1. Sources
Registration, portal intake, diagnostic devices, lab feeds, faxes, email, scanned paper, call notes, referrals, e-prescribing, and external records. Document format, identity matching, validation, and temporary storage.
Medical clinics often have PHI spread across more systems than leadership realizes. A reliable HIPAA program starts with a realistic application and data-flow inventory.
Medical software environments are chains of collection, transformation, transmission, storage, and retrieval. The EHR may appear to be the center, but risk often sits in an interface engine, scanning folder, portal connector, lab queue, report export, cloud mailbox, or support account outside the primary application.
Registration, portal intake, diagnostic devices, lab feeds, faxes, email, scanned paper, call notes, referrals, e-prescribing, and external records. Document format, identity matching, validation, and temporary storage.
EHR or EMR, practice management, scheduling, billing, document management, imaging, specialty modules, and local services. Record system owner, administrator, hosting, identity, privilege, logging, backup, and downtime dependency.
HL7 or FHIR interfaces, APIs, clearinghouses, health information exchange, labs, pharmacies, referral portals, secure messaging, fax services, and vendor remote support. Record authentication, encryption, queue monitoring, error handling, and incident contact.
Microsoft 365, cloud drives, shared folders, local downloads, report servers, analytics, archives, backups, mobile devices, print queues, and removable media. Document retention, access, discovery, deletion, and recovery.
A message can arrive for the wrong patient, lose a field, duplicate, queue silently, or fail without user awareness. Assign reconciliation ownership and retain evidence of interface monitoring, correction, and escalation.
Define the clinical consequences when a portal, lab feed, e-prescribing service, identity provider, internet circuit, interface engine, or vendor support channel is unavailable. Test a downtime workflow that does not create uncontrolled PHI copies.
Look for overbroad API scopes, reusable service credentials, test environments with production data, unsecured exports, forgotten integration accounts, vendor support tools, and interfaces whose logs contain patient identifiers.
The technical owner maintains configuration, identity, interfaces, logs, patching, backup, and recovery. The operational owner validates correct patient matching, complete workflow, queue reconciliation, acceptable downtime, and appropriate workforce use. The inventory should name both rather than assigning everything vaguely to “IT.”
For critical lab, imaging, prescription, referral, and result interfaces, define expected volume, failure alerts, retry behavior, duplicate handling, unmatched messages, correction, and escalation. Preserve evidence that someone reviews exceptions and confirms clinical resolution.
Test, training, development, reporting, and analytics environments can contain copied ePHI. Document authorization, de-identification or minimization, access, refresh process, retention, vendor involvement, backup, logging, and secure disposal. Do not assume “test” means low risk.
Inventory client applications, service principals, tokens, scopes, secrets, certificates, owners, expiration, logs, and revocation. Determine whether integrations can read more data than their workflow requires and whether unused credentials remain active after a project or vendor change.
Clinical and billing reports may move to local desktops, shared folders, email, Microsoft 365, SFTP, analytics tools, consultants, or payers. Record who can generate bulk exports, how activity is logged, where files land, how long they remain, and how they are deleted.
Investigation depends on synchronized clocks, retained logs, consistent user identity, and protected records. Document time sources, log coverage, administrative access to logs, retention, export capability, and limitations that could prevent reconstruction of a suspected event.
Test patient identification, allergies, medication information, orders, results, referrals, documentation, prescriptions, scheduling, billing capture, and later reconciliation. Control paper and local files created during downtime and verify safe entry after restoration.
An architecture map is complete only when it shows data movement, trust boundaries, operational ownership, failure detection, recovery dependency, and the evidence needed to investigate inappropriate access or incorrect clinical information.
Clinics may use EHR, EMR, and practice-management systems such as athenahealth, eClinicalWorks, NextGen Healthcare, AdvancedMD, DrChrono. These platforms should be mapped for PHI type, user access, admin control, audit logging, MFA, backup, export behavior, vendor access, and BAA status.
The review should confirm whether each platform is cloud hosted, server based, or hybrid, because local cache folders, scanned documents, report exports, and integration files may create PHI copies outside the primary record system.
Medical workflows often extend into connected services such as Microsoft 365, Google Workspace, RingCentral, Updox, along with lab portals, imaging platforms, e-prescribing tools, clearinghouses, patient communication services, and cloud backup providers.
