Free tool
Map how patient data moves through your practice.
Drag entities onto the canvas, draw connections between them, and the mapper automatically scores each data flow for HIPAA compliance risk. Missing BAAs, unencrypted transports, and non