Summary
Protecting sensitive patient information starts with how every detail is documented and shared. This article outlines practical steps for safer EHR records, from secure clinical photos to confidential communication. Insights from experts in the field show how to reduce privacy risks without slowing essential care.
- Contributor
- Staff
- Published
- September 25, 2026
- Contributors







Dr. Cameron Rokhsar MD FAAD FAACS · Jose Ayala MD · Andrei Blaj · Sanju Zachariah · Bharat Sharma · Michele Vacarino LMHC-QS · Andrzej Kulesza · Dr. Robert Thompson DO, MS, CPE, FAAFP · Dr. Christa Smith Ph.D. · Rahul Agrawal · Carol Lokare, RN · Josh Spencer · Jacqueline Stephenson DO, FACS · Katelyn Murray
Store Clinical Photos in Secure EHR Modules

Dr. Cameron Rokhsar MD FAAD FAACS, Founder & Medical Director
A large share of the sensitive documentation in my practice is clinical photography, before and after images of a patient's face or body for a cosmetic procedure, or serial photos tracking a suspicious lesion over time. The protocol I follow is keeping all clinical photos inside the EHR's dedicated, access-controlled imaging module rather than a general device camera roll or a shared drive, with automatic tagging to that patient's chart only, since a stray photo saved locally is one of the easiest ways a practice ends up with an actual privacy breach.
For narrative notes, I document the clinical facts precisely, lesion size, morphology, treatment rationale, without editorializing or including information that is not medically relevant, since anything written in the chart can eventually be read by the patient, another treating physician, or in a legal context. The protocol other practices might benefit from is a standing rule that any photo or note involving a sensitive area or a cosmetic concern the patient is self-conscious about gets a plain, clinical label rather than a casual description, which protects both accuracy and the patient's dignity if that record is ever shared or reviewed.
Verify Portal Proxy Access First

Jose Ayala MD, CEO & Medical Director
In healthcare sensitive information needs as enough detail is required to support good care, but not so much that the chart becomes unnecessarily revealing. In our practice, we always try to keep the medical record focused on the facts that actually affect diagnosis, treatment, or follow up. We also avoid placing sensitive details in places where they do not belong, such as appointment notes, general alerts, or message subject lines, where they may be seen or noticed by more people than necessary.
One habit that has made a real difference is checking portal and proxy access before sending sensitive information electronically. For example, before sharing a sensitive test result or personal history through the portal, we confirm whether anyone else has authorized access to that account and choose a more appropriate communication method when needed. That extra check takes very little time but can prevent an unintended disclosure. The U.S. Department of Health and Human Services (HHS) notes that EHR safeguards should include access controls and audit capabilities so electronic health information is available only to authorized users.
Match Security Friction to Risk

Andrei Blaj, Co-founder
My perspective on this is from the platform side. I build the systems clinicians use to document and share sensitive patient information, so I'll speak to the protocols that make efficient, private documentation possible rather than the clinical act of charting itself.
The core principle we design around is that privacy and efficiency shouldn't be in tension. When security adds friction, clinicians create workarounds, and workarounds are where sensitive data actually leaks. So the goal is to make the private, compliant path the easiest path.
The protocol I'd point others to is tiered access with friction calibrated to sensitivity.
Not every action carries the same risk, so not every action should carry the same barrier. Routine clinical access uses single sign-on with the institution's identity provider, so clinicians don't have to log in repeatedly during normal work. But higher-risk actions, like sharing a record externally or accessing especially sensitive data, trigger additional verification. The highest-risk actions, such as bulk exports, require multi-factor verification and an audit log entry that the user can see.
This keeps day-to-day documentation fast, because the common case is frictionless, while concentrating protection on the actions that actually matter. Clinicians stop feeling like security is fighting them, which means they stop working around it.
The second protocol worth adopting is structured documentation rather than free text, where possible. When information is captured in discrete, structured fields rather than narrative notes, it's easier to apply granular access controls, audit, and de-identify data when it needs to be shared. Free text is harder to protect because sensitive details can appear anywhere in it. Structure makes privacy enforceable.
Underlying both is a design principle I'd urge any organization to adopt: build privacy into the architecture rather than bolting it on. Encryption in transit and at rest, least-privilege access by default, and immutable audit logs on every access should be defaults, not features. Retrofitting them later is far more expensive, and in healthcare, getting it wrong isn't recoverable.
The one protocol I'd single out: calibrate friction to risk. Make the routine easy and the sensitive deliberate.
Treat Every Artifact as PHI

