A medical practice can spend months choosing an EHR. Security questionnaires get reviewed. Contracts go back and forth. Someone asks about encryption, somebody else asks about audit logs, and eventually the practice signs off on a system everyone agrees is appropriate for patient data.
Then somebody exports a patient list to a spreadsheet and saves it in the wrong cloud folder.
Or the billing manager starts working from home and accesses a third-party portal from a personal laptop. A new online form sends appointment details into an inbox. The practice adds an AI transcription service, a remote answering service and a new backup provider over the course of a year.
The EHR may still be secure. The problem is that patient information no longer lives only inside the EHR.
The EHR is one room in a much bigger house
A patient fills out a form on the practice website. Referral documents arrive by email. Staff jump between cloud storage, telehealth, payment portals and whatever new AI app someone started using last quarter. None of those additions feel like a major technology decision at the time, which is how the stack gets complicated without anyone really noticing.
Some patient information may never sit inside the EHR at all. It can pass through a web form, a billing system, a backup service or the server environment behind another application. If those systems handle ePHI, details such as encryption, access logs, backups and authentication matter there too, and HIPAA hosting can be part of that setup. The trouble is often a system that nobody remembered to include when the practice last reviewed where its patient data was going.
HHS makes the responsibility fairly clear in its guidance on HIPAA and cloud computing. A cloud service provider that creates, receives, maintains or transmits ePHI on behalf of a covered entity or business associate can itself be a business associate, even when it stores encrypted data without holding the encryption key. The organization using that service still has responsibilities of its own.
That part is easy to underestimate. Signing a business associate agreement matters, but it doesn’t mean the practice can stop asking questions about where information is stored, who can reach it or what happens when something goes wrong.
Follow the data, not the software labels
Take a normal patient visit.
Maria books an appointment online. Her name, phone number and reason for visiting enter one system before she has even opened the patient portal. At check-in, her insurance card is scanned. During the appointment, information goes into the EHR. Afterward, coding and billing data move elsewhere. A lab result comes back. A specialist receives a referral. Later, someone may download a report for an audit or send documentation to a payer.
Where did Maria’s information actually go?
For many practices, that question takes longer to answer than it should. Staff know which applications they open every morning, but they may not know where files are stored behind the scenes, whether an integration makes another copy of the data, who can access backups or whether a vendor relies on subcontractors.
The HIPAA Security Rule goes well beyond having a strong password. HHS addresses areas such as access controls, audit controls, authentication, transmission security and contingency planning, including procedures for backing up ePHI and restoring lost information.
Take one recent appointment and trace what actually happened to the information. Where did the intake form go? Who scanned the insurance card? Was anything emailed, downloaded to a desktop, uploaded to a shared drive or sent to an outside vendor? Do the same for the claim and any referral that followed. That exercise usually turns up more than asking staff to list every system they use from memory.
It doesn’t need to become a six-page diagram. A few boxes on a sheet of paper can be enough. If someone suddenly remembers that the answering service stores call recordings, or that an outside accountant receives exported billing reports every month, you’ve already learned something useful.
Convenience creates quiet exceptions
Security policies usually describe how work is supposed to happen. Daily work has a habit of becoming messier.
A physician needs a report before leaving for the hospital, so someone downloads it to a desktop. The billing team keeps a spreadsheet of unresolved claims because it’s easier to sort. A manager emails herself a file so she can finish it after dinner. An employee who moved to another role six months ago still has access to a folder because nobody thought to remove it.
None of these choices necessarily feels reckless to the person making it. They’re usually shortcuts taken because the approved process feels slower than the task in front of them.
The easiest workaround to prevent is the one staff no longer need. If clinical and billing work can stay inside a HIPAA-compliant billing workflow, there is less reason to export claim lists, email files between coworkers or keep a separate spreadsheet just to bridge two systems. It won’t eliminate every security problem, but it can cut down the number of copies floating around the practice.
Permissions deserve the same level of attention. Asking whether software supports role-based access doesn’t tell you whether the practice is actually using it well.
Look at the receptionist who moved into billing last quarter. Does she still have access to everything she needed at the front desk? When an employee leaves, who shuts off their accounts, and how quickly does it happen? Can administrators see repeated failed logins? Does the office still have a shared password that several people know because changing it would be annoying?
NIST’s HIPAA Security Rule cybersecurity guidance is useful because it treats security as something that has to keep up with the practice, not something settled when a system is purchased. For a small office, the questions can be fairly ordinary: what patient information do we have, where is it sitting today, who can get to it, and what happens if that system is unavailable tomorrow morning? Those answers often tell you more than a policy document written several software purchases ago.
A practice that last reviewed access three years ago may be protecting a version of its workflow that no longer exists.
The vendor list deserves more attention than the feature list
Healthcare software buying tends to revolve around features. Can the tool connect with the EHR? Does it automate scheduling? Can it generate notes quickly? Will the staff actually use it?
Those are reasonable questions. They just aren’t the only ones.
If a vendor will touch patient information, somebody should also know where that information is stored, who can access it, whether subcontractors are involved, whether an appropriate BAA is available and what happens to the data when the contract ends.
Backups deserve a specific question too: has anyone actually tested a restore?
A vendor can truthfully say that data is backed up while still leaving plenty unanswered. How recent is the backup? How long would recovery take? Who is allowed to start the process? Would the practice still be able to see schedules, prescriptions or patient contact details while systems were being restored?
AI has added another wrinkle because new applications can enter a practice faster than older software ever did. An AI-powered EHR can keep AI-supported documentation within a managed clinical system, but that doesn’t stop someone from copying patient details into a separate AI service because they want help rewriting a letter or summarizing a long note.
The same blind spot appears on practice websites. A page listing office hours isn’t especially complicated. A form that asks about symptoms, insurance details or treatment needs is different. Marketing staff may think of it as a lead form while the compliance team sees patient information moving through another system.
Not every vendor deserves the same level of scrutiny. Payroll software that never sees patient information is a different risk from a transcription company processing encounter audio. A scheduling vendor that holds names and appointment reasons deserves more attention than a tool used only to create social media graphics.
Start with the systems that handle the most sensitive information or would cause the biggest disruption if they stopped working. Those are usually the places where a little extra digging pays off fastest.
Wrap-up takeaway
Buying a HIPAA-compliant EHR is an important decision, but plenty can happen to patient information after it leaves the chart. A staff member downloads a report, a website form sends data somewhere unexpected, a billing file gets copied to a spreadsheet, or a new vendor is added and stays off the security team’s radar. Those ordinary handoffs are worth paying attention to because they’re easy to miss once they become part of the daily routine. A practice should be able to name the systems that hold patient information, the people who can access them and the vendors involved along the way. That list won’t stay accurate forever as software and workflows change. Pick one recent patient visit today and follow the information from the first appointment request through the final claim; anything you can’t account for deserves a closer look.