D220 Task 2 Technology Change Proposal Example

This D220 Task 2 example proposes replacing personal text messaging with a secure messaging platform at a composite home health agency whose 42 nurses, therapists and aides coordinate care for about 600 patients a month on their own phones. The second WGU D220 task, Information Technology in Nursing Practice, has RN to BSN nurses plan a technology change and weigh its legal and ethical implications. The sample traces a wound photo from a personal camera roll to a cloud backup to show the risk, describes the platform and its safeguards, separates HIPAA Security Rule duties from the ethical duty of privacy, and flags the staff privacy issue of using personal devices. A 60-day rollout and three measures, adoption, safety and documentation, close the plan.

CourseD220 Information Technology in Nursing Practice
TaskTask 2
Paper typeTechnology change proposal
LengthAbout 1,200 words, 5 pages
FormatAPA 7
SchoolWestern Governors University (WGU)
ProgramRN to BSN
UpdatedSeptember 2026

Free sample paper for D220 Task 2

1

Replacing Personal Text Messages With a Secure Messaging Platform in a Home Health Agency: Legal, Ethical, and Practical Safeguards

Student Name

Leavitt School of Health, Western Governors University

D220: Information Technology in Nursing Practice, Task 2

Course Instructor

Month Day, Year

What this page is doingThe title states the change, the setting and the lens the paper uses. Home health is a useful setting for this task because nurses work alone, on their own phones, far from the IT department, which is exactly where protected information leaks.
2

Replacing Personal Text Messages With a Secure Messaging Platform in a Home Health Agency: Legal, Ethical, and Practical Safeguards

Introduction

In the composite home health agency described here, 42 registered nurses, therapists and aides visit about 600 patients a month across three rural and suburban counties. They coordinate care by sending ordinary text messages from their personal phones: a wound photo to the wound care nurse, a blood pressure reading to the case manager, a patient's name and new medication list to the office. The practice is fast and familiar, and it places protected health information on dozens of unmanaged devices. This paper proposes one technology change, a secure messaging platform linked to the agency's electronic health record, and examines its legal and ethical implications, the safeguards it requires and how its success would be measured.

Current Practice and Its Risks

A typical day shows the problem. A nurse photographs a sacral wound on a personal phone, texts it with the patient's first name and address to a colleague for a second opinion, and forgets the image is still in the camera roll, which backs up automatically to a personal cloud account. An aide texts the office that a patient's daughter has asked for visit times to change. None of these messages is encrypted end to end on an agency-controlled system, none is stored in the patient's record, and if a phone is lost or an employee leaves, the agency has no way to remove the information. The clinical content of the messages is also lost to the record, so the next nurse cannot see why a dressing order changed.

What this page is doingThe section describes the current practice concretely, one message at a time, before naming any law. An evaluator can see the actual risk points: storage, backup, loss of the device and loss of the information from the record.
3

Proposed Technology Change

The agency will adopt a secure messaging application that runs on agency-managed smartphones and on staff personal phones enrolled in mobile device management. Messages and images are encrypted, stored on the vendor's servers rather than on the phone, and deleted from the device after a set period. Staff sign in with their agency credentials and a second authentication factor. Messages that change care, such as a new wound photo or a medication question, can be attached to the patient's chart in the electronic health record with one action, so the information that used to vanish becomes part of the record.

Health systems that have evaluated these products describe three tiers, from basic secure texting to platforms built into existing clinical applications to full collaboration systems, and recommend choosing based on the clinical processes the organization most needs to improve, together with decisions on message archiving, device management and bring-your-own-device policy (Liu et al., 2019). For this agency, the most important feature is the link to the patient record, so a product in the second tier, integrated with the existing electronic health record, is the best fit for its size and budget.

Legal Implications

The Health Insurance Portability and Accountability Act Security Rule requires covered entities to protect electronic protected health information with administrative, physical and technical safeguards, including access controls, audit controls, integrity controls and transmission security (U.S. Department of Health and Human Services [HHS], 2022). Ordinary text messages on personal phones meet almost none of these requirements, and a lost phone containing patient images could be a reportable breach. Moving communication onto a managed, encrypted platform with audit logs brings the agency into line with the rule and gives it evidence of compliance if a breach is ever investigated.

