Buying Guides

Mapping Every System That Touches ePHI Before You Buy an EMR

The short answer

Most organizations discover the true scope of their patient data after buying the EMR, during the first risk analysis, which is the most expensive order to do it in. Building the inventory first changes the integration requirements, the migration estimate, and the assessment scope, and all three are cheaper to get right before a contract is signed.

The Security Rule's assessment obligation at 45 CFR §164.308(a)(1)(ii)(A) covers electronic protected health information the organization creates, receives, maintains, or transmits. That is an organizational boundary, not a system boundary.

Why the EMR is not the boundary

An EMR purchase is usually scoped from the clinical workflow outward. The inventory has to be built the other way, from the data outward, because data leaves the clinical workflow constantly.

A single encounter can put patient data into the EMR, a picture archiving system, a laboratory information system, a billing clearinghouse, a transcription service, a patient portal, a secure messaging application, and a scheduling reminder platform, before anyone has opened a spreadsheet.

The inventory categories

Work through these six. They cover most of what an organization holds.

Core clinical systems. The EMR or EHR, and any specialty system a service line runs alongside it, such as ophthalmology imaging, cardiology, oncology, or behavioral health.

Diagnostic and ancillary systems. Picture archiving and communication systems, radiology information systems, laboratory information systems, pharmacy systems, and the interfaces that connect them.

Revenue cycle. Practice management, coding, clearinghouse connections, patient statements, and collection agency transfers.

Communication and patient-facing tools. Patient portal, secure messaging, telehealth platform, appointment reminders, intake forms, and any survey tool that returns identified responses.

Endpoints and infrastructure. Workstations, laptops, mobile devices, removable media, on-premises servers, backup systems, and cloud storage.

Everything at the edges. Networked medical devices, fax servers, shared drives, departmental databases built years ago by someone who has left, and paper records still held on site. Paper is not electronic and sits outside the Security Rule, but it is inside the Privacy Rule and it belongs on the map.

Systems people forget

These appear late in nearly every inventory.

  • Networked medical devices such as infusion pumps, imaging modalities, and monitoring equipment
  • Fax servers and multifunction printers that store scanned documents on internal drives
  • Departmental applications a single service line purchased independently
  • Legacy systems kept read-only for record retention after a migration
  • Spreadsheets and local databases used for tracking, referrals, or registries
  • Cloud file shares holding exports that were meant to be temporary
  • Backup and disaster recovery copies, including anything held by a third party
  • Business associate systems, where the data is out of your building but not out of your obligation

How to build the list

A method that works, in five passes.

Pass one, follow the money. Pull the vendor list from accounts payable and mark every entry that could touch patient data. This catches systems purchased outside IT.

Pass two, follow the network. Ask for a list of devices with an address on the clinical network, and reconcile it against the asset register. Differences are the interesting part.

Pass three, follow the interfaces. Ask for every inbound and outbound interface on the current EMR. Each one has a system on the other end.

Pass four, ask the departments. Ask each department manager what they use that is not the EMR. Ask specifically about spreadsheets, and ask without implying it is a problem, or the answer will be "nothing."

Pass five, check the agreements. Every vendor holding patient data on your behalf needs a Business Associate Agreement. Reconcile the list of agreements against the list of systems. Gaps run in both directions, and an agreement with no matching system is as interesting as a system with no agreement.

What the inventory changes about the purchase

Four decisions move once the list exists.

DecisionHow the inventory changes it
Integration requirementsInterfaces become a counted list with named endpoints rather than an estimate
Migration scopeLegacy and departmental systems that must be read from, or retained read-only, become visible before the statement of work
Assessment scopeThe risk analysis covers a known estate, so the effort can be quoted accurately rather than discovered
Vendor and BAA workloadThe agreement count is known, which determines whether tracking is a filing task or a managed program

FAQ

Do we have to inventory systems the EMR will replace?

Yes, while they hold data. A decommissioned system holding retained records is still in scope until the data is disposed of under your retention schedule.

Are paper records part of this?

Paper is outside the Security Rule, which applies to electronic protected health information, but it is inside the Privacy Rule and inside the physical safeguards at 45 CFR §164.310. Put it on the map.

Does a business associate's system count as ours?

The system is theirs. The obligation to have a Business Associate Agreement and to have assessed the arrangement is yours, and the data remains your responsibility to account for.

How often should the inventory be updated?

Treat it as a living record rather than an annual exercise. The practical trigger points are any new vendor, any new interface, any departmental purchase, and any decommissioning.

Is an asset inventory required by HIPAA?

The Security Rule does not name an asset inventory as a standard, but an accurate and thorough risk assessment under §164.308(a)(1)(ii)(A) is difficult to perform without one, and HHS guidance treats knowing where ePHI lives as the starting point.