Your electronic health record is protected by sign-in rules, role-based access and audit logging. The moment someone exports a report to a spreadsheet, those protections stay behind. The file lands in a downloads folder, gets attached to an email, copied to a USB drive or uploaded to a personal cloud account. Resident names, birth dates and diagnoses are now sitting in a file that nobody is watching.
Extracts are a normal and necessary part of operations. Billing teams, quality staff, corporate analysts and surveyors all need data. The goal is not to stop exporting. It is to make sure exported data is handled as carefully as the system it came from.
Copies multiply. One export becomes five when it is emailed and re-saved.
No expiration. Files linger in downloads folders for years.
Weak storage. Personal laptops, shared drives with broad permissions and unencrypted USB sticks are common destinations.
Over-inclusion. Reports often include more columns than the task requires.
Lost context. Months later, nobody remembers why the file exists or who owns it.
HIPAA's minimum necessary standard and its Security Rule safeguards apply to protected health information wherever it lives, including in spreadsheets.
Not every EHR user needs the ability to download data. Review roles and remove export rights from those who do not need them. Combine this with your regular access review. Where your EHR logs exports, ask for those logs to be reviewed periodically, because unusual volumes can indicate misuse.
Before running a report, ask what fields are really needed. Choose the narrowest date range and the fewest columns. If the analysis does not need names, leave them out, and use a resident ID or de-identified values instead. A smaller file is a smaller risk.
Pick one or two locations where extracts may be saved, such as a restricted folder in your company file storage, with access limited to the team that needs it. Prohibit:
Saving to the desktop or downloads folder as a long-term location.
Personal email and personal cloud storage.
Unencrypted USB drives and other removable media.
Messaging apps and text messages.
Company laptops should use full-disk encryption. Files sent outside the organization should go through encrypted email or a secure portal, never an ordinary attachment. If a file must be password-protected, send the password through a different channel.
Share by link or folder permission, with a named list of people, rather than emailing copies. Set expiration dates on links to outside parties. Confirm that a business associate agreement exists before sending protected information to any vendor or consultant.
Decide how long extracts may be kept. A working file might be deleted after the project is finished, or after 30 days, unless there is a reason to keep it. Build a regular cleanup: someone checks the shared folder and removes files past their date. Check for legal holds before deleting anything.
For recurring or sensitive extracts, record who requested it, who ran it, its purpose, where it is stored and when it was deleted. A simple spreadsheet is enough. It helps with audits and incident response, since you can quickly say what data was in which file.
Imagine a regional quality manager who exports a monthly list of falls with resident names and room numbers, saves it to a laptop and emails it to three facility leaders. A better practice would be to export only an ID and the fields needed, save to a restricted folder, share a link with expiration and delete the working file after the review meeting.
Most extract problems happen because people did not realize the risk. Brief training should cover what counts as protected information, where files may be saved, how to send them securely and what to do if one is sent to the wrong person. Make reporting mistakes easy, because quick action limits harm.
Ask IT about data loss prevention tools that can flag or block sensitive data in email and file sharing, about disabling USB storage on company computers and about automatic encryption. These add a safety net, but they cannot replace clear rules.
UnityCare IT works with long-term care and healthcare organizations in Oklahoma, Texas and Arkansas on file storage, encryption and access controls around EHR data. If you are not sure where your exports end up, we can help you find out.
Keeping PointClickCare and other EHR systems fast, connected and available.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172