A post-acute network agrees to receive a nightly file from an acute partner so that a placement model can rank incoming referrals. The file contains diagnoses, prior utilization and social information for patients the network has not admitted and may never admit. Everyone involved is acting in good faith, the arrangement is described in a paragraph of an existing agreement, and nobody has written down what happens to the records of the patients who go somewhere else. NR-588AI Week 2 is where that omission becomes the assignment: what data crosses which boundary, on what basis, for what purpose, held how long, and destroyed when. Your section may print this as NR 588AI or NR588AI; it is the same course. Chamberlain publishes no syllabi outside Canvas. The placement here is our teaching judgment from the course's catalog arc; your section's rubric decides what your week actually asks.
What NR-588AI Week 2 asks for
Data governance sounds administrative and is in fact the stage where most of the course's ethical content actually lives. An algorithm is a function of the data it was given, so every question about fairness, accuracy and accountability later in the session traces back to decisions made about information before anyone wrote a line of clinical policy. The graded task in this stage is to write those decisions down as commitments rather than as values.
The distinction the rows reward is between purposes. Information gathered to care for a person, information used to run a service, and information used to build or tune a model are three different purposes, and the fact that an organization lawfully holds data for the first does not settle whether it may be used for the third. A paper that says patient data must be protected has said nothing scoreable. A paper that says which purpose each data flow serves, and who authorized that purpose, has begun.
Cross-boundary work adds the harder half. When information moves between organizations, the receiving party inherits obligations it did not negotiate and often cannot audit. What may it do with the file. May it retain records for patients it never served. May it use the file to improve its own model. Who is told when the arrangement changes. In practice these questions surface at the moment something goes wrong, which is exactly why a governance framework has to answer them in advance.
De-identification deserves explicit treatment because students routinely overstate what it accomplishes. Removing names from a file does not make it anonymous when the file also contains a rare diagnosis, a facility, an admission date and a discharge destination. Writing one honest paragraph about re-identification risk in small populations, which post-acute and long-term care settings certainly are, is worth more than a page asserting that data is de-identified and therefore safe.
Deliverables at this depth are usually a written data governance analysis or a draft framework section, sometimes with a table of flows, and occasionally a posted response defending a single provision. If your section runs a discussion this week, pick the provision most people forget, which is almost always retention and destruction. Posts do not reopen after submission in Canvas.
The NR-588AI Week 2 method, step by step
Six moves for writing data governance as a set of commitments two organizations could sign.
-
Read the rubric for whether it wants analysis or provisions
An analysis discusses risks and principles. A framework section states obligations with owners and intervals. Rows containing govern, ensure or accountability usually want the second, and a thoughtful discussion of privacy principles will not satisfy them however well written it is.
-
Draw the flows before you judge them
Each flow gets a sender, a receiver, a content description, a frequency, a transport method and a stated purpose. Include internal flows and vendor flows, since a model hosted by a supplier means data leaves both clinical organizations even when it feels like it stayed inside one.
-
Attach a purpose and an authority to every flow
Treatment, operations, quality improvement, model development or research, and the basis on which each is permitted. Where you are not certain, say that determining the basis is a required step and name the role that would make the determination. Guessing at a legal conclusion is the one thing to avoid here.
-
Write the reuse boundary explicitly
State what the receiving party may not do: use the file to train or tune its own model, retain records for people it never served, share onward with a subcontractor, or repurpose the data for marketing or referral competition. Prohibitions written plainly are the part of a framework that actually constrains behavior.
-
Specify retention, destruction and proof
How long each party holds the data, what triggers deletion, who confirms it happened and how that confirmation is evidenced. This is the provision most often missing from student drafts and one of the easiest to write well, because it is entirely concrete.
-
Add the change and exit clause
What happens when the vendor is replaced, when the model is retired, or when one organization leaves the arrangement. Who returns or destroys what, and by when. A framework without an exit provision assumes the relationship is permanent, and in contracted health services it never is.
A layout and word budget for a data governance section
Our frame for a data governance analysis spanning two organizations and a vendor, sized for roughly 1,200 to 1,500 words plus a flow table. It is our own outline rather than anything the university issues, and your week's rubric outranks it wherever the two disagree.
| Provision | What it has to settle | Word target |
|---|---|---|
| Flows and purposes | Every movement of data with sender, receiver, content, frequency, transport and the purpose it serves. | 230 to 280 |
| Authority and consent | The basis for each purpose, what the patient was told, and where a determination still has to be made. | 200 to 250 |
| Minimization | What is sent that the model does not need, and what would be removed without degrading the clinical purpose. | 170 to 210 |
| Reuse prohibitions | The uses the receiving party is barred from, stated as prohibitions rather than as expectations. | 190 to 240 |
| Re-identification risk | Why removing identifiers is insufficient in small populations, and what additional controls apply. | 180 to 220 |
| Retention, destruction, exit | Holding periods, deletion triggers, proof of destruction, and what happens when a party or a vendor leaves. | 200 to 250 |
Evidence craft for governance writing
Cite frameworks rather than inventing categories. Published governance frameworks for health data and for artificial intelligence in healthcare exist, are issued by named bodies and are dated. Adopting one structure, attributed, means a grader can check your provisions against a recognized set instead of against your intuition.
Describe legal requirements at the level you can support. It is legitimate to write that a use of this kind requires a determination of permitted purpose and to name the role who makes it. It is not legitimate to assert a legal conclusion about a specific arrangement, and rubrics in this territory reward the first kind of sentence and penalize the second when it is stated flatly and wrongly.
Use the re-identification literature explicitly. There is published work on how few attributes are needed to single out an individual in a data set, and citing it converts your caution about small populations from a worry into a supported claim. In post-acute settings, where facility, admission window and diagnosis narrow a population very quickly, this citation does real work.
Give every commitment an owner and an interval. Reviewed annually by the party operating the model is a commitment. Reviewed regularly is not. In governance writing the specificity is the substance, and rows that mention accountability are looking precisely for the named party and the date.
De-identify organizations and vendors, and mark what is proposed. A contracted analytics supplier, a regional acute care partner, a post-acute network. Present tense for what is in force, explicit conditional language for what you are recommending, so no reader can mistake a proposal for a description of the current arrangement.
Five mistakes that cost points in this week's territory
- Principles instead of provisions. Paragraphs about privacy, transparency and trust are unscoreable against rows that ask what each party is obliged to do.
- Assuming permission travels with the data. The right to hold information for care does not settle the right to use it to build or run a model for another organization.
- Treating de-identification as a solution. In small populations it reduces risk rather than removing it, and saying otherwise is a substantive error.
- Silence on retention. A framework with no deletion trigger means data about people you never served accumulates indefinitely at a partner you cannot audit.
- Stating legal conclusions you cannot support. Naming the determination that must be made, and who makes it, is stronger and safer than asserting an outcome.
Before you submit
- Every data flow has a sender, receiver, content, frequency, transport and purpose
- Each purpose has an authority basis or an explicit note that one must be determined
- Minimization is addressed by naming what would be removed and what that would cost
- Reuse prohibitions are written as prohibitions, not as expectations
- Re-identification risk in small populations is addressed with a cited source
- Retention, destruction, proof of destruction and exit are all specified with owners
Drafting the governance section for NR-588AI?
Send the rubric and the arrangement you are analyzing. A premium original draft comes back in 24 to 48 hours with flows tabulated, prohibitions written plainly and every commitment carrying an owner and an interval, and revisions run until the grade lands.