We are exhibiting at GISEC Global 2026 · 16-18 Sept · Expo City DubaiBook a booth session with our CEO
AccuSights
Products
Assess
Comply
Protect
Free Tools
Email Breach Checker
Cyber Hygiene Test
Regulator directory
Regulatory calendar
ADHICS
ADGM
CBUAE
CSC
DFSA
DHA
DHCC
DIFC
DOH
FSRA
NIAF
Malaffi
MOHAP
NABIDH
NCAP
SCA
VARA
Healthcare
Finance
AI & Machine Learning
Defence & Military
Government Contractor
Professional Services
Technology & SaaS
Retail & Hospitality
Real Estate & Construction
Architecture, Design & Construction
Cybersecurity in Dubai
Cybersecurity in Abu Dhabi
Cybersecurity in Sharjah
All emirates
Chambers of Commerce
MSP
Partner Program
About Us
Why AccuSights
Compliance Center
Blog
Threat Dashboard
Threat Headlines
Contact

Blog / The data you hold

The data you hold

Where PHI Hides in a Small Practice: 14 Places Nobody Thinks to Check

What is PHI, and where does it live in a small practice? Fourteen places patient data hides outside the practice-management system, and how to find them.

Dr. Kashmala KhalidDr. Kashmala Khalid Dr. KashCo-Founder, healthcare and defense programs2 September 2026 · 6 min read

The intraoral camera has a hard drive

The office manager of a six-operatory dental practice is preparing for the annual HIPAA risk analysis and begins with the sentence she has said for years: "All our patient data is in the practice-management system." Then she walks the building with a clipboard.

Operatory three has the intraoral camera laptop. It stores every image it has ever taken, with patient names, on a local drive that has never been backed up or encrypted. The recall texting tool holds names, mobile numbers and the reason for the next visit. The fax-to-email inbox has eleven years of referral letters and insurance pre-authorizations, searchable by anyone with the password, which is written on a sticky note under the keyboard.

The front-desk WhatsApp group is where the hygienists share photos of a patient's swelling so the dentist can decide whether to come in early. The old panoramic X-ray unit runs on a computer that stopped receiving updates in 2020. The billing clerk's desktop holds a spreadsheet named "outstanding balances" with dates of birth in column C.

By lunch there are fourteen places on the clipboard. The practice-management system is one of them. A risk analysis that looked only at that one system would have missed thirteen doors. The auditor would not. Neither would the attacker.

What this means in plain words

PHI, protected health information, is any information that identifies a patient and relates to their health, their care or the payment for it. Under HIPAA that covers the obvious chart and the less obvious: an appointment reminder, a photo of a molar with a name attached, an invoice with a procedure code.

ePHI is the same information in electronic form. The letter E matters, because the HIPAA Security Rule applies to it, and the Security Rule is what regulators check.

A data inventory, sometimes called data mapping, is the list of every place PHI is created, stored, sent or received. It is the first step of a risk analysis. It is also the step most practices skip, because they assume they already know the answer.

An identifier is any of the eighteen elements HIPAA lists, from name and date of birth to a photograph or a device serial number. Remove all of them and the record is de-identified. Leave one and it is PHI.

In the UAE the same information falls under ADHICS in Abu Dhabi and the Dubai Health Authority's NABIDH policies, which require a complete audit trail on every patient record. Different regulator, same clipboard.

The numbers that matter

OCR announced its 11th and 12th Risk Analysis Initiative settlements in February 2026, and it names the failure to conduct an accurate and thorough risk analysis as the root finding in nearly every recent Security Rule action (HHS OCR, 2026). You cannot analyze the risk to data you have not found.

There were 21 OCR settlements in 2025 (HIPAA Journal, 2026). Most were with providers the size of the practice in this story, not health systems with a legal department.

The median healthcare breach in the first half of 2026 affected 2,451 individuals (HIPAA Journal, H1 2026). That is a dental practice's active patient list. It is no longer the hospital that gets breached; it is you.

