Legitimate purpose is the test
Under the Data Privacy Act of 2012 (RA 10173), health information is sensitive personal information. It may be processed, which includes viewing, only for a legitimate purpose and only to the extent proportional to that purpose. A nurse caring for the client has a legitimate purpose. This nurse from another ward has no role in his care, so opening his record to satisfy personal interest has no legitimate purpose and is a breach of privacy, even though she shares nothing. Viewing itself is a form of processing; the breach does not depend on disclosure.
Why curiosity access is a breach
Being a health worker in the same hospital does not give access to every record. Access is based on role and need to know: the people who need the information to provide care, process payment, or perform authorized functions. Her neighborly concern may be kind, but it does not create a care role. Hospitals also use audit trails in the electronic health record, which log who opened which record and when. Such unauthorized access can lead to disciplinary action and penalties under the law.
| Statement | Accurate? | Reason |
|---|
| No care role, so no legitimate purpose | Yes | Purpose and role decide lawful access |
| Should have asked family consent | No | Family consent does not make it lawful |
| Only computers on the client's ward | No | Rules depend on role, not location |
| Breach only with a colleague's login | No | Own login does not make it lawful |
Why the other explanations are wrong
Family consent does not authorize access; the information belongs to the client, and lawful access requires a legitimate purpose or the client's own consent. Access rules depend on role and purpose, not on which computer is used. Using a colleague's login would be an additional violation, but using her own login does not make the access lawful; access without a care role is a breach in itself.
What she could do instead
If she wishes to know how he is, she can visit him as a neighbor or ask him or his family directly, outside her professional role. The nurse also has a duty to report privacy breaches according to hospital policy, and nurses should log out of terminals and protect their credentials.
Exam takeaway
Key point Under RA 10173, health information is accessed only for a legitimate purpose tied to a role in care. Viewing without such a role is a breach, even if nothing is shared.