Data privacy: Rules Admin Page Usability Testing

The Problem
I inherited designs for a rule-creation workflow that had already undergone usability testing.

The issue: the prior results weren't reliable.

What I did

Three objectives for the usability test:

(1) validate that users understood the difference between rule types and could make informed choices

(2) pinpoint friction points in the creation process

(3) identify where copy or interaction design needed clarification

Findings:

Data-specific setup was the biggest friction point

Users struggled to identify which data types to restrict.

Many selected only diagnoses or missed the other data categories (orders & results, medications) entirely.

Users had trouble understanding why save or activation was unavailable, especially when required fields were missing or incomplete

Rule type choice wasn't self-evident

Several users selected the wrong rule type or switched between EAR and data-specific rules mid-task.

One participant explicitly stated the choice was unclear—observed behavior confirmed broader confusion about when to use each type

After - Design Changes

Restructured data selection into a vertical workflow
Moving to vertical steps made the progression clearer

Rewrote labels and instructions for clarity
Created more explicit, instructional copy for each section—moving beyond generic labels to explain what users needed to do and why so that users can navigate the setup process with confidence.

Improved the rule-type selection point

Improved card wording and icons so users can quickly ascertain the intent of each

Shipped

Unblocked users with error guidance

Surfaced clear explanations of what was missing and what they needed to fix

These design changes were shipped to development. We will validate these changes during alpha testing, where we expect to see improvement.