# Situation: A public health nurse supervises the midwife and barangay health workers (BHWs) of a Barangay Health Station (BHS), which is linked to the Rural Health Unit (RHU), and oversees its records and referrals. The BHS now enters client data into an electronic health record system. A BHW who helps with encoding asks to use the nurse's login because her own account has not yet been activated. What should the nurse do?

> source: MyMerci (mymerci.kr)  
> url: https://mymerci.kr/pages/nclex_q.php?qn_id=627277  
> language: ko  
> subject: Nursing Practice I — Community Health Nursing

## 문제

Situation: A public health nurse supervises the midwife and barangay health workers (BHWs) of a Barangay Health Station (BHS), which is linked to the Rural Health Unit (RHU), and oversees its records and referrals.

The BHS now enters client data into an electronic health record system. A BHW who helps with encoding asks to use the nurse's login because her own account has not yet been activated. What should the nurse do?

## 보기

1. Share the login for this week and change the password later
2. Decline and have the BHW's own account activated first **✔ 정답**
3. Let the BHW use a common account for all the station staff
4. Share the login but stay beside the BHW while she encodes

**정답: 2**

## 해설

Each user must use a personal account and never share credentials, so that role-based access and the audit trail show exactly who entered or viewed each record. Client records contain sensitive personal information protected by the Data Privacy Act (RA 10173). The BHW should encode only after her own account is active.

## 심화 해설

Core Issue: Credential Sharing in the Electronic Health Record

The situation presents a conflict between workflow convenience and information security. A barangay health worker (BHW) requests use of the nurse’s login because her own account is not yet active. The correct action is to decline and have the BHW’s own account activated first. This is not about being unhelpful; it is about preserving the integrity of the audit trail and protecting sensitive personal information under the Data Privacy Act (RA 10173).

Every user must have a unique, personal account because role-based access and audit logs must show exactly who entered, modified, or viewed each client record. When a BHW uses the nurse’s login, the system records the nurse as the actor. If the BHW makes an encoding error, accesses a record outside her scope, or if a data breach occurs, the nurse becomes legally and professionally accountable for actions she did not perform.

Watch out! Staying beside the BHW while she encodes (option 4) does not solve the problem. The audit trail still attributes every action to the nurse’s credentials, not the BHW. Physical supervision cannot replace digital identity.

Key point! A shared or common account for all station staff (option 3) is equally unacceptable because it destroys individual accountability. If multiple people use one login, no one can be identified as the source of an entry or a privacy violation.

Why the Audit Trail Matters in the BHS Setting

In a Barangay Health Station linked to a Rural Health Unit, multiple personnel—nurses, midwives, BHWs—handle the same client records. The electronic health record (EHR) system is designed to capture who did what and when. This is the foundation of accountability and continuity of care.

The systematic review by Cahill et al. (2025) highlights that EHR design directly influences usability and medication safety, with poorly designed systems contributing to user errors . While that review focuses on design elements, the underlying principle applies here: the system’s user identification mechanism is a critical safety feature. If the system cannot reliably distinguish one user from another, every downstream function—order entry, documentation, referral tracking—becomes vulnerable to error and misattribution.

A personal account is not merely an access key; it is the mechanism by which the EHR enforces role-based permissions and generates a trustworthy record of care. When credentials are shared, the system’s ability to support safe, auditable practice is compromised.

Data Privacy and Legal Accountability

Client records in the BHS contain sensitive personal information—reproductive health history, family planning data, communicable disease status, and socioeconomic details. The Data Privacy Act (RA 10173) imposes obligations on personal information controllers and processors to implement reasonable safeguards against unauthorized access or disclosure.

Sharing a login is a direct violation of the principle of accountability under data privacy law. If a breach occurs, the organization must be able to determine which individual accessed or disclosed the data. A shared credential makes that determination impossible and exposes both the nurse and the health facility to legal liability.

The systematic review by Alomar et al. (2024) examined patient access to EHRs and its impact on health care engagement . While that review focuses on patients rather than staff, it underscores a broader point: EHR systems are built on the assumption that each user is uniquely identified, because the value of the system depends on accurate attribution of every interaction with a record. The same logic applies to staff access. Without unique identifiers, the system cannot support meaningful engagement, quality monitoring, or legal compliance.

Practical Steps for the Nurse

The nurse should explain to the BHW that the delay in account activation is an administrative issue to be resolved through the proper channel, not a reason to bypass security controls. The appropriate actions are:

| Action | Rationale |
| --- | --- |
| Decline to share the login | Preserves the audit trail and prevents misattribution of actions |
| Facilitate activation of the BHW’s own account | Ensures role-based access and individual accountability |
| Report the delay to the supervising RHU or IT administrator | Addresses the root cause without compromising security |
| Document the request and the response | Creates a record of appropriate handling if the issue recurs |

The nurse’s role as supervisor includes ensuring that all staff understand why credential sharing is prohibited, not simply enforcing the rule. A brief explanation that the system records who enters data—and that this protects both the client and the staff member—can turn a frustrating delay into a learning moment about professional accountability.

Key point! The correct answer is not about being strict or uncooperative. It is about recognizing that the integrity of the health record depends on every user being uniquely identified, and that sharing credentials undermines the very purpose of the electronic system.

## 임상 시나리오

EHR Access Control in the BHSProtecting Audit Trails and Client Privacy
Every user must have a personal account with role-based access. Never share credentials, even temporarily. The audit trail must show exactly who entered, viewed, or modified each record.

Client records contain sensitive personal information protected by the Data Privacy Act (RA 10173). A BHW should encode only after her own account is active.

CautionStaying beside the BHW while she uses your login does not solve the problem. The system still records all actions under your credentials, making you legally accountable for her entries.

## 핵심 개념

- **Audit trail** — A chronological record of system activities that shows exactly who entered, modified, or viewed each client record.
- **Role-based access** — A security model where users are granted access based on their specific job role and responsibilities.
- **Data Privacy Act (RA 10173)** — Philippine law protecting individual personal information in both government and private sector information and communications systems.
- **Credential sharing** — The practice of allowing another person to use one's username and password, which violates security protocols and destroys individual accountability.
- **Electronic health record** — A digital version of a patient's paper chart that contains sensitive personal information requiring strict access controls.

## 같은 주제 문제

- [Situation: A public health nurse is assigned to organize and assess a coastal barangay in …](https://mymerci.kr/pages/nclex_q.php?qn_id=627074)
- [Situation: A public health nurse is assigned to organize and assess a coastal barangay in …](https://mymerci.kr/pages/nclex_q.php?qn_id=627075)
- [Situation: A public health nurse is assigned to organize and assess a coastal barangay in …](https://mymerci.kr/pages/nclex_q.php?qn_id=627076)
- [Situation: A public health nurse is assigned to organize and assess a coastal barangay in …](https://mymerci.kr/pages/nclex_q.php?qn_id=627077)
- [Situation: A newly assigned public health nurse at the Rural Health Unit (RHU) of an agric…](https://mymerci.kr/pages/nclex_q.php?qn_id=627079)
- [Situation: A newly assigned public health nurse at the Rural Health Unit (RHU) of an agric…](https://mymerci.kr/pages/nclex_q.php?qn_id=627080)
- [Situation: A newly assigned public health nurse at the Rural Health Unit (RHU) of an agric…](https://mymerci.kr/pages/nclex_q.php?qn_id=627081)
- [Situation: A newly assigned public health nurse at the Rural Health Unit (RHU) of an agric…](https://mymerci.kr/pages/nclex_q.php?qn_id=627082)

---

More free questions: [기출문제](https://mymerci.kr/)

_학습 참고용입니다. 실제 임상은 최신 지침과 소속 기관 프로토콜을 따르세요._

