Core Issue: Credential Sharing in the Electronic Health Record
The situation presents a conflict between workflow convenience and information security. A barangay health worker (BHW) requests use of the nurse’s login because her own account is not yet active. The correct action is to
decline and have the BHW’s own account activated first. This is not about being unhelpful; it is about preserving the integrity of the
audit trail and protecting
sensitive personal information under the Data Privacy Act (RA 10173).
Every user must have a unique, personal account because role-based access and audit logs must show exactly who entered, modified, or viewed each client record. When a BHW uses the nurse’s login, the system records the nurse as the actor. If the BHW makes an encoding error, accesses a record outside her scope, or if a data breach occurs, the nurse becomes legally and professionally accountable for actions she did not perform.
Watch out! Staying beside the BHW while she encodes (option 4) does not solve the problem. The audit trail still attributes every action to the nurse’s credentials, not the BHW. Physical supervision cannot replace digital identity.
Key point! A shared or common account for all station staff (option 3) is equally unacceptable because it destroys individual accountability. If multiple people use one login, no one can be identified as the source of an entry or a privacy violation.
Why the Audit Trail Matters in the BHS Setting
In a Barangay Health Station linked to a Rural Health Unit, multiple personnel—nurses, midwives, BHWs—handle the same client records. The
electronic health record (EHR) system is designed to capture
who did what and when. This is the foundation of
accountability and
continuity of care.
The systematic review by Cahill et al. (2025) highlights that EHR design directly influences
usability and
medication safety, with poorly designed systems contributing to user errors . While that review focuses on design elements, the underlying principle applies here: the system’s
user identification mechanism is a critical safety feature. If the system cannot reliably distinguish one user from another, every downstream function—order entry, documentation, referral tracking—becomes vulnerable to error and misattribution.
A personal account is not merely an access key; it is the mechanism by which the EHR enforces role-based permissions and generates a trustworthy record of care. When credentials are shared, the system’s ability to support safe, auditable practice is compromised.
Data Privacy and Legal Accountability
Client records in the BHS contain
sensitive personal information—reproductive health history, family planning data, communicable disease status, and socioeconomic details. The Data Privacy Act (RA 10173) imposes obligations on
personal information controllers and
processors to implement reasonable safeguards against unauthorized access or disclosure.
Sharing a login is a direct violation of the principle of
accountability under data privacy law. If a breach occurs, the organization must be able to determine
which individual accessed or disclosed the data. A shared credential makes that determination impossible and exposes both the nurse and the health facility to legal liability.
The systematic review by Alomar et al. (2024) examined patient access to EHRs and its impact on health care engagement . While that review focuses on patients rather than staff, it underscores a broader point:
EHR systems are built on the assumption that each user is uniquely identified, because the value of the system depends on accurate attribution of every interaction with a record. The same logic applies to staff access. Without unique identifiers, the system cannot support meaningful engagement, quality monitoring, or legal compliance.
Practical Steps for the Nurse
The nurse should explain to the BHW that the delay in account activation is an administrative issue to be resolved through the proper channel, not a reason to bypass security controls. The appropriate actions are:
| Action | Rationale |
|---|
| Decline to share the login | Preserves the audit trail and prevents misattribution of actions |
| Facilitate activation of the BHW’s own account | Ensures role-based access and individual accountability |
| Report the delay to the supervising RHU or IT administrator | Addresses the root cause without compromising security |
| Document the request and the response | Creates a record of appropriate handling if the issue recurs |
The nurse’s role as supervisor includes ensuring that all staff understand
why credential sharing is prohibited, not simply enforcing the rule. A brief explanation that the system records
who enters data—and that this protects both the client and the staff member—can turn a frustrating delay into a learning moment about professional accountability.
Key point! The correct answer is not about being strict or uncooperative. It is about recognizing that
the integrity of the health record depends on every user being uniquely identified, and that sharing credentials undermines the very purpose of the electronic system.