Sanju Zachariah, Software Specialist, Management Consult for IT Automation, IT Program Manager, Founder & President
Plays Well With Others: Good privacy practices and efficient documentation should be born from the same design process. Operationally, that might mean confining data to the approved EHR whenever possible, structured documentation when you can, and restricting access to what a person needs to complete the task at hand. Your team doesn't need to create side channels for patient info to optimize workflows, and having a clear, read-only document trail can eliminate questions about who changed what without bureaucratizing.
A process I recommend is by treating any artifact capable of containing PHI-application logs, error reports, screenshots, export files, and even Notes-as PHI, capturing only what is needed, removing unneeded identifiers if information migrates outside of the chart, and holding third-party vendors to the same standard. Making it easier to comply with privacy even when you don't want to will save headaches at review time.
Adopt Immutable Segmented Audits

Bharat Sharma, Delivery Manager, Enterprise CX Solutions
In order to effectively secure confidential information contained in patients' medical records, organizations must transition their focus from a general electronic medical record interface to the peculiar details of each data transaction. The information's confidentiality can be maintained by ensuring that sensitive data is processed in a trusted and encrypted workflow before it enters the shared database. Over the last 20 years of managing the company's document workflow processes, mainly in the field of healthcare, I have come to understand that the greatest risk of confidentiality violations takes place during the manual typing of confidential notes or in situations when several people are allowed to see an open record. While in most companies the record is treated as a regular notepad, efficient teams always prefer using encryption containers for their sensitive information. Moreover, using this technology results in complete identifying information concerning the user that typed the particular data.
An example of what I suggest is called Immutable Segmented Audit. Instead of providing opportunities for straight editing changes to a patient's record, companies must use a framework based on treating each note as a separate event that is digitally signed. This means that instead of entering data into a common text box, the provider will have to go through filling in a secure form which requires a digital signature. This approach ensures that such data gets a timestamp and remains unchanged from the moment it was created.
Redact Identifiers and Require Two-Factor Access

Michele Vacarino LMHC-QS, Clinical Director
Electronic health records have made our lives as medical practitioners at once easier and more difficult. Navigating patient interactions and making sure to follow HIPAA laws can be tricky when you are doing much of your communication and almost all of your documentation work electronically.
Good patient notes are essential, not only for your own successful treatment of the patient, but they can also be useful to other doctors to whom you may refer the patient. Thorough notes allow doctors to take over care of a patient without starting from scratch. But, keeping them compliant and maintaining patient privacy is a top priority.
One of the most important ways that I protect private patient data is by adhering closely to the AMA's information blocking guidelines. These protocols serve to discourage access to and exchange of a patient's electronic health information record.
I also practice redaction, or in other words, I hide all sensitive identifiers like names when they are not needed. Using a combination of redaction and employing 2-factor authentication protocols for anyone accessing patient data, both within the clinical staff and from outside, including the patient, act as my first lines of defense when protecting patient privacy in my clinical notes.
Write Respectful Need-to-Know Records

Andrzej Kulesza, Co-Founder & Medical Director
In addiction medicine this question carries extra weight, because a substance use history in the wrong hands can cost a patient a job, a custody case or a professional licence. From years on the front lines of emergency medicine before transitioning to addiction and mental health treatment, the protocol I rely on is simple: write every note as though the patient will read it and as though it may one day leave the building.
In practice that means three habits. Document observations and clinical facts rather than characterisations, so "reports drinking daily, last drink 10pm" rather than labels that read as judgement. Record only what the care decision requires, since detail that is not clinically needed is pure risk. And avoid copying forward from previous notes, which is how outdated or sensitive information spreads into places it no longer belongs.
The benefit is twofold. Records become safer to share on a need-to-know basis with other clinicians, and patients who ask to see their own notes, which is increasingly common, find them accurate and respectful rather than distressing. That builds the trust that makes honest disclosure possible in the first place.
Use the Screen Turn Protocol

Dr. Robert Thompson DO, MS, CPE, FAAFP, Medical Contributor
The best way to protect privacy for the things you are typing is to type less. I've been practicing emergency medicine for the last 28 years and the one thing I have learned the fastest was asking myself before I start typing this: "Does the next clinician need this detail to make a decision?" Your partner beating you, an affair, an abortion, an immigration status, a relapse. If not, it goes in the encounter as a short clinical phrase that has the same value as three long paragraphs of narrative: "Patient reports interpersonal violence, safety plan discussed, resources given." It will cause a fraction of the problem when the chart is subpoenaed or displayed on a shared portal at the kitchen table.
Don't make reference to third parties - don't refer to the boyfriend, don't refer to the coworker, don't refer to the person who drove them over. Just don't do that. That name has no clinical value, and it's the most common thing I see clinicians say to regret in a record.
The screen turn is the protocol to steal. Before I sign a sensitive note, I turn the monitor and read the assessment out loud to the patient. The screen turn protocol takes ninety seconds. It catches errors, builds trust, and makes the patient a partner in what gets recorded about them.
Apply a Detail-by-Detail Relevance Test

