Compliance briefing · 30 minutes · no demo
The PHI Exchange Review
Four questions about how patient information leaves your organization, one worksheet of output, thirty minutes. You leave with a PHI exchange map you can take to your compliance committee, or keep on file for your next risk analysis.
- A misdirected email or fax started a breach risk assessment this year
- You can't say how many outside organizations receive PHI from you, or which have a BAA on file
- Your last risk analysis covered your EHR but not email, fax, portals and file links
No demo. No follow-up sequence unless you ask. The worksheet is yours either way.
- Who it's for:
- whoever owns HIPAA compliance at community hospitals, specialty groups and practices, up to about 1,000 staff. IT is welcome but not required.
- Who runs it:
- MnemoShare's CISO and Chief Product Officer, with more than 45 years of combined experience building and running healthcare data platforms and compliance programs.
Compliance briefing · worksheet
PHI Exchange Map
A working artifact from your 30-minute session
- 01Channel inventory
- 02Recipients & BAAs
- 03Evidence of who received it
- 04Breach readiness
01 · Channel inventory
Every way patient data leaves, and the one you can't see into.
02 · Recipients & BAAs
Who receives PHI from you, and is each one covered?
03 · Evidence of who received it
Who opened that record? What could you show, and how fast?
04 · Breach readiness
A misdirected email today: your clock, and your first gap.
The cheapest time to find out which channels your risk analysis missed is before a complaint, an audit or a misdirected fax asks you.
What you leave with
The artifact is yours to use regardless of whether you ever work with us, which is why the blank worksheet is a download rather than a form.
- A PHI exchange map with a channel-by-channel inventory, for your compliance committee, your board, or the practice owner.
- A compliance scorecard that keeps your criteria separate from IT's technical ones. The four answers become the framework you bring to any decision.
- An honest read on which channels carry PHI with no record, and which of the three paths you're closest to. Where the fix isn't something we do, we'll say so.
The four questions we work through
None of them need a data pull, system access or any patient information. Several are most useful when the honest answer is "I'm not sure".
In scope: how PHI leaves your organization, by email, fax, portals, file links and paper. Not in scope: who accesses records inside your EHR. That's a different review, and your EHR's own audit tools cover it.
01
Channel inventory
In how many ways does patient information leave your organization today? We fill in the worksheet's channel grid together: email attachments, fax, the patient portal, file-sharing links, payer and lab portals, paper. Which carries the most, and which can't you see into?
A good answer looks like: A list of channels you can name, a rough sense of which carries the most, and one you'd admit you have no visibility into.
02
Recipients & BAAs
How many outside organizations receive PHI from you: labs, billing and coding companies, transcription, IT and cloud vendors, referring practices? Which are business associates, and when was your BAA list last checked against who actually receives data?
A good answer looks like: You know where the BAA inventory lives and when it was last reconciled. "Legal has them somewhere" is the answer that means no.
45 CFR 164.502(e), 164.504(e)
03
Evidence of who received it
If a patient, an auditor or OCR asked who received or opened a specific record outside your EHR, what could you produce, and how long would it take?
A good answer looks like: A named system, a realistic production time, and an honest list of the channels that leave no record at all.
Audit controls: 45 CFR 164.312(b)
04
Breach readiness
If PHI went to the wrong recipient this morning, who runs the risk assessment, what do they need to judge whether it was actually viewed, and how much of your notification window would finding that out use up?
A good answer looks like: You can name who owns the assessment, state the clock you're on, and say which part of the scope you'd struggle to prove first.
Risk assessment: 45 CFR 164.402 · Notification: 164.404–164.410
The three outcomes
Across the four answers, compliance teams land in one of three places. Only one of them is a project, and we'll tell you which one you're in. Where the answer is fax, paper or a setting in a tool you already own, that's what we'll recommend.
You're fine
Tighten what you have
Your channels are sound and the gaps are process: reconcile the BAA list, turn on encryption you already pay for, tighten fax cover-sheet and minimum-necessary habits. You leave with a short, specific list and no vendor conversation.
Worth pressing
Close one or two channels
Most PHI moves through channels you can evidence, but one or two carry it with no record. Closing those is a contained fix, whether that's a tracked channel, a portal setting or retiring a fax line, and the map says which to start with.
There's work
Consolidate how PHI leaves
PHI leaves through too many tools to evidence any of them well. That's a program, not a fix, and the map is what you use to scope it and make the case for it.
Before you book
- Is this a sales call in disguise?
- No. We don't show you MnemoShare unless your own answers surface something that maps to what we do, and even then only if you ask. If the session ends with us telling you your current stack is fine, that's a normal outcome and we'll say so plainly.
- What if we're happy with our incumbent?
- Then you leave with a documented, dated artifact saying so, which is useful evidence in its own right for a board, an auditor, or a diligence questionnaire.
- Can I just have the worksheet without the call?
- Yes. The download is right there, no email required. It's designed to be self-serve. The session mostly saves you time and adds an outside read on your answers.
- What do you keep, and do you need any of our data?
- We don't record the call, and we don't keep a copy of your worksheet. We keep your name, organization and booking details, and nothing about your answers. Nothing in the session needs system access or patient information, so please don't bring PHI to the call, and no BAA is needed.
- Is this a HIPAA risk analysis?
- No, and we won't call it one. It doesn't replace your Security Rule risk analysis. It's a focused look at one part of it, how PHI leaves, and the map is useful input the next time you do one.
- We're a small practice without a compliance department. Is this for us?
- Yes. The four questions are the same, and a practice's answers are usually shorter. The practice owner or office manager is the right person to join, and a short list of channels to fix can be all a small office needs.
Someone will ask where your patient data goes. Better on your calendar than theirs.
Thirty minutes, four questions, and a map you own, whether the answer is that your channels are fine or that they aren't.
No demo. No follow-up sequence unless you ask. The worksheet is yours either way.