Spreadsheets Full of PHI: Exporting and Sharing Data Safely

Every healthcare organization runs on spreadsheets. A census export for the dietary team. A list of residents due for assessments. A billing aging report emailed to a consultant. Each begins as a reasonable request and ends as a file with protected health information sitting on a desktop, in a downloads folder or in someone's inbox, long after anyone remembers it exists.

These loose copies are one of the most common and least visible sources of risk. They are also manageable with habits and a few settings. This article covers how to reduce the problem without making staff unable to do their jobs.

Why spreadsheet copies are risky

They multiply. One export becomes five copies as people save, rename and forward it.

They outlive their purpose. Files remain on laptops and shared drives for years.

They escape controls. Once data leaves the EHR or billing system, its permissions, audit trail and access limits no longer apply.

They travel easily. Email attachments can be forwarded to the wrong person, and laptops and USB drives can be lost.

They hide in odd places. Downloads folders, email sent items and personal cloud storage often hold forgotten files.

Under HIPAA, these files are still protected health information, and the same safeguards apply wherever they live.

Start with the question: do you need identifiers at all?

The best protection is not collecting more than necessary. Before exporting, ask:

Could this report use initials, a room number or an internal ID instead of full names?

Is a date of birth needed, or would an age range do?

Can the report be limited to the relevant unit, date range or columns?

Does the recipient truly need all of it?

The HIPAA minimum necessary standard applies to many uses and disclosures, and trimming a report is the easiest way to meet it. Hiding columns is not enough, since hidden data remains in the file. Delete what the recipient should not see.

Control where files live

Designate approved locations

Choose one or two places where files containing PHI may be stored, such as a protected shared drive or your managed cloud storage, with access limited by role. Tell staff plainly that desktops, downloads folders and personal accounts are not approved.

Turn on encryption

Laptops and removable drives should have full-disk encryption. If a device is lost, encryption can be the difference between a minor inconvenience and a reportable breach.

Limit removable media

If USB drives are not needed, restrict them. Where they are needed, use encrypted, organization-approved devices.

Share safely

Avoid plain email attachments

Email is convenient and risky. Prefer a secure sharing link with access limited to named people, expiration dates and the ability to revoke access. If email is unavoidable, use your organization's encrypted email option and confirm recipient addresses before sending.

Verify recipients

Autocomplete fills in the wrong name more often than anyone admits. Build the habit of checking the recipient list before pressing send.

Use business associate agreements

If an outside party, such as a consultant or billing company, receives PHI to do work for you, a business associate agreement should be in place before any data is shared.

Protect with passwords carefully

A password-protected spreadsheet offers some protection, but send the password through a different channel, and do not rely on it alone.

Clean up what exists

Search. Have IT scan shared drives and workstations for files with likely PHI indicators and for large exports.

Sort. Decide what must be kept, moved or deleted.

Delete securely. Remove copies no longer needed, including from Recycle Bins and old backups where practical.

Set a rule. For example, working copies are deleted within 30 days unless a documented need exists.

Repeat. Schedule the cleanup quarterly.

Technical tools that help

Data loss prevention rules that warn or block when someone emails a file containing Social Security numbers or similar patterns

Sensitivity labels that mark and protect files automatically

Audit logs showing who downloaded and shared what

Conditional access limiting downloads to managed devices

Many Microsoft 365 licenses include some of these. They need configuration to be effective.

Train in plain language

Staff are not careless on purpose. They are usually trying to get something done quickly. Short, specific guidance works better than a long policy: where to save, how to share, what to do if a file goes to the wrong person. Make sure everyone knows to report mistakes immediately, without fear of blame, since quick reporting limits harm.

When something goes wrong

If a file is sent to the wrong recipient or a device is lost, report it at once to your privacy or security officer. Whether the event is a reportable breach depends on a risk assessment, which should be documented.

Supporting your team

UnityCare IT helps healthcare organizations find stray PHI, configure encryption and sharing controls, and write simple guidance staff will actually follow.

Related service

An outsourced IT department with proactive maintenance and one number to call.

Related articles

Keep reading

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172