Every healthcare organization runs on spreadsheets. A census export for the dietary team. A list of residents due for assessments. A billing aging report emailed to a consultant. Each begins as a reasonable request and ends as a file with protected health information sitting on a desktop, in a downloads folder or in someone's inbox, long after anyone remembers it exists.
These loose copies are one of the most common and least visible sources of risk. They are also manageable with habits and a few settings. This article covers how to reduce the problem without making staff unable to do their jobs.
They multiply. One export becomes five copies as people save, rename and forward it.
They outlive their purpose. Files remain on laptops and shared drives for years.
They escape controls. Once data leaves the EHR or billing system, its permissions, audit trail and access limits no longer apply.
They travel easily. Email attachments can be forwarded to the wrong person, and laptops and USB drives can be lost.
They hide in odd places. Downloads folders, email sent items and personal cloud storage often hold forgotten files.
Under HIPAA, these files are still protected health information, and the same safeguards apply wherever they live.
The best protection is not collecting more than necessary. Before exporting, ask:
Could this report use initials, a room number or an internal ID instead of full names?
Is a date of birth needed, or would an age range do?
Can the report be limited to the relevant unit, date range or columns?
Does the recipient truly need all of it?
The HIPAA minimum necessary standard applies to many uses and disclosures, and trimming a report is the easiest way to meet it. Hiding columns is not enough, since hidden data remains in the file. Delete what the recipient should not see.
Choose one or two places where files containing PHI may be stored, such as a protected shared drive or your managed cloud storage, with access limited by role. Tell staff plainly that desktops, downloads folders and personal accounts are not approved.
Laptops and removable drives should have full-disk encryption. If a device is lost, encryption can be the difference between a minor inconvenience and a reportable breach.
If USB drives are not needed, restrict them. Where they are needed, use encrypted, organization-approved devices.
Email is convenient and risky. Prefer a secure sharing link with access limited to named people, expiration dates and the ability to revoke access. If email is unavoidable, use your organization's encrypted email option and confirm recipient addresses before sending.
Autocomplete fills in the wrong name more often than anyone admits. Build the habit of checking the recipient list before pressing send.
If an outside party, such as a consultant or billing company, receives PHI to do work for you, a business associate agreement should be in place before any data is shared.
A password-protected spreadsheet offers some protection, but send the password through a different channel, and do not rely on it alone.
Search. Have IT scan shared drives and workstations for files with likely PHI indicators and for large exports.
Sort. Decide what must be kept, moved or deleted.
Delete securely. Remove copies no longer needed, including from Recycle Bins and old backups where practical.
Set a rule. For example, working copies are deleted within 30 days unless a documented need exists.
Repeat. Schedule the cleanup quarterly.
Data loss prevention rules that warn or block when someone emails a file containing Social Security numbers or similar patterns
Sensitivity labels that mark and protect files automatically
Audit logs showing who downloaded and shared what
Conditional access limiting downloads to managed devices
Many Microsoft 365 licenses include some of these. They need configuration to be effective.
Staff are not careless on purpose. They are usually trying to get something done quickly. Short, specific guidance works better than a long policy: where to save, how to share, what to do if a file goes to the wrong person. Make sure everyone knows to report mistakes immediately, without fear of blame, since quick reporting limits harm.
If a file is sent to the wrong recipient or a device is lost, report it at once to your privacy or security officer. Whether the event is a reportable breach depends on a risk assessment, which should be documented.
UnityCare IT helps healthcare organizations find stray PHI, configure encryption and sharing controls, and write simple guidance staff will actually follow.
An outsourced IT department with proactive maintenance and one number to call.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172