Blog / The data you hold
The data you hold
Where PHI Hides in a Small Practice: 14 Places Nobody Thinks to Check
What is PHI, and where does it live in a small practice? Fourteen places patient data hides outside the practice-management system, and how to find them.
The intraoral camera has a hard drive
The office manager of a six-operatory dental practice is preparing for the annual HIPAA risk analysis and begins with the sentence she has said for years: "All our patient data is in the practice-management system." Then she walks the building with a clipboard.
Operatory three has the intraoral camera laptop. It stores every image it has ever taken, with patient names, on a local drive that has never been backed up or encrypted. The recall texting tool holds names, mobile numbers and the reason for the next visit. The fax-to-email inbox has eleven years of referral letters and insurance pre-authorizations, searchable by anyone with the password, which is written on a sticky note under the keyboard.
The front-desk WhatsApp group is where the hygienists share photos of a patient's swelling so the dentist can decide whether to come in early. The old panoramic X-ray unit runs on a computer that stopped receiving updates in 2020. The billing clerk's desktop holds a spreadsheet named "outstanding balances" with dates of birth in column C.
By lunch there are fourteen places on the clipboard. The practice-management system is one of them. A risk analysis that looked only at that one system would have missed thirteen doors. The auditor would not. Neither would the attacker.
What this means in plain words
PHI, protected health information, is any information that identifies a patient and relates to their health, their care or the payment for it. Under HIPAA that covers the obvious chart and the less obvious: an appointment reminder, a photo of a molar with a name attached, an invoice with a procedure code.
ePHI is the same information in electronic form. The letter E matters, because the HIPAA Security Rule applies to it, and the Security Rule is what regulators check.
A data inventory, sometimes called data mapping, is the list of every place PHI is created, stored, sent or received. It is the first step of a risk analysis. It is also the step most practices skip, because they assume they already know the answer.
An identifier is any of the eighteen elements HIPAA lists, from name and date of birth to a photograph or a device serial number. Remove all of them and the record is de-identified. Leave one and it is PHI.
In the UAE the same information falls under ADHICS in Abu Dhabi and the Dubai Health Authority's NABIDH policies, which require a complete audit trail on every patient record. Different regulator, same clipboard.
The numbers that matter
OCR announced its 11th and 12th Risk Analysis Initiative settlements in February 2026, and it names the failure to conduct an accurate and thorough risk analysis as the root finding in nearly every recent Security Rule action (HHS OCR, 2026). You cannot analyze the risk to data you have not found.
There were 21 OCR settlements in 2025 (HIPAA Journal, 2026). Most were with providers the size of the practice in this story, not health systems with a legal department.
The median healthcare breach in the first half of 2026 affected 2,451 individuals (HIPAA Journal, H1 2026). That is a dental practice's active patient list. It is no longer the hospital that gets breached; it is you.
What to do this week
- Walk the building with a clipboard, every room, and write down each device that has ever displayed or stored a patient's information: the camera laptop, the X-ray computer, the tablet at check-in, the manager's home laptop. (CIS 1 Inventory and Control of Enterprise Assets)
- List every application and service the same way: practice-management system, recall texting, fax-to-email, cloud imaging, the messaging app the hygienists use, the payment terminal software. Note who at the practice can log in to each. (CIS 2 Inventory and Control of Software Assets)
- For each of the fourteen, decide whether PHI needs to be there at all. Move the intraoral images to the managed server and wipe the local drive. Delete the balances spreadsheet and run the report from the system when it is needed. (CIS 3 Data Protection)
- Close the WhatsApp group by Friday and replace it with the secure messaging built into your practice-management system, or a healthcare messaging tool that will sign a business associate agreement. Tell the team why, in one sentence: those photos are patient records. (CIS 3 Data Protection)
- Encrypt every device that stays on the list, starting with the laptops that leave the building. Turn on the built-in disk encryption and record the recovery keys somewhere other than the device. (CIS 3 Data Protection)
- Date the clipboard list and file it as the data-inventory page of your risk analysis. Repeat the walk when you buy a device, add a vendor or open a room. (CIS 1 Inventory and Control of Enterprise Assets)
Where AccuSights fits
Our assessment begins with the walk, not the software. We find where patient data actually sits, then check whether each place is encrypted, logged and covered by an agreement, and give you a prioritized list a practice manager can act on. The Cyber Hygiene Test takes three minutes. A 15-minute call with an engineer turns the clipboard into a plan that fits the way a clinic runs.
