Core principle: authentication and the audit trail
The correct action is to
log out so the colleague can sign in under her own account. In an electronic health record, every entry must be traceable to the person who actually made it. When a nurse lets someone else type under an open session, the system records that entry as if the original nurse authored it. This breaks two linked safeguards:
authentication, which verifies that the person entering data is who the system says they are, and the
audit trail, which is the chronological record of who accessed, created, or modified information and when . Without both, the record can no longer reliably answer the question, “Who documented this observation, and were they authorized to do so?”
Why sharing a login is never acceptable
EHR systems are built on the assumption that each user has unique credentials tied to a specific role and scope of practice.
Nurses chart only the care they themselves provided or directly observed. If a colleague types her notes under another nurse’s login, the system attributes that documentation to the wrong person. Even if the colleague writes her name inside the note text, the metadata—the system-level record of who created the entry—still points to the original nurse. The same problem occurs if the nurse types the notes “for” the colleague or reviews and countersigns afterward: the entry’s origin is misrepresented, and the audit trail is corrupted from the start.
Watch out! Writing a name in the body of a note does not fix the authentication problem. The EHR’s audit log, not the typed name, is what courts, regulators, and quality reviewers examine.
Legal and data-protection context
Health information is classified as
sensitive personal information under the Data Privacy Act of 2012 (Republic Act 10173). This classification imposes stricter safeguards on access, use, and disclosure. Shared logins defeat those safeguards because they make it impossible to determine who actually accessed a patient’s record. In the Philippine setting, organizational factors such as staffing, infrastructure, and training affect how consistently EHR safeguards are applied . However, even when a computer freezes or time is short, the security requirement does not change: each user must authenticate individually.
Applying this to the psychiatric ward scenario
The patient has schizophrenia and was placed in seclusion after an aggressive episode. This is a high-risk clinical situation where documentation must be precise, timely, and clearly attributable. Seclusion is a restrictive intervention with legal and ethical implications, so every observation note—behavior before seclusion, response during seclusion, vital signs, mental status—must be linked to the nurse who actually observed and recorded it.
A shared login would make the seclusion documentation legally indefensible if the patient’s care or the seclusion order were later reviewed.
| Option | What happens in the EHR | Why it fails or succeeds |
|---|
| 1. Log out; colleague signs in | Each entry is attributed to the correct author | Preserves authentication and audit trail; correct action |
| 2. Let her type; she writes her name | Metadata still names the original nurse as author | Name in text does not override system attribution |
| 3. Type her notes; name her as observer | Original nurse is recorded as the data enterer | Misrepresents who performed the documentation |
| 4. Let her type; review and countersign | Original nurse appears as author; countersignature adds confusion | Does not restore accurate attribution of the original entry |
Practical workflow point
The colleague’s frozen computer is an equipment problem, not a reason to bypass access controls. The correct response is to have the colleague use another workstation, wait for the computer to be restored, or contact IT support.
Key point! Authentication is a per-user requirement; it cannot be delegated, shared, or temporarily suspended for convenience. The nurse should log out of the open session immediately so the colleague can authenticate with her own credentials and document her own observations.
The systematic review on EHR adoption in Philippine public hospitals highlights that inconsistent implementation and resource constraints can create pressure to take shortcuts . However, documentation integrity is a non-negotiable component of safe psychiatric nursing care, particularly when restrictive measures such as seclusion are involved. The audit trail is the mechanism that makes the record trustworthy, and it only works when each entry is genuinely tied to the person who created it .