2.4 Confidentiality & Professional Conduct

Key Takeaways

  • HIPAA protects Protected Health Information (PHI); the CNA may share resident information only with the care team on a need-to-know basis — never in hallways, elevators, break rooms, social media, or with family/friends who are not authorized.
  • Mandated reporting of suspected abuse, neglect, or a crime is the key exception to confidentiality: that duty overrides HIPAA, so reporting is never a privacy violation.
  • Professional boundaries mean the CNA does not accept gifts/tips, lend or borrow money, share personal contact information, give care outside the care plan, or form a personal/romantic relationship with a resident.
  • An ethical dilemma is resolved by protecting safety first, following resident rights, the care plan, and facility policy, staying within scope, and escalating to the licensed nurse — never deciding alone or honoring a request that conflicts with safety or law.
  • Cultural and spiritual respect requires asking about and accommodating preferences (food, modesty, language, religious practice, gender of caregiver) without judgment, using a facility interpreter rather than family for important communication.
Last updated: June 2026

Confidentiality and HIPAA

The Health Insurance Portability and Accountability Act (HIPAA) of 1996 makes resident health information legally protected. Protected Health Information (PHI) is any information that identifies a resident and relates to their health, care, or payment — name, diagnosis, room number, photographs, lab results, even the simple fact that a person is a resident of the facility. PHI can be spoken, written, or electronic, and the CNA encounters it constantly.

CNA Rules for PHI

  • Share information only with the care team, and only on a need-to-know basis tied to the resident's care.
  • Do not discuss residents in hallways, elevators, the cafeteria, the break room, or at home.
  • Do not post about residents or the facility on social media — even without a name, even a "harmless" photo. This is a leading cause of CNA dismissal and Nurse Aide Registry referral.
  • Do not release resident information to visitors, family, or friends unless the nurse confirms they are authorized.
  • Keep charts, computer screens, and assignment sheets out of public view; log off shared workstations; shred printed PHI.

The one exception the exam tests: a CNA must report suspected abuse, neglect, exploitation, or a crime even though it involves resident information. Mandated reporting overrides confidentiality — making a good-faith report is never a HIPAA violation.

Professional Boundaries

A professional boundary is the line that keeps the relationship therapeutic rather than personal. The CNA cares deeply and stays professional; over-involvement and under-involvement both harm care.

Maintains BoundariesCrosses Boundaries
Declines tips and gifts politelyAccepts cash or jewelry from a resident
Keeps personal life privateShares phone number; meets a resident outside work
Follows the care planProvides off-plan care a resident requests
Treats all residents equitablyPlays favorites or neglects a 'difficult' resident
Reports financial concernsHelps a resident change a will or move money
Keeps relationships caring but professionalDevelops a romantic relationship with a resident

Crossing a financial boundary can shade into misappropriation or exploitation, which is reportable, so the safe answer is always to decline graciously and inform the nurse.

Resolving Ethical Dilemmas

An ethical dilemma is a situation where values or duties conflict — for example, a resident asks the CNA to keep a fall secret, or a family member asks for information the resident wants withheld. Use a stable, defensible method:

  1. Protect resident safety first — a hidden fall must still be reported.
  2. Follow resident rights, the care plan, and facility policy.
  3. Stay within your scope — do not make clinical or care-plan decisions.
  4. Escalate to the licensed nurse whenever duties genuinely conflict.

The CNA does not resolve a serious dilemma alone and does not honor a request that conflicts with safety or the law. Promising a resident you will keep a dangerous secret is the wrong answer; explaining that you care and must tell the nurse for their safety is the right one.

Cultural and Spiritual Respect

New Jersey serves a highly diverse resident population. Cultural competence means delivering care that respects each resident's beliefs, language, and practices without judgment, as part of the dignity and "highest practicable well-being" rights.

  • Ask about preferences for food, modesty, eye contact, personal space, and the gender of the caregiver, and accommodate within facility policy.
  • Support religious and spiritual practices — prayer times, dietary laws (kosher, halal, vegetarian), clergy visits, and end-of-life rituals; never impose your own beliefs or pressure a resident.
  • When there is a language barrier, use a facility interpreter or language line, not the resident's family or improvised gestures, for anything important — accuracy and privacy both matter.
  • Avoid stereotyping: ask the individual, because culture is a starting point, not a script.

Professional Workplace Conduct

Professionalism is reliability, honesty, and respect in action. The well-prepared CNA arrives on time and ready, documents truthfully, completes delegated tasks or reports that they could not, communicates respectfully with the team and residents, maintains appropriate appearance and hygiene (clean uniform, short clean nails, minimal jewelry for infection control), controls emotions under stress, protects PHI, and raises concerns through the chain of command rather than gossip or social media. These behaviors are tested directly and define a CNA whom residents, families, and the team can trust.

Teamwork and Accountability

A CNA rarely works alone. Good teamwork means giving and receiving a clear shift report, answering any resident's call light (not only your own assignment), and asking for help with a heavy transfer rather than risking injury. Accountability means owning mistakes honestly: if you give the wrong tray or miss a task, tell the nurse immediately so it can be corrected — covering it up turns a small error into neglect or false documentation. Conflicts with a coworker go to the supervisor through the chain of command, never into a confrontation in front of residents or a vent on social media.

Stress, Burnout, and Self-Care

Professional conduct also means managing your own stress so it never spills onto residents. CNA work is physically and emotionally demanding, and unmanaged stress can lead to burnout — exhaustion, irritability, and detachment that raises the risk of errors and even abuse. Recognize your own warning signs, use healthy coping (rest, exercise, talking with a supervisor or employee-assistance program), take scheduled breaks, and ask for help with heavy assignments. Stepping away to calm down before responding to a difficult resident is a professional skill, not a weakness, and it directly protects resident safety.

HIPAA in Daily Practice and Mandatory Reporting

The exam often blends HIPAA with the reporting duty, so be precise about how they fit together. HIPAA limits routine sharing of PHI to the care team on a need-to-know basis, but it contains a clear exception: required reports to authorities — including mandated reports of suspected abuse, neglect, exploitation, or a crime under New Jersey's Peggy's Law — are permitted disclosures. Making a good-faith report is never a HIPAA violation, and you do not need the resident's permission to report suspected abuse.

Day-to-day, protect PHI by turning monitors away from public view, logging off shared computers, keeping assignment sheets in your pocket rather than on a counter, shredding printed reports, and never discussing residents where visitors or other residents can overhear. A faxed or emailed record goes only to verified, authorized recipients.

The same standard applies to photos and video: capturing or sharing any image of a resident without proper authorization breaches privacy and dignity and can be reported as abuse. Treating every piece of resident information — spoken, written, or electronic — as confidential is a habit that protects residents and your certification together, and it is the conduct New Jersey expects of every CNA on every shift.

Test Your Knowledge

A CNA takes a photo of a smiling resident at a facility birthday party and, with the resident's verbal okay, posts it on a personal social media page captioned with the facility's name. Why is this a HIPAA and professionalism problem?

A
B
C
D
Test Your Knowledge

A long-term resident becomes very attached to a CNA, offers her $100 'for being so good to me,' and asks for her cell number so they can stay in touch after discharge. What is the most professional response?

A
B
C
D
Test Your Knowledge

A CNA is caring for a resident who speaks limited English and needs to understand instructions about a new dietary restriction. What is the best way to communicate?

A
B
C
D