When Patient Data Leaves the Building
Records emailed to specialists, appointment texts, the doctor checking charts from home — patient data leaves your office every day. Here is what is safe and what is not.

Emailing Records: Regular Email Is a Postcard
Think of a normal email like a postcard: everyone who handles it along the way can read it. That is fine for lunch plans. It is not fine for a referral letter with a diagnosis, lab results, or anything else tied to a patient.
The rule is simple: if the email contains patient information, send it encrypted. Most practices do this one of two ways — an encrypted email service built for healthcare, or a patient portal / secure messaging feature inside the EHR. Pick one, make it the default, and make plain email the thing people have to justify, not the habit.
A few specifics worth nailing down. Sending records to another provider for treatment purposes is allowed — the question is never whether you can send, it is whether you sent it securely. Faxes still count as a normal channel in healthcare, but remember the output-tray problem from the first article in this series: what prints on the other end sits where anyone can read it. And if a patient asks you to email their records to their regular personal address, you can honor the request — it is their data — but warn them in plain language that regular email is not secure, and write down that they asked for it anyway.
Texting Patients: Reminders Yes, Diagnoses No
Texting is where the most well-meaning mistakes happen. Appointment reminders — “Reminder: your visit is tomorrow at 10” — are routine, expected by patients, and low risk. Clinical information over text is a different animal: test results, diagnoses, medication details sent by SMS travel unencrypted, live forever on both phones, and pop up on lock screens.
Draw the line in one sentence and teach it to everyone: texts are for logistics, never for clinical content. If a conversation starts heading clinical — the patient replies “what did my labs show?” — the staffer’s answer is “I’ll have the nurse call you” or a link to the portal, not the result typed into the message thread.
Get consent, too. Patients should agree to receive texts, and they should know what kinds of messages you will send. Most appointment-reminder services handle the opt-in wording for you. And keep the texting on a practice-owned number or service — not the front desk’s personal cell — so the message history belongs to the practice and does not walk out the door with an employee.
Remote Access: The Doctor Checking Charts From Home
Some version of this happens in every practice: the doctor or the biller needs the system after hours, from home, or from a conference in Corpus Christi. Remote access itself is fine. The way it is set up is everything.
The safe way is a VPN — a virtual private network — plus multifactor authentication. Think of it as a private, encrypted tunnel from the home computer straight into the office network. The doctor logs in, approves a code on their phone, and works as if they were at their desk. When the session ends, the tunnel closes.
The unsafe way is remote desktop left open to the internet — the office computer reachable directly from anywhere in the world with just a password. This is one of the most attacked setups in existence, because criminals scan the entire internet looking for exactly it, knocking thousands of times a day. If anyone in your practice “just remotes in” without a VPN, that door needs closing this week, not this quarter.
One more rule for remote work: practice business on practice-managed devices. A home computer shared with teenagers, running no antivirus and five years of toolbars, should not be the window into your EHR — VPN or not.
Laptops, USB Drives, and the Parking Lot
Data also leaves the building in people’s bags. A laptop taken home for the weekend, a USB drive with a billing export, a phone with patient photos — every one of them is the practice’s data traveling without the practice’s walls around it.
The defenses are the same ones from earlier in this series, applied to the road: full-disk encryption on every laptop (so a stolen bag is an inconvenience, not a breach), no patient data on USB drives as a matter of policy, and a simple habit — devices come inside, out of cars, out of sight. A surprising number of breaches start with a smash-and-grab in a parking lot, and encryption is what turns that story from a disaster into a police report.
If someone must carry data physically, make it the exception with a reason, not the routine. “I always take the laptop home just in case” is a habit worth breaking; remote access through the VPN exists precisely so the data can stay put while the person goes home.
What to Do Monday Morning
Three checks, thirty minutes. First, send a test email with patient information the way your staff normally would — is it actually going out encrypted, or did everyone quietly drift back to plain email? Second, read your last ten outgoing patient texts; if any of them contain clinical content, that is your training topic for the week. Third, ask how the doctor and the biller connect from home — if the answer is anything other than “VPN with the phone code,” put fixing it at the top of the list.
Data will keep leaving the building — that is modern practice. The goal was never to stop it. The goal is that every copy traveling outside your walls is encrypted, every message stays on the right side of the logistics line, and every remote door has two locks on it.
Not sure where your practice stands?
Our free network assessment reviews your computers, backups, and security — and gives you a plain-English read on what's solid and what isn't. No scare tactics.
Call (361) 704-1373 or request yours online.
Request your assessment →Not ready to book? Start with the checklist.
Our 10-Point Small Business IT Security Checklist walks you through the ten things that matter most — in plain English, no jargon. Work through it at your own pace. No sales call, no pitch — just the checklist.
Frequently asked questions
Can we email records to a specialist?
Yes — sharing records for treatment is allowed. The requirement is how: use encrypted email or your EHR’s secure messaging, not a plain email with the chart attached.
Can patients text the office?
For logistics like scheduling and reminders, yes, with their consent and on a practice-owned number or service. Keep clinical content out of texts entirely — move those conversations to a call or the patient portal.
Is it okay for the doctor to check charts from home?
Yes, through a VPN with multifactor authentication, on a practice-managed device. What is not okay is remote desktop left open directly to the internet, or charting on a shared family computer.
What if a patient insists we email records to their regular Gmail?
Patients have a right to their records, including by unsecure email if they ask for it. Warn them plainly that regular email is not secure, honor the request, and document that they asked for it that way.
Do we really need a VPN?
If anyone accesses practice systems from outside the office — the doctor, the biller, you — then yes. A VPN with multifactor authentication is the standard, safe way to do it, and it replaces the habit of carrying data home on laptops.
Are appointment reminder texts a HIPAA problem?
No, as long as patients consented to texts and the messages stick to logistics. Keep them free of diagnoses, results, and anything clinical, and you are on solid ground.