There is a second legal issue: the record. Messages that inform care decisions belong in the legal medical record. When they sit on personal phones, the agency cannot produce them for a review, a subpoena or a patient's request for records. The integration feature addresses this, but only if the agency writes a policy that defines which messages must be attached to the chart and trains staff to do it.

Ethical Implications

The nurse's duty to protect patient privacy and confidentiality is set out in the profession's code of ethics, which asks nurses to safeguard the patient's right to privacy and to protect personal health information in every form (American Nurses Association [ANA], 2015). Home health patients let nurses into their homes; a photo that shows a wound also shows a bedroom, family photographs and sometimes other people. Sending that image through an unsecured channel treats the patient's home as less private than a hospital room, which is the opposite of what the trust of a home visit requires.

The change also raises an ethical question for staff. Asking employees to install agency software on their personal phones means the agency can see and wipe part of their device. Fairness requires that the agency provide a phone to anyone who does not want to use their own, explain exactly what mobile device management can and cannot see, and limit remote wipe to the agency's container rather than the whole phone.

What this page is doingLegal and ethical implications are kept apart: the law governs safeguards and the record, while ethics addresses the patient's home and the employee's own device. Naming the staff privacy issue shows the writer has thought about both sides of the change.
4

Safeguards and Implementation

The change will be introduced over 60 days. In the first two weeks, the informatics lead, the director of nursing and two field nurses will configure the platform, set message retention to 30 days on the device, disable screenshots within the application and write a short policy that bans patient information in ordinary texts. In weeks three and four, every staff member will complete a 30-minute training session covering sign-in, attaching messages to the chart, photographing wounds inside the application rather than the phone camera, and what to do if a device is lost. From week five, ordinary texting of patient information ends, and the office will stop responding to clinical texts outside the platform.

Volume is a risk of its own. A study of 61,057 secure messages between interns and nurses at an academic medical center found heavy traffic with sharp peaks at certain hours, and the authors called for protocols that cut nonessential messages (Madabhushi et al., 2025). The agency will therefore set simple rules from the start: urgent clinical issues go by phone call, routine updates go in a single end-of-day message, and group threads are limited to each patient's care team.

Measuring Success

Three measures will show whether the change worked. The primary measure is the proportion of clinical messages sent through the secure platform, estimated from a monthly one-week audit in which staff record every clinical message they send and its channel; the target is 95% by the end of the third month. The second is the number of privacy incidents involving mobile devices, including lost phones with patient data and texts sent to the wrong person, reported through the agency's incident system and compared with the previous six months. The third is the proportion of wound photos in the chart that were taken inside the application, drawn from the electronic health record each month. Staff satisfaction with the platform will be surveyed at 90 days so that problems with usability are found before staff drift back to ordinary texting.

What this page is doingEach measure names its data source and its interval. The primary measure is about adoption, the second about safety, the third about the record, so success cannot be claimed from installation numbers alone.
5

Conclusion

Personal text messaging is convenient for home health staff and incompatible with the legal and ethical duties that come with patient information. A secure messaging platform linked to the electronic health record, supported by clear rules, device safeguards, fair treatment of staff devices and measures that track adoption and incidents, keeps the speed staff value while bringing patient information back under the agency's protection.

References

American Nurses Association. (2015). Code of ethics for nurses with interpretive statements. Nursesbooks.org.

