Data Exports From Your EHR: Safe Handling of Extracts

Your electronic health record is protected by sign-in rules, role-based access and audit logging. The moment someone exports a report to a spreadsheet, those protections stay behind. The file lands in a downloads folder, gets attached to an email, copied to a USB drive or uploaded to a personal cloud account. Resident names, birth dates and diagnoses are now sitting in a file that nobody is watching.

Extracts are a normal and necessary part of operations. Billing teams, quality staff, corporate analysts and surveyors all need data. The goal is not to stop exporting. It is to make sure exported data is handled as carefully as the system it came from.

Why extracts are risky

Copies multiply. One export becomes five when it is emailed and re-saved.

No expiration. Files linger in downloads folders for years.

Weak storage. Personal laptops, shared drives with broad permissions and unencrypted USB sticks are common destinations.

Over-inclusion. Reports often include more columns than the task requires.

Lost context. Months later, nobody remembers why the file exists or who owns it.

HIPAA's minimum necessary standard and its Security Rule safeguards apply to protected health information wherever it lives, including in spreadsheets.

Controls to put in place

1. Limit who can export

Not every EHR user needs the ability to download data. Review roles and remove export rights from those who do not need them. Combine this with your regular access review. Where your EHR logs exports, ask for those logs to be reviewed periodically, because unusual volumes can indicate misuse.

2. Apply minimum necessary

Before running a report, ask what fields are really needed. Choose the narrowest date range and the fewest columns. If the analysis does not need names, leave them out, and use a resident ID or de-identified values instead. A smaller file is a smaller risk.

3. Define approved storage locations

Pick one or two locations where extracts may be saved, such as a restricted folder in your company file storage, with access limited to the team that needs it. Prohibit:

Saving to the desktop or downloads folder as a long-term location.

Personal email and personal cloud storage.

Unencrypted USB drives and other removable media.

Messaging apps and text messages.

4. Encrypt in storage and in transit

Company laptops should use full-disk encryption. Files sent outside the organization should go through encrypted email or a secure portal, never an ordinary attachment. If a file must be password-protected, send the password through a different channel.

5. Control sharing

Share by link or folder permission, with a named list of people, rather than emailing copies. Set expiration dates on links to outside parties. Confirm that a business associate agreement exists before sending protected information to any vendor or consultant.

6. Set retention and deletion rules

Decide how long extracts may be kept. A working file might be deleted after the project is finished, or after 30 days, unless there is a reason to keep it. Build a regular cleanup: someone checks the shared folder and removes files past their date. Check for legal holds before deleting anything.

7. Name an owner and keep a log

For recurring or sensitive extracts, record who requested it, who ran it, its purpose, where it is stored and when it was deleted. A simple spreadsheet is enough. It helps with audits and incident response, since you can quickly say what data was in which file.

A hypothetical example

Imagine a regional quality manager who exports a monthly list of falls with resident names and room numbers, saves it to a laptop and emails it to three facility leaders. A better practice would be to export only an ID and the fields needed, save to a restricted folder, share a link with expiration and delete the working file after the review meeting.

Train staff

Most extract problems happen because people did not realize the risk. Brief training should cover what counts as protected information, where files may be saved, how to send them securely and what to do if one is sent to the wrong person. Make reporting mistakes easy, because quick action limits harm.

Use technology to help

Ask IT about data loss prevention tools that can flag or block sensitive data in email and file sharing, about disabling USB storage on company computers and about automatic encryption. These add a safety net, but they cannot replace clear rules.

UnityCare IT works with long-term care and healthcare organizations in Oklahoma, Texas and Arkansas on file storage, encryption and access controls around EHR data. If you are not sure where your exports end up, we can help you find out.

Related service

Keeping PointClickCare and other EHR systems fast, connected and available.

Related articles

Keep reading

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172