These tools may be outside the main EHR but still contain PHI in messages, files, call notes, attachments, exports, recordings, backups, or administrative reports. Include them in the same evidence and vendor review.
PHI may exist in scanned intake forms, referral PDFs, lab results, email attachments, fax folders, voicemail transcripts, portal exports, billing reports, claims files, shared drives, laptop downloads, call-center notes, spreadsheet trackers, backup repositories, and local cache folders.
Specialty clinics should also review imaging systems, device exports, procedure reports, diagnostic equipment, and third-party portals used for labs, referrals, authorizations, or patient communication.
Document system owner, vendor, deployment model, PHI stored, ePHI transmission paths, user roles, administrator accounts, privileged access, MFA support, audit-log availability, retention settings, backup coverage, integration points, BAA status, and evidence location.
An inventory is useful only if it becomes part of ongoing operations. Update it after software changes, new integrations, staff changes, vendor changes, acquisitions, incidents, or new clinic locations.
Microsoft 365 can support healthcare operations, but it must be configured with appropriate security, access control, retention, auditing, sharing restrictions, MFA, conditional access, and user training. Email and cloud storage often become informal PHI repositories.
For deeper technical review, see Microsoft 365 Security Audit Services and Microsoft 365 Managed Services.
Use this scrollable worksheet as a starting structure for PHI mapping. It is not a substitute for a full assessment, but it helps teams collect the right evidence.
| Area | PHI or ePHI Risk | Evidence to Review |
|---|---|---|
| Practice management / EHR | Charts, demographics, insurance, treatment, billing | Users, roles, MFA, audit logs, backup scope, BAA |
| Imaging / X-ray / scanner | Images, scans, referrals, exports | Local folders, exports, retention, workstation encryption |
| Email and cloud storage | Attachments, referrals, patient communication | Sharing controls, MFA, retention, DLP, training |
| Billing and clearinghouse | Claims, insurance, payment records | BAA, access, transmission security, reports |
| Backups | Databases, file shares, images, mailboxes | Restore tests, isolation, encryption, retention |
| Remote access | Vendor support paths, admin access | MFA, approval, logging, termination |
| Workstations and laptops | Cached reports, downloads, scans | Encryption, EDR, patching, timeout, disposal |
| Paper and scanned records | Intake, consents, insurance cards | Scanning workflow, disposal, storage, retention |
Document ADT feeds, lab orders and results, imaging links, e-prescribing, eligibility, claims, remittance, referral exchange, patient portal, payment, and analytics. Record direction, protocol, authentication, service account, data elements, error queue, logging, vendor, and downtime behavior.
Include fax folders, email attachments, voicemail transcription, scanned documents, shared drives, call-center notes, spreadsheets, device exports, browser downloads, collaboration channels, and temporary migration files. These often escape EHR-centered reviews.
For each system, name the business owner, technical administrator, vendor escalation contact, backup owner, log source, recovery objective, identity source, and person authorized to approve access. Confirm how the clinic obtains audit logs, preserves evidence, disables a compromised integration, restores service, and notifies affected partners.
Use federal implementation guidance to connect software architecture with risk analysis, access control, integrity, transmission security, audit controls, and contingency planning.
HHS provides the current Security Rule framework for protecting ePHI. Review Security Rule guidance
NIST maps the rule to modern security practices and provides sample questions useful for system and interface inventories. Open the NIST guide
Yes. Portals that contain patient results, images, referrals, or reports should be included in the PHI inventory and vendor review.
No. Microsoft provides capabilities and contractual options, but the healthcare organization remains responsible for configuration, access, training, policies, and appropriate use.
At least annually and whenever systems, vendors, locations, integrations, or PHI workflows change.
OC Security Audit can help map medical software, interfaces, identities, ePHI stores, logs, vendors, risks, and evidence beyond the EHR screen.
IT Perfection can support technical remediation involving Microsoft 365, Azure, endpoints, servers, backups, networks, monitoring, patching, and managed IT operations.
This website uses essential cookies for security and operation. Optional analytics and advertising cookies help measure site use and outreach. Choose Allow or Deny. You can change your choice at any time.