← All posts
Filed in / hipaa · security · compliance

HIPAA Compliant File Sharing: From Upload to Offboarding

In this piece
  1. 01 Map where the files go
  2. 02 Check the agreement and the sharing defaults
  3. 03 Test access with three different people
  4. 04 Separate link access from downloaded copies
  5. 05 Plan recovery and retention separately
  6. 06 Assign the retention decision
  7. 07 Make the pilot produce a working procedure

HIPAA compliant file sharing requires reviewing the entire exchange, from upload and recipient access to retained copies and offboarding. Follow one business process, such as sending supporting records to a billing partner.

Use synthetic records to test the chosen process. Include electronic protected health information (ePHI) in attachments, shared folders, chat conversations, and synced downloads in your review.

Map where the files go

HHS risk analysis guidance calls for identifying the ePHI an organization creates, receives, maintains, or transmits and assessing the risks to it. A review limited to the EHR can miss other places where staff work with the same information. See HHS guidance on risk analysis.

For your chosen process, write down who uploads the file, who receives it, where copies are stored, and who decides when access ends. Include the file name and notification content: patient details can be exposed before anyone opens the document.

Use that map to build a short list of approved destinations. A tool should earn a place on that list through review of its contract, configuration, and actual behavior.

Check the agreement and the sharing defaults

HHS specifically warns that file-sharing and cloud tools introduce risks that belong in risk analyses, risk management, and business associate agreements (BAAs). Its file-sharing guidance also highlights the danger of security controls being disabled or left at default settings.

Ask the vendor which file services and integrations its BAA covers. Then inspect the settings users will encounter on their first upload. Check who can see a newly created folder.

Use the following recommended tests to evaluate your intended sharing workflow.

Test access with three different people

Create a document owner, an intended recipient, and an unrelated test user. Try each action from all three accounts:

Action What to establish
Open a shared link Whether access requires the intended identity or simply possession of the URL
Browse the parent folder Whether one shared file exposes neighboring records
Reshare the document Who can add recipients and how the owner learns about it
Edit or replace a file Whether changes are attributable and earlier versions can be recovered
Remove a recipient Whether access stops in existing sessions as well as new ones

Choose a sharing scope appropriate to the task, recognizing that HIPAA’s minimum necessary standard has exceptions, including disclosures to or requests by a healthcare provider for treatment. Avoid applying a blanket rule that every treatment disclosure must be reduced to a fixed subset of a record. See HHS minimum necessary guidance.

If your current sharing process is difficult to explain or repeat, request a healthcare file-sharing pilot with IRONKEEP. Bring one document exchange and the three test roles above to scope the evaluation. The workspace is in private beta, with BAA scope reviewed before introducing ePHI.

Revoking a link can stop future access through that service. It cannot retrieve a file already downloaded to another device.

For the billing example, agree on the recipient’s handling process before the transfer: where they store the file, who else can access it, and what happens when the engagement ends. Check whether staff can complete the work through the approved service without creating extra copies just to get around a difficult interface.

If the process also uses email, include the email workflow review in the same exercise.

Plan recovery and retention separately

Run a recovery test with a disposable file. Delete it, restore it, and confirm that the correct content and permissions return. Record who can perform the recovery and what information they need.

The HIPAA Privacy Rule does not establish a universal medical-record retention period; HHS points to state laws that generally govern retention. Protection still applies while records are maintained, including disposal. See HHS medical-record retention guidance.

HIPAA separately requires certain Security Rule documentation to be retained for six years from creation or last effective date, whichever is later. That is not an instruction to delete all healthcare files after six years. See the HHS Security Rule summary.

Assign the retention decision

Have the records owner resolve schedules and preservation obligations before enabling automatic deletion.

Make the pilot produce a working procedure

At the end of the evaluation, keep a simple record of the approved sharing path, access settings, recovery test, and offboarding steps. Repeat the exercise when a new partner or integration changes where files go.

Bring a synthetic document, the intended recipient list, and your recovery requirements to the evaluation. Use the BAA questions to connect the vendor review to that exchange.

Healthcare · Private beta

Scope your healthcare workspace.

Evaluate email, files and docs, and team access with IRONKEEP. Start with your workflow and BAA needs.

Request a healthcare pilot