Most healthcare IT teams pour their security budgets into perimeter defences. Firewalls, intrusion detection, endpoint monitoring. But a huge chunk of patient data breaches don’t start with a hacker breaking through a wall. They start with someone on staff emailing a discharge summary to the wrong address, uploading imaging files to a personal Dropbox, or sharing a referral link that never expires.
The HHS Office for Civil Rights breach portal shows that hacking and IT incidents account for over 80% of large healthcare data breaches. But dig into those incident reports, and you’ll find that many of the initial access points trace back to email accounts, unsecured file transfers, and cloud platforms that were never built for protected health information.
Where the Exposure Happens
Picture how clinical files move through a typical health system on any given day. A referring physician emails imaging results to a specialist. A discharge coordinator shares a summary with a post-acute facility using a shared drive link. A nurse uploads patient notes to a personal cloud folder so they can finish charting at home.
Every one of those actions opens an exposure window, a period where ePHI sits outside the organisation’s security controls. The file might travel unencrypted, land in a consumer-grade storage account with no audit trail, or sit in someone’s sent folder indefinitely.
The PIH Health case is a good example. In 2025, HHS settled with the California-based health network for $600,000 after a phishing attack compromised 45 employee email accounts, exposing ePHI for nearly 190,000 patients. The root cause wasn’t some advanced exploit. It was email.
The Clinical Workflows That Create the Biggest Gaps
Not all file-sharing carries the same risk. A few workflows consistently generate the most exposure.
- Referrals and specialist consultations involve large imaging files and clinical notes moving between separate health systems. When EHR-to-EHR transfers fail (and they often do), staff will default to email or consumer file-sharing tools.
- Discharge summaries go to multiple recipients across different systems, and the path of least resistance is usually an unencrypted attachment.
- Imaging transfers push staff towards external file-sharing services because the files are too large for email. Many of those services don’t encrypt end-to-end, and shared links often stay active long after anyone needs them.
What HHS Is Looking For Now
OCR’s enforcement priorities have made one thing clear: they’re no longer just penalising organisations for breaches after the fact. They’re actively investigating whether organisations have done the groundwork to prevent them.
In 2025, risk analysis failures were cited in nearly every OCR enforcement action, from a $25,000 settlement with a small imaging centre to a $3 million penalty against a national medical supplier. The pattern was consistent: these organisations hadn’t mapped where their ePHI was being stored and transmitted. If you don’t know that staff are using personal email accounts to send patient files, you can’t protect against it.
OCR has also confirmed that its 2026 enforcement priorities will expand beyond risk analysis into risk management. Identifying vulnerabilities won’t be enough on its own. Organisations will need to show they’ve taken concrete steps to fix them.
How to Audit Your File-Sharing Tools
If you’re an IT director or compliance officer, here’s a quick framework for evaluating file-sharing against HIPAA requirements:
- Map every ePHI data flow. Document every way files enter, leave, or move within your organisation, including email, EHR exports, fax, cloud drives, and any platforms staff use informally.
- Check encryption status. Are files encrypted both in transit and at rest? Consumer-grade tools usually don’t offer both.
- Review access controls and link expiry. Can shared links be password-protected? Do they expire automatically?
- Confirm audit logging. Can you track who accessed a file, when, and from where?
End-to-end encrypted cloud storage covers several of these requirements in one place. Files are encrypted on the user’s device before upload, so the data stays protected even if the provider’s servers are compromised. Password-protected sharing links with expiry dates will give IT teams control over who can access what.
File Sharing Is a Security Decision, Not Just a Workflow One
The takeaway for healthcare IT teams is simple. Every time a file containing ePHI leaves your controlled environment, whether by email, shared link, or USB drive, it becomes a potential breach. The organisations that avoid enforcement actions aren’t the ones with the fanciest security tools. They’re the ones that have mapped their data flows, locked down their file-sharing methods, and can prove it to OCR when asked.
Start with the audit. Know where your files are going. And make sure the tools your staff are using were actually built to protect patient data.