We map the assessment to DoH ADHICS and DHA NABIDH, and our read-only compliance agent shows where patient data sits and which controls have drifted, so you prioritize the right things and keep an eye on them. Like a falcon, it singles out the one thing that matters from the noise. We have no access and do not remediate; you or your IT partner fix, and we show you where.
Questions people ask
Is a patient's name alone PHI? A name on its own, with nothing tying it to health care, is not PHI. A name on a list that came from your practice is, because the list itself says the person is a patient. That is why a mail-merge export of your recall list or a WhatsApp photo captioned with a surname counts. The context supplies the health information even when the words do not.
Are appointment reminders PHI? Yes. A reminder links an identifiable person to a provider, a date and often a reason for the visit. HIPAA allows you to send them, but the tool that sends them holds PHI, so it belongs on your inventory and the vendor needs a business associate agreement. Keep the message content to the minimum: name, time, phone number to reschedule.
Is PHI in email a HIPAA violation? Sending PHI by email is not a violation by itself. Sending it without safeguards can be. The Security Rule expects you to assess the risk and apply reasonable protection, which in practice means encryption in transit, access controls on the mailbox and a rule about what may be emailed to whom. A fax-to-email inbox with eleven years of referrals and a shared password would fail that assessment on every count.
A surgeon counts the instruments before closing. Count the places your patients' records live, and the risk analysis writes itself.
Questions people ask
Is a patient's name alone PHI?
A name on its own, with nothing tying it to health care, is not PHI. A name on a list that came from your practice is, because the list itself says the person is a patient. That is why a mail-merge export of your recall list or a WhatsApp photo captioned with a surname counts. The context supplies the health information even when the words do not.
Are appointment reminders PHI?
Yes. A reminder links an identifiable person to a provider, a date and often a reason for the visit. HIPAA allows you to send them, but the tool that sends them holds PHI, so it belongs on your inventory and the vendor needs a business associate agreement. Keep the message content to the minimum: name, time, phone number to reschedule.
Is PHI in email a HIPAA violation?
Sending PHI by email is not a violation by itself. Sending it without safeguards can be. The Security Rule expects you to assess the risk and apply reasonable protection, which in practice means encryption in transit, access controls on the mailbox and a rule about what may be emailed to whom. A fax-to-email inbox with eleven years of referrals and a shared password would fail that assessment on every count.
Controls this post maps to
CIS Controls v8.1, the baseline the UAE IA Standard and ADHICS build on. These are the same controls our assessment scores.
Sources
Dr. Kashmala Khalid, Co-Founder, healthcare and defense programs. The clinical and regulatory authority behind the healthcare and defence programmes. Compliance with the precision of a surgeon and none of the fear-mongering. About the team →
Keep reading
Three more from the same shelf.
AI Governance for a Small Business: NIST AI RMF, ISO 42001 and the UAE AI Charter Without the Consultancy Bill
An AI governance framework a 30-person business can run: what NIST AI RMF, ISO 42001 and the UAE's AI rules ask, and the five documents to write first.
The data you holdCard Data: The Safest Way to Store It Is to Never Touch It
PCI scope reduction in plain terms: why a small business should never store card numbers, what tokenization does, and what changed in SAQ A in 2025.
The data you holdClient Financial Data: What a Law Firm, CPA or Wealth Advisor Is Really Holding
Client financial data security for law firms, CPAs and advisors: what you are holding, the 30-day breach clocks that now apply, and the folder to lock first.
