NURS 8210 informatics ethics and the law discussion
The Week 5 discussion asks for an ethical issue, its liabilities under the AMIA Code of Ethics, and strategies — inside 350 words. This guide covers choosing an issue narrow enough to survive that ceiling, building the bridge from an aspirational code to organisational exposure, and what a liability actually is.
Editorial process
Last reviewed · August 6, 2026
What NURS 8210 is marking in 350 words
The constraint that shapes this post is the word ceiling. Two hundred and fifty to three hundred and fifty words, excluding references, against three separate tasks: describe the issue, analyse the liabilities it poses with reference to the AMIA Code of Ethics, and formulate strategies to address it. That is roughly a hundred words each. A broad issue — data breaches, patient privacy, cybersecurity — cannot be described, mapped to a code and remediated in a hundred words apiece, so the choice of issue is the whole assignment. Pick something narrow enough to state in one sentence and specific enough that its remedy is also one sentence: shared clinical logins on a shared workstation, screens visible from a waiting area, standing access rights that outlive a rotation, clinical data reused for quality improvement without notice.
The AMIA code is not a legal instrument and the prompt does not pretend it is — it asks you to analyse liabilities by referencing the code, which is a bridge you have to build rather than a lookup. The code is explicitly aspirational and describes itself as extending beyond regulatory and legal obligations, so nothing in it creates liability by itself. The move is two-step: name the duty the practice breaches, then name the exposure that follows if the practice is discovered — regulatory, civil, contractual, professional or reputational. Posts that stop at the first step describe an ethical failing and call it a liability. Posts that skip to the second cite HIPAA and never touch the code the prompt named. Both lose the same marks, and the fix is a single connecting sentence.
Knowing how the code is organised saves you the search. It is arranged around the roles an informatics professional occupies and the constituents they serve — patients, colleagues, clinicians, researchers, students, institutions, vendors — rather than by topic. So you do not look up "access control" in it; you ask which role you are in when the practice happens and which constituent carries the cost. A standing access right that outlives a rotation is a duty owed to patients, exercised in the role of someone who administers systems, and the obligation it breaches is about limiting use of information to what the work requires. Framed that way the citation lands on a specific provision rather than on the code in general, which is the difference between referencing it and mentioning it. It also keeps the citation short, which the word budget needs.
Ethical duty in play | Practice that breaches it | The exposure that follows |
|---|---|---|
Limit access to what the work requires | Standing rights outliving a rotation | OCR finding, corrective action plan |
Protect information you hold | Shared logins on a shared workstation | No attributable audit trail; enforcement |
Be honest about secondary use | Clinical data reused for QI without notice | Contractual and research governance risk |
Safeguard information physically | Screens visible from a public area | Reportable incident, published on the breach portal |
Be precise about what a liability is, because the word does most of the work in the second task. A liability is exposure the organisation carries, not the harm a patient suffers. Regulatory exposure means an enforcement investigation and a corrective action plan; civil exposure means claims; contractual exposure means obligations flowing through business associate agreements to vendors; professional exposure means licensure consequences for the individuals; reputational exposure is concrete rather than vague, since breaches above the reporting threshold appear on a public federal portal that anyone can search by organisation name. Naming which kinds apply, rather than listing all five, is what a doctoral-level answer looks like here — and it constrains the strategies you propose in the third task. Pick the two that genuinely apply to your practice and say why the others do not, in a clause. Ruling one out is evidence you distinguished them.
The strategies have to be things the organisation can actually implement, and at this level the useful addition is sequence. Policy, access review, audit logging, physical layout and training are all legitimate answers, but they differ enormously in cost, in how fast they take effect, and in whether they address the mechanism or the behaviour. Say which one you would do first and why — usually the control that removes the possibility rather than the one that asks people to be careful — and what you would measure to know it worked. That last clause is rarely written and is the cheapest way to sound like someone who has implemented something rather than someone who has read about it. Name the measure and the interval — a quarterly access review with a count of orphaned accounts, say — rather than promising to monitor compliance.
Likely learning objectives
Inferred from the brief — check these against your own rubric.
- 01Scope an issue to fit a word ceiling rather than compressing a broad one.
- 02Connect an aspirational professional code to concrete organisational exposure.
- 03Distinguish liability from harm when analysing an information governance failure.
- 04Sequence remediation strategies and state what would demonstrate they worked.
Read the full question
Review every instruction before using the planning guidance that follows.
The initial post and the two responses
- 01A described ethical issue related to data collection or information management at an organisation you know.
