NR-588AI · Week 2 of 8 · Data governance across organizational boundaries

NR-588AI Week 2 Data Governance: How to Write It

The short answer

A post-acute network agrees to receive a nightly file from an acute partner so that a placement model can rank incoming referrals. The file contains diagnoses, prior utilization and social information for patients the network has not admitted and may never admit. Everyone involved is acting in good faith, the arrangement is described in a paragraph of an existing agreement, and nobody has written down what happens to the records of the patients who go somewhere else. NR-588AI Week 2 is where that omission becomes the assignment: what data crosses which boundary, on what basis, for what purpose, held how long, and destroyed when. Your section may print this as NR 588AI or NR588AI; it is the same course. Chamberlain publishes no syllabi outside Canvas. The placement here is our teaching judgment from the course's catalog arc; your section's rubric decides what your week actually asks.

NR 588AI Week 2 grading scale at Chamberlain, the criterion levels this assessment is scored on, from Chamberlain Tutors
How Chamberlain grades NR 588AI Week 2, visualized by Chamberlain Tutors.

What NR-588AI Week 2 asks for

Data governance sounds administrative and is in fact the stage where most of the course's ethical content actually lives. An algorithm is a function of the data it was given, so every question about fairness, accuracy and accountability later in the session traces back to decisions made about information before anyone wrote a line of clinical policy. The graded task in this stage is to write those decisions down as commitments rather than as values.

The distinction the rows reward is between purposes. Information gathered to care for a person, information used to run a service, and information used to build or tune a model are three different purposes, and the fact that an organization lawfully holds data for the first does not settle whether it may be used for the third. A paper that says patient data must be protected has said nothing scoreable. A paper that says which purpose each data flow serves, and who authorized that purpose, has begun.

Cross-boundary work adds the harder half. When information moves between organizations, the receiving party inherits obligations it did not negotiate and often cannot audit. What may it do with the file. May it retain records for patients it never served. May it use the file to improve its own model. Who is told when the arrangement changes. In practice these questions surface at the moment something goes wrong, which is exactly why a governance framework has to answer them in advance.

De-identification deserves explicit treatment because students routinely overstate what it accomplishes. Removing names from a file does not make it anonymous when the file also contains a rare diagnosis, a facility, an admission date and a discharge destination. Writing one honest paragraph about re-identification risk in small populations, which post-acute and long-term care settings certainly are, is worth more than a page asserting that data is de-identified and therefore safe.

Deliverables at this depth are usually a written data governance analysis or a draft framework section, sometimes with a table of flows, and occasionally a posted response defending a single provision. If your section runs a discussion this week, pick the provision most people forget, which is almost always retention and destruction. Posts do not reopen after submission in Canvas.

The NR-588AI Week 2 method, step by step

Six moves for writing data governance as a set of commitments two organizations could sign.

  1. Read the rubric for whether it wants analysis or provisions

    An analysis discusses risks and principles. A framework section states obligations with owners and intervals. Rows containing govern, ensure or accountability usually want the second, and a thoughtful discussion of privacy principles will not satisfy them however well written it is.

  2. Draw the flows before you judge them

    Each flow gets a sender, a receiver, a content description, a frequency, a transport method and a stated purpose. Include internal flows and vendor flows, since a model hosted by a supplier means data leaves both clinical organizations even when it feels like it stayed inside one.

  3. Attach a purpose and an authority to every flow

    Treatment, operations, quality improvement, model development or research, and the basis on which each is permitted. Where you are not certain, say that determining the basis is a required step and name the role that would make the determination. Guessing at a legal conclusion is the one thing to avoid here.

  4. Write the reuse boundary explicitly

    State what the receiving party may not do: use the file to train or tune its own model, retain records for people it never served, share onward with a subcontractor, or repurpose the data for marketing or referral competition. Prohibitions written plainly are the part of a framework that actually constrains behavior.

  5. Specify retention, destruction and proof

    How long each party holds the data, what triggers deletion, who confirms it happened and how that confirmation is evidenced. This is the provision most often missing from student drafts and one of the easiest to write well, because it is entirely concrete.

  6. Add the change and exit clause

    What happens when the vendor is replaced, when the model is retired, or when one organization leaves the arrangement. Who returns or destroys what, and by when. A framework without an exit provision assumes the relationship is permanent, and in contracted health services it never is.

A layout and word budget for a data governance section

Our frame for a data governance analysis spanning two organizations and a vendor, sized for roughly 1,200 to 1,500 words plus a flow table. It is our own outline rather than anything the university issues, and your week's rubric outranks it wherever the two disagree.

