Where Your Clinic’s Patient Data Actually Lives

Before you can protect patient data, you have to know where all of it is. Most clinic owners can name their EHR — and that is where the list ends.

Nurse reviewing patient information on a tablet

Your EHR Is Only the Beginning

If you ask a clinic owner where patient data lives, you get one answer: the EHR. And that answer is right — the EHR is the system of record, the place charts live, the software you pay for every month.

But it is also incomplete, and the incomplete part is where the trouble starts. Every time someone exports a report, prints a schedule, emails a referral, or photographs an insurance card, a second copy of patient data is born. Then a third. Then a twentieth. A ten-chair dental practice in Portland can easily hold patient data in a dozen places the owner has never written down in one place.

HIPAA’s Security Rule requires every covered practice to complete a risk analysis — an honest look at where electronic patient data could be exposed and what you are doing about it. You cannot do that analysis on data you have not found yet. The inventory comes first. Everything else in this series — encryption, access control, devices — assumes you know what you are protecting.

Email, Faxes, and the Paper Trail

Start with the copies hiding in plain sight. Referral letters with diagnoses attached and emailed to a specialist in Corpus Christi. Prior-authorization forms sent to insurance. Explanation-of-benefits files downloaded from a payer portal and saved to somebody’s desktop. Every one of those is patient data sitting outside the EHR.

Then there is the fax machine. Plenty of Coastal Bend practices still fax every day — specialists, pharmacies, insurers. A fax that prints at the other end lands in an output tray where anyone walking by can read it. The fax you receive sits in your tray the same way. And many multifunction printers keep a digital copy of everything they scan, fax, or copy on an internal hard drive most owners do not know exists.

Old email accounts are another quiet one. A biller who left two years ago may still have an inbox full of claim attachments, and if nobody disabled the account, that inbox is still reachable. Shared drives fill up with scanned intake forms named things like scan001.pdf, sitting in folders the whole office can open.

Phones, Tablets, and the Front Desk

Walk up to your own front desk and look at what is within arm’s reach. There is usually a computer logged in all day, sometimes under a login the whole staff shares. There may be a tablet patients use for intake forms, and a phone the front desk uses to text appointment reminders.

Now think about personal phones. It is common — and completely understandable — for staff to snap a photo of an insurance card or a driver’s license with their own phone when the scanner is acting up. That photo then lives in a camera roll, backs up to a personal cloud account, and stays there long after the patient has left. Nobody meant any harm. But that is patient data on a device the practice does not control, cannot wipe, and cannot audit.

Do not forget voicemail. Patients leave messages with their full name, date of birth, and why they are calling. If those messages live on a phone system nobody manages, or get emailed as audio files to a shared inbox, that is another copy — with some of the most sensitive details a patient can share.

Billing, Backups, and the Back Room

Your billing setup is a data store most owners underestimate. The practice management system, the clearinghouse portal, downloaded remittance files, spreadsheets the biller keeps “just in case” — all of it holds names tied to diagnoses and procedures. If your biller works from home some days, ask where those files go after hours.

Then there is the back room. Almost every clinic has one: a storage room with paper charts from years ago, a retired computer nobody wiped, an old server humming in a closet, a stack of drives from a system upgrade. If any of it ever held patient data, it is still your responsibility until it is properly wiped or destroyed — deleting files is not wiping, and a drive in a closet is not “out of sight, out of mind” under HIPAA.

Shred bins deserve a mention too. The bin itself is fine — it means you are trying. But a bin that overflows for three weeks, or a bag of half-shredded pages, is a gap. Paper counts under the Privacy Rule even though most of the safeguards in this series are about electronic data.

What to Do Monday Morning

Set aside thirty minutes and walk your own office with a notepad. Write down every device that touches patient information: computers, tablets, phones, printers, fax machines, the voicemail system, USB drives, the old computer in storage. Then ask your staff one question: “When you need patient information to do your job, where do you go to get it?” The answers will surprise you, and that list — messy, handwritten, honest — is the first real inventory most practices ever make.

Keep the list somewhere safe, date it, and revisit it once a year or whenever you add new software or equipment. You have just done the hardest part of a risk analysis: admitting where the data actually is.

Not sure where your practice stands?

Our free network assessment reviews your computers, backups, and security — and gives you a plain-English read on what's solid and what isn't. No scare tactics.

Call (361) 704-1373 or request yours online.

Request your assessment →

Not ready to book? Start with the checklist.

Our 10-Point Small Business IT Security Checklist walks you through the ten things that matter most — in plain English, no jargon. Work through it at your own pace. No sales call, no pitch — just the checklist.

Your download link appears right after you submit. Prefer to talk? Call (361) 704-1373, Mon–Fri 8am–5pm CT.

Frequently asked questions

Does HIPAA actually require a data inventory?

Not by that name. The Security Rule requires a risk analysis of where electronic protected health information lives and what threatens it. You cannot do an honest risk analysis without first listing every place the data sits — so in practice, the inventory is step one.

What counts as patient data beyond the EHR?

Anything that ties a person to health information: names with diagnoses, dates of birth, insurance details, photos of ID cards, voicemails, billing records. If it could identify a patient and says something about their care or payment for care, treat it as protected.

Do paper records count?

Yes. The Security Rule focuses on electronic data, but the Privacy Rule covers paper too. Old charts in storage, printed schedules, fax printouts — all of it needs the same common-sense protection: locked up, limited access, shredded when done.

How often should we redo the inventory?

At least once a year, and any time you add software, replace equipment, or change how the office works. A new intake tablet or a biller starting to work from home changes the map.

What about the old computer in the storage room?

If it ever stored patient data, it is still your responsibility until the drive is properly wiped or destroyed. Deleting files or reformatting is not enough. Keep a written record of what you did with it and when.