In this piece
Look for ePHI wherever your team creates, receives, maintains, or transmits it, including locations beyond the EHR. Follow electronic protected health information into billing spreadsheets, email attachments, shared folders, and connected services.
HHS says risk analysis must cover the ePHI an organization creates, receives, maintains, or transmits. Its risk analysis guidance includes identifying information locations and external sources. An inventory helps establish that scope but does not replace the risk analysis.
Follow one real workflow with fictional data
Choose a familiar process such as a billing follow-up or records request. Ask the person doing the work to demonstrate it using synthetic information. Watch where information is opened, copied, attached, downloaded, and forwarded.
Use this illustrative billing workflow as a starting point:
| Step | Possible ePHI location | Person to ask |
|---|---|---|
| Receive a question | Shared mailbox and attachment | Billing coordinator |
| Prepare supporting detail | Exported spreadsheet | Billing system owner |
| Request internal review | Shared folder or chat attachment | Operations lead |
| Send to a partner | Delivery service and recipient system | Vendor relationship owner |
| Work away from the office | Laptop download or synced folder | Device administrator |
| Recover an earlier version | Backup or retained copy | Backup administrator |
The exercise often raises a useful question: which of those copies would disappear from view if you looked only at the list of purchased applications?
Give each location a usable record
A spreadsheet is enough to begin. Create one row per distinct system or location that needs its own ownership or handling decision. Record:
- Location: System name and supported workflow
- Information: ePHI categories without patient details
- Ownership: Business owner and access administrator
- Audience: Authorized groups and external organizations
- Transfers: Sources and onward destinations
- Copies: Local downloads, exports, and backups
- Handling: Vendor agreement and retention decision
- Review: Last check date and unresolved questions
Store the inventory in an approved location with appropriate access. It can reveal sensitive system and security details even when it contains no patient records.
If the map shows repeated copying between inboxes, spreadsheets, and shared folders, request a healthcare pilot around one mapped workflow. Use a fictional version to evaluate IRONKEEP’s private beta workspace for collaboration beyond the EHR, starting with access needs and BAA scope.
Check the places between applications
Ask staff about attachments that are saved before upload, spreadsheets emailed back for correction, screenshots attached to support tickets, and downloads kept for convenience. Ask administrators about forwarding rules, synchronization, mobile access, and retired systems that remain available.
Include service accounts and automated transfers in the conversation. A process can move information without anyone signing in interactively. Document the purpose and destination before deciding whether the connection should remain.
Use the file sharing guide to review document exchanges and the email guide to examine message handling. Those reviews can reveal locations that a license inventory misses.
Include vendors and retained copies
For each outside provider, connect the inventory entry to the service actually being used. Record whether the agreement review is complete or still unresolved. The BAA review guide provides questions for that discussion.
Do not collapse active storage, backup, and archive into a single “cloud” entry if different owners, access rules, or deletion processes apply. Ask who can restore a copy and where the restored information would appear. Connect retention questions to the records retention guide.
Turn the inventory into risk analysis work
After mapping locations, evaluate threats, vulnerabilities, existing safeguards, likelihood, and potential impact. HHS describes those steps, along with documentation and continuing review, in its risk analysis guidance.
For example, “billing export on a laptop” is an inventory finding. The next task is to understand the device’s access controls, recovery arrangements, and exposure scenarios, then determine any needed action. Assign an owner and track resolution.
Review the map when workflows change: a new client, a new integration, a departing contractor, or a replacement application. Keep the process close enough to daily work that staff can point out a missing destination.
Bring the map to a workspace evaluation
Bring a fictional version of one mapped workflow, the roles involved, and the destinations that need review. Compare where copies are created and who administers each step. Keep unresolved questions attached to their inventory entries so the evaluation produces decisions your team can follow up on.
Scope your healthcare workspace.
Evaluate email, files and docs, and team access with IRONKEEP. Start with your workflow and BAA needs.