- 02An analysis of the potential liabilities it poses, referencing the AMIA Code of Ethics.
- 03Strategies the organisation could implement to address the issue.
- 04250–350 words for the initial post, excluding references, by Day 3.
- 05Responses to two different colleagues, on two different days, by Day 6.
- 06Specific citations from the week's Learning Resources and additional scholarly sources, in APA.
Structuring issue, duty, exposure and strategy
The issue, in one sentence
Name a specific data collection or information management practice at a known organisation.
The duty it breaches
Locate the issue in the AMIA code by role and constituent, and name the provision.
The exposure that follows
Say which categories of liability apply — regulatory, civil, contractual, professional, reputational.
Strategies, in order
Give the controls, say which comes first, and say why.
The two responses
Probe, extend or offer an alternative supported by evidence, on two different days.
Where the AMIA code and the enforcement record live
Recommended databases
- Walden University Library
- CINAHL
- MEDLINE / PubMed
- Journal of the American Medical Informatics Association
- HHS Office for Civil Rights
Search sequence
- 1.Read the current AMIA code in full before choosing the issue — it is short, and the roles framing decides where your issue sits.
- 2.Search the federal breach portal for incidents of the same type to see how they were categorised and at what scale.
- 3.Read one or two OCR resolution agreements involving the same control failure, which state the exposure in the regulator's own words.
- 4.Check the Security Rule's administrative safeguards for the named control before proposing it.
- 5.Add one peer-reviewed source from the week's resources so the post is anchored in the course as well as in regulation.
Reference shortlist
These are authoritative starting points, not a ready-made bibliography. A qualified reviewer must confirm that each source fits the assignment and supports the claim beside which it is cited.
Nothing here is cleared for citation until you have read it.
- 01
AMIA's code of professional and ethical conduct 2022
Journal of the American Medical Informatics Association, via PubMed Central · 2022
The code the prompt names, in its current version. Note its own statement that it is aspirational and extends beyond regulatory and legal obligations — that is the sentence the liability bridge has to cross.
- 02
Resolution Agreements
Office for Civil Rights, US Department of Health and Human Services · 2026
Actual enforcement outcomes with corrective action plans. Two entries — a Colorado hospital and a city health department, both for failing to terminate a former employee's access — match the standing-access example exactly, which turns an asserted liability into a documented one.
- 03
Breach Portal — Office for Civil Rights
Office for Civil Rights, US Department of Health and Human Services · 2026
The public, searchable record of reportable breaches, listed by organisation name. It is what makes reputational exposure a concrete claim rather than a rhetorical one.
- 04
The Security Rule
US Department of Health and Human Services · 2026
The administrative, physical and technical safeguards. Check the control you propose against the standard it implements, so the strategy section names a requirement rather than a good idea.
- 05
Code of Ethics for Nurses
American Nurses Association · 2025
The nursing duty that runs alongside the informatics one. Useful when the practice you choose is carried out by clinical staff rather than by systems administrators.
Before the Day 3 post goes up
Common mistakes
- Choosing an issue too broad to describe, analyse and remediate in roughly a hundred words each.
- Citing the AMIA code without naming the specific duty the practice breaches.
- Treating an ethical failing as a liability without saying what exposure follows from it.
- Describing patient harm when the question asks about liabilities to the organisation.
- Proposing every control at once rather than sequencing them and defending the first.
- Writing about a hypothetical breach instead of an actual practice at a known organisation.
- Directly quoting source material, which this rubric penalises rather than rewards.
Submission checklist
- The issue is stated in one sentence and is a practice, not an incident.
- A specific AMIA duty is named, not the code in general.
- One sentence connects the breached duty to a named category of exposure.
- Liabilities are exposure to the organisation, not harms to patients.
- Strategies are sequenced, with the first one defended.
- Something measurable is named as evidence the strategy worked.
- 250–350 words excluding references; no direct quotations.
Use this guide to plan and review your own work. Follow your institution's rules and read our academic-integrity policy.

Written by
Aaron Bishop
MA, Education
assignment interpretation and research-methods coaching across disciplines
Aaron leads the EssayCrackers editorial desk. He works on how assignment briefs are read — what a rubric is actually asking for, and where students most often answer a different question than the one set.

Reviewed by
Dr. Nathan Cole
PhD, Rhetoric & Composition
Argumentation and thesis development
Nathan teaches first-year composition and directs a university writing center. He reviews EssayCrackers guides for argumentative soundness and citation accuracy.