What to do this week

  1. Walk the building with a clipboard, every room, and write down each device that has ever displayed or stored a patient's information: the camera laptop, the X-ray computer, the tablet at check-in, the manager's home laptop. (CIS 1 Inventory and Control of Enterprise Assets)
  2. List every application and service the same way: practice-management system, recall texting, fax-to-email, cloud imaging, the messaging app the hygienists use, the payment terminal software. Note who at the practice can log in to each. (CIS 2 Inventory and Control of Software Assets)
  3. For each of the fourteen, decide whether PHI needs to be there at all. Move the intraoral images to the managed server and wipe the local drive. Delete the balances spreadsheet and run the report from the system when it is needed. (CIS 3 Data Protection)
  4. Close the WhatsApp group by Friday and replace it with the secure messaging built into your practice-management system, or a healthcare messaging tool that will sign a business associate agreement. Tell the team why, in one sentence: those photos are patient records. (CIS 3 Data Protection)
  5. Encrypt every device that stays on the list, starting with the laptops that leave the building. Turn on the built-in disk encryption and record the recovery keys somewhere other than the device. (CIS 3 Data Protection)
  6. Date the clipboard list and file it as the data-inventory page of your risk analysis. Repeat the walk when you buy a device, add a vendor or open a room. (CIS 1 Inventory and Control of Enterprise Assets)

Where AccuSights fits

Our assessment begins with the walk, not the software. We find where patient data actually sits, then check whether each place is encrypted, logged and covered by an agreement, and give you a prioritized list a practice manager can act on. The Cyber Hygiene Test takes three minutes. A 15-minute call with an engineer turns the clipboard into a plan that fits the way a clinic runs.

We map the assessment to DoH ADHICS and DHA NABIDH, and our read-only compliance agent shows where patient data sits and which controls have drifted, so you prioritize the right things and keep an eye on them. Like a falcon, it singles out the one thing that matters from the noise. We have no access and do not remediate; you or your IT partner fix, and we show you where.

Questions people ask

Is a patient's name alone PHI? A name on its own, with nothing tying it to health care, is not PHI. A name on a list that came from your practice is, because the list itself says the person is a patient. That is why a mail-merge export of your recall list or a WhatsApp photo captioned with a surname counts. The context supplies the health information even when the words do not.

Are appointment reminders PHI? Yes. A reminder links an identifiable person to a provider, a date and often a reason for the visit. HIPAA allows you to send them, but the tool that sends them holds PHI, so it belongs on your inventory and the vendor needs a business associate agreement. Keep the message content to the minimum: name, time, phone number to reschedule.

Is PHI in email a HIPAA violation? Sending PHI by email is not a violation by itself. Sending it without safeguards can be. The Security Rule expects you to assess the risk and apply reasonable protection, which in practice means encryption in transit, access controls on the mailbox and a rule about what may be emailed to whom. A fax-to-email inbox with eleven years of referrals and a shared password would fail that assessment on every count.

A surgeon counts the instruments before closing. Count the places your patients' records live, and the risk analysis writes itself.

Questions people ask

Is a patient's name alone PHI?

A name on its own, with nothing tying it to health care, is not PHI. A name on a list that came from your practice is, because the list itself says the person is a patient. That is why a mail-merge export of your recall list or a WhatsApp photo captioned with a surname counts. The context supplies the health information even when the words do not.

Are appointment reminders PHI?

Yes. A reminder links an identifiable person to a provider, a date and often a reason for the visit. HIPAA allows you to send them, but the tool that sends them holds PHI, so it belongs on your inventory and the vendor needs a business associate agreement. Keep the message content to the minimum: name, time, phone number to reschedule.

Is PHI in email a HIPAA violation?

Sending PHI by email is not a violation by itself. Sending it without safeguards can be. The Security Rule expects you to assess the risk and apply reasonable protection, which in practice means encryption in transit, access controls on the mailbox and a rule about what may be emailed to whom. A fax-to-email inbox with eleven years of referrals and a shared password would fail that assessment on every count.

Controls this post maps to

CIS 3 Data ProtectionCIS 1 Inventory and Control of Enterprise AssetsCIS 2 Inventory and Control of Software Assets

CIS Controls v8.1, the baseline the UAE IA Standard and ADHICS build on. These are the same controls our assessment scores.

Dr. Kashmala Khalid, Co-Founder, healthcare and defense programs. The clinical and regulatory authority behind the healthcare and defence programmes. Compliance with the precision of a surgeon and none of the fear-mongering. About the team →

Where AccuSights fits

Check, then repeat. We provide read-only insight so you prioritize the right things and keep an eye on them.

We have no access and do not remediate. You or your IT partner fix; we show you where, mapped to your regulators. Thirty minutes with an engineer draws the map for your organization.

Compliance is not security. The audit is not the exam; the attacker is.