Dr. Christa Smith Ph.D., Psychologist
Write every sensitive note as though the patient will read it, because increasingly they will, and because that single assumption settles most of the judgment calls before you have to make them. The protocol worth adopting is a relevance test applied detail by detail: does this specific fact change what the next clinician does. If it does not, it belongs in the record as a category rather than a narrative. A history of interpersonal trauma is clinically necessary and should be there. The identity of the other person, the location, the sequence of events almost never changes management, and recording it creates durable exposure for the patient in exchange for nothing clinical. So the line reads: patient reports a history of interpersonal trauma, relevant to current presentation, details discussed and held at the patient's discretion. There is a second effect worth knowing about. Patients disclose more, and earlier, once they understand that the granular version is not being typed while they speak. Document what governs the treatment. Remember the rest.
Check Source, Destination, and Reviewer

Rahul Agrawal, Founder & CEO
My perspective is healthcare software implementation. I recommend a three-check protocol before an AI-assisted note or handoff moves downstream: source, destination, reviewer.
First, keep the original encounter information traceable so the clinician can check the draft. Second, distinguish the clinical record from the administrative task it generates. Third, require clinician review, editing and sign-off before documentation enters the record or billing workflow.
An illustrative example: a patient needs a return appointment after discussing a sensitive concern. Preserve the clinically necessary detail in the authorized medical record; give the scheduling task the information staff need to arrange the visit, without automatically copying the whole narrative into reminders or general work queues.
Have the practice's privacy lead approve role-based templates and access rules before rollout. HHS guidance supports limiting unnecessary access, but its minimum-necessary standard has exceptions, including disclosures to or requests by providers for treatment. It should not become an excuse to strip useful clinical context from care.
The practical takeaway: reduce redundant copying, and make the destination of sensitive information as deliberate as its wording.
Read Each Line Aloud Before Sign-Off

Carol Lokare, RN, Nursing Education Advisor
Anyone who charts for a living knows sensitive details slip in when you're rushing between five patients and three call lights. My rule is to chart what the care team needs and nothing extra. If a patient mentions a painful divorce while I'm hanging an IV, I chart "reports poor sleep for two weeks" and leave the story out.
The protocol I'd push every nurse to adopt is to write every note as if the patient will read it. Since 2021, the 21st Century Cures Act has given patients electronic access to most of their clinical notes.
At the medical respite facility where I worked with people experiencing homelessness, I watched labels like "drug seeking" follow patients from one hospital to the next for years. Some stopped coming in for care because they felt judged before they ever sat down.
So before I sign any note, I ask one question, would I read this line out loud to the patient, and if not, I rewrite it. "Noncompliant" becomes "did not take evening dose, states cost is the barrier," and "drug seeking" becomes "requested pain medication twice in four hours." Both give the next nurse more useful facts, and neither insults the patient.
Vet AI Privacy Before Chart Finalization

Josh Spencer, Founder
Before any AI-assisted documentation step, require clear answers to the privacy questions that matter (where data goes, who can access it, what a BAA covers) and keep a clean line between ambient capture and what is finalized in the chart.
Route Essential Details to Confidential Fields

Jacqueline Stephenson DO, FACS, General Surgery
My protocol is a clinical relevance and placement check before I sign the note. For every sensitive detail, I ask two questions: Does this information affect diagnosis, treatment, procedural safety, consent, or follow-up? If so, where in the EHR does it belong so that the appropriate members of the care team can find it without repeating it throughout the chart?
I document necessary facts in neutral, specific language and avoid personal commentary, speculation, or background that does not change care. When the EHR offers designated confidential fields or role-based access controls, particularly sensitive information should be placed there rather than copied into general notes, problem lists, or messages. Copy-forward text also deserves review because an old sensitive detail
can persist long after it stops being clinically relevant.
The goal is not to make the record vague. In surgical care, omitting relevant history can create safety risks. The better standard is to document enough for safe, coordinated care while avoiding unnecessary duplication and limiting access according to the organization's privacy policies. A useful final check is: "Would the next clinician understand what matters without learning anything they do not need?"
Encrypt Enquiries From First Contact

Katelyn Murray, Digital Marketing Specialist
One protocol our agency believes every health practice should adopt is keeping sensitive information strictly on a need-to-know basis from the very first point of contact, even before a patient record exists.
That first contact is often a website enquiry form, where people share names, contact details and health concerns. A standard contact form usually emails that in plain text, copies it into the website database and includes it in backups, so anyone with admin access can see it. That includes the web agency, hosting provider and plugin supplier, none of whom the person meant to share their story with.
Co-founder Scott Maynard says, "We've seen countless practice websites unknowingly using insecure general-purpose forms to submit personal health information, including full names, explanations of health conditions, and it definitely felt like something that needed addressing."
His principle is to simply separate the notification from the content. The people responding to an enquiry may need the full context. Everyone else only needs to know that it has arrived.
In practice, that means encrypting the enquiry when it's submitted, letting only the staff responding unlock it, and moving the details into the patient record only once the person becomes a patient. It also keeps things efficient, because staff work from one secure place instead of hunting through inboxes and website plugins.