions, they govern the network, identify its data and risks, protect access and information, detect misuse, respond to incidents and plan for recovery. Simple enough for a volunteer at a pantry and firm enough for a clinic, they give every participant the same expectations. Module 5 turns to interoperability, since reducing double entry is essential to getting agencies to use the platform at all.

14

References

Cartier, Y., Fichtenberg, C., & Gottlieb, L. M. (2020). Implementing community resource referral technology: Facilitators and barriers described by early adopters. Health Affairs, 39(4), 662-669. https://doi.org/10.1377/hlthaff.2019.01588

National Institute of Standards and Technology. (2024). The NIST Cybersecurity Framework (CSF) 2.0 (NIST CSWP 29). https://doi.org/10.6028/NIST.CSWP.29

Sittig, D. F., & Singh, H. (2010). A new sociotechnical model for studying health information technology in complex adaptive healthcare systems. Quality and Safety in Health Care, 19(Suppl. 3), i68-i74. https://doi.org/10.1136/qshc.2010.042085

HLTH 6443 Module 4 instructions, in plain terms

In many sections, the fourth HLTH 6443 module asks for written protocols. A typical prompt wants procedures for how staff access a system, what data they may view and enter, how information is protected in transit and on devices, how long records are kept, how misuse is detected and what happens after a breach. Some instructors name a security framework; others ask you to justify your own structure. Protocols should be specific enough that a new employee could follow them on the first day without asking for help. Build on the legal requirements from Module 2 and keep in mind the users your training plan identified. Many instructors also appreciate protocols that state the rights of the people whose data the system holds.

How this HLTH 6443 Module 4 example is built

An introduction ties the protocols to the rules and training from the previous two modules and introduces the NIST functions as the organizing structure. A section on governance and identification assigns ownership and describes the data inventory and annual risk review. Eight protocol sections follow, each written as steps with time limits, roles and examples, such as disabling unused accounts at 90 days or suppressing counts under 11. Incident response includes notification duties and a lessons-learned review. A section written for families sets out their rights to see, correct and withdraw their information, and a brief conclusion links the protocols to interoperability in the next module.

Reading the HLTH 6443 Module 4 rubric

Protocol papers are generally graded on specificity, completeness and alignment with requirements. Rubrics tend to reward procedures with clear steps, responsible roles and time frames, coverage of prevention, detection and response and consistency with the laws and policies identified earlier. Using a recognized framework to show that nothing important is missing adds credibility and makes the set easier to audit. Attention to the realities of users, such as shared computers or high turnover, shows practical judgment. APA 7 citations for security frameworks and supporting research complete the protocols. Including the rights of the people whose information is held shows an understanding that security serves people, not only systems.

Common HLTH 6443 Module 4 mistakes, and how to avoid them

Security protocols often read as general promises to protect data rather than steps anyone could follow. If you need help writing procedures for access, consent, auditing or breach response, or organizing them under a framework, a writer can support you. Describe your system, its users and the rules that apply, attach the prompt, and the Module 4 paper that results will set out protocols with roles, steps and time limits. If your organization already follows a security standard, the protocols will map to it. A simple incident report form can be drafted too, along with a plain-language notice of rights for families or clients.

Write yours, or have the desk draft it

This paper is an original model document written by our desk, not a submitted student paper and not an official American College of Education document. Read it for the moves, then write your own to the instructions in your classroom. If you want one built to your exact prompt and rubric, the first custom sample is free and arrives in 24 to 48 hours.

More HLTH 6443 and Ed.S. in Public Health Education sample papers

HLTH 6443 Module 4 questions, answered

What does HLTH6443 Module 4 usually ask for?

In many HLTH6443 sections, Module 4 is where written protocols come in: how data in a system are used, protected, watched and handled after a mistake.

What are the functions of the NIST Cybersecurity Framework 2.0?

Govern, identify, protect, detect, respond and recover.

What is role-based access?

A way of limiting what each user can see and do in a system to what their job requires, so staff see only the records they need.

Where can I find a free HLTH 6443 Module 4 sample paper?

You can read the full Module 4 paper here: eight access, consent, messaging, retention, audit, incident and data-request protocols for a county referral network, organized by NIST functions.

Why suppress small numbers in reports?

Very small counts can allow readers to identify individuals, so many organizations hide any count below a set threshold, such as 11.