ProvisionWhat it has to settleWord target
Flows and purposesEvery movement of data with sender, receiver, content, frequency, transport and the purpose it serves.230 to 280
Authority and consentThe basis for each purpose, what the patient was told, and where a determination still has to be made.200 to 250
MinimizationWhat is sent that the model does not need, and what would be removed without degrading the clinical purpose.170 to 210
Reuse prohibitionsThe uses the receiving party is barred from, stated as prohibitions rather than as expectations.190 to 240
Re-identification riskWhy removing identifiers is insufficient in small populations, and what additional controls apply.180 to 220
Retention, destruction, exitHolding periods, deletion triggers, proof of destruction, and what happens when a party or a vendor leaves.200 to 250

Evidence craft for governance writing

Cite frameworks rather than inventing categories. Published governance frameworks for health data and for artificial intelligence in healthcare exist, are issued by named bodies and are dated. Adopting one structure, attributed, means a grader can check your provisions against a recognized set instead of against your intuition.

Describe legal requirements at the level you can support. It is legitimate to write that a use of this kind requires a determination of permitted purpose and to name the role who makes it. It is not legitimate to assert a legal conclusion about a specific arrangement, and rubrics in this territory reward the first kind of sentence and penalize the second when it is stated flatly and wrongly.

Use the re-identification literature explicitly. There is published work on how few attributes are needed to single out an individual in a data set, and citing it converts your caution about small populations from a worry into a supported claim. In post-acute settings, where facility, admission window and diagnosis narrow a population very quickly, this citation does real work.

Give every commitment an owner and an interval. Reviewed annually by the party operating the model is a commitment. Reviewed regularly is not. In governance writing the specificity is the substance, and rows that mention accountability are looking precisely for the named party and the date.

De-identify organizations and vendors, and mark what is proposed. A contracted analytics supplier, a regional acute care partner, a post-acute network. Present tense for what is in force, explicit conditional language for what you are recommending, so no reader can mistake a proposal for a description of the current arrangement.

Five mistakes that cost points in this week's territory

  • Principles instead of provisions. Paragraphs about privacy, transparency and trust are unscoreable against rows that ask what each party is obliged to do.
  • Assuming permission travels with the data. The right to hold information for care does not settle the right to use it to build or run a model for another organization.
  • Treating de-identification as a solution. In small populations it reduces risk rather than removing it, and saying otherwise is a substantive error.
  • Silence on retention. A framework with no deletion trigger means data about people you never served accumulates indefinitely at a partner you cannot audit.
  • Stating legal conclusions you cannot support. Naming the determination that must be made, and who makes it, is stronger and safer than asserting an outcome.

Before you submit

  • Every data flow has a sender, receiver, content, frequency, transport and purpose
  • Each purpose has an authority basis or an explicit note that one must be determined
  • Minimization is addressed by naming what would be removed and what that would cost
  • Reuse prohibitions are written as prohibitions, not as expectations
  • Re-identification risk in small populations is addressed with a cited source
  • Retention, destruction, proof of destruction and exit are all specified with owners

Drafting the governance section for NR-588AI?

Send the rubric and the arrangement you are analyzing. A premium original draft comes back in 24 to 48 hours with flows tabulated, prohibitions written plainly and every commitment carrying an owner and an interval, and revisions run until the grade lands.

Questions students ask about this stage

I do not have access to the actual data sharing agreement. Can I still write this?
Yes, and the paper is often better for it, provided you handle the gap honestly. Write the framework as a proposal for what the arrangement should contain rather than as a description of what it does contain, and say so in a sentence near the beginning. Then use the gap analytically: note which provisions you would expect to find, which you can confirm exist from what you observe in practice, and which you cannot verify at all. A statement such as the operational behavior observed at the receiving site is consistent with a broad permitted-purpose clause, though the agreement itself was not available for review, is both accurate and sophisticated. What fails is inventing the contents of a document you never read.
Does consent solve the reuse problem?
Rarely on its own, and the reasons are worth writing about because they are the substance of the stage. Consent obtained at admission for treatment is not consent for a partner organization to use a record to develop a predictive model, and consent language broad enough to cover any future use is exactly the language ethicists criticize as uninformed. There are also practical limits in the populations this course tends to concern: residents with cognitive impairment, decisions made by responsible parties, and situations where declining is difficult because care is already underway. The defensible position in a framework is layered. Use the narrowest lawful basis for each purpose, minimize what is sent, prohibit reuse contractually, and treat consent as one control among several rather than as the provision that makes everything else unnecessary.
How do I handle a vendor that will not disclose what it does with the data?
Treat the non-disclosure as a governance finding and write it into the framework rather than around it. Say what the arrangement requires the vendor to disclose, what it currently does not, and what the organization should do about the gap: require disclosure at contract renewal, restrict the data sent until it is provided, or accept the residual risk explicitly at a named level of authority. That last option is legitimate and is frequently what happens in reality, but it must be a documented decision by someone empowered to make it, not a silence. Framing an unanswerable question this way demonstrates exactly the accountability reasoning the course rewards, and it produces a section that reads as governance rather than as a complaint about a supplier.

Keep going

Online now