Liu, X., Sutton, P., McKenna, R., Sinanan, M., Fellner, B., Leu, M., & Ewell, C. (2019). Evaluation of secure messaging applications for a health care system: A case study. Applied Clinical Informatics, 10(1), 140-150. https://doi.org/10.1055/s-0039-1678607

Madabhushi, S., Nguyen, A. M., Hsia, K., Kher, S., Harvey, W., Murzycki, J., Chandler, D., & Davis, M. (2025). Effect of smartphone-based messaging on interns and nurses at an academic medical center: Observational study. JMIR Medical Informatics, 13, e66859. https://doi.org/10.2196/66859

U.S. Department of Health and Human Services. (2022). Summary of the HIPAA Security Rule. https://www.hhs.gov/hipaa/for-professionals/security/laws-regulations/index.html

What the D220 Task 2 instructions ask

The second D220 task asks you to propose a technology change and think through its consequences. Most versions ask you to describe current practice and the problem it creates, propose a specific technology, discuss the legal and ethical implications, describe safeguards and how the change would be implemented, and explain how success would be measured. The technology can be new software, a device or a new use of an existing system. The evaluator expects legal and ethical implications to be distinct: laws and regulations on one side, professional duties and values on the other. A proposal that treats privacy as a single paragraph covering both tends to fall short.

How this D220 Task 2 example is built

The proposal starts with the agency's size and its current habit of texting, then shows one day's workflow to make the risks concrete. The proposed platform is described by what it does with data, not by brand. Legal implications draw on the HIPAA Security Rule's safeguards and the record-keeping duty; ethical implications draw on the nursing code of ethics and add the less obvious issue of employee privacy on personal phones. The safeguards and implementation section gives a 60-day plan with named roles and device settings. Three success measures each have a data source and interval, so the change cannot be declared a success simply because the app was installed. The order of the sections mirrors the order in which a director of nursing would ask questions: what is wrong now, what would replace it, is it legal, is it right and how will we know it worked.

Where the D220 Task 2 rubric puts the marks

For D220 Task 2 the evaluator marks each aspect competent, approaching competence or not evident. A current practice aspect checks that the problem is described with its risks. The proposal aspect wants a specific technology and how it would work in the setting. Legal and ethical implications are scored separately, and each needs accurate content with sources. A safeguards or implementation aspect looks for concrete steps, roles and timelines. The evaluation aspect asks for measures that show whether the change achieved its purpose. APA citations of laws, codes and research, and professional writing, run through the whole rubric.

D220 Task 2 help: what sends it back

Proposals come back most often when legal and ethical implications are merged. Keep HIPAA and other regulations in one section and professional ethics in another. Second, students describe the technology in marketing terms. Explain what it does with patient information and how that reduces risk. Third, implementation plans are often a single sentence about training. Give a timeline, who leads each step and how devices or settings will be configured. Fourth, success measures frequently count installations or logins. Measure what matters, such as the share of clinical messages sent securely and the number of privacy incidents. Finally, cite the actual regulation rather than a secondary summary when you describe legal duties.

Get a D220 Task 2 example written to your instructions

Send the Task 2 instructions and rubric from your D220 course of study, along with the system, unit and problem your proposal has to address. We write a custom example to those aspects, with the safeguards sorted by category and the measure tied to a baseline, and return it in 24-48h. The first custom sample is free.

More D220 papers

Other Nursing (BSN) sample papers

D220 Task 2 questions, answered

How is Task 2 different from Task 1 in D220?

The first analyzes a system against the nursing work it supports. The second takes one finding from that analysis and proposes a change, then carries it through implementation, protection of patient information, teaching and measurement. The analysis is input here rather than the deliverable, so its restatement stays short and the space goes to making the change credible.

Do I have to propose new software?

Rarely, and it raises the bar when you do. A replacement brings selection, migration, interface work and a long transition into a single submission, which is a great deal to defend at once. A narrower change to configuration, a template, an alert threshold or a handoff step is usually argued better and reads as far more feasible against the aspects.

How much privacy detail is expected?

Enough to show the change was designed with protected information in mind. Name the safeguards by category, say which roles gain access to what, and describe how the change would be logged and reviewed. Citing the relevant federal requirements is fine, but the aspect wants them applied to your proposal rather than explained at length in the abstract.

Does D220 Task 2 have to be about the same setting as Task 1?

Not always; check your instructions. The sample uses a home health agency to show a different setting, and the proposal works because the technology fits that setting's real workflow.

Where can I find a free D220 Task 2 sample paper?

The full technology proposal is on this page with margin notes. If your change or setting differs, share the D220 task and the desk will return a first custom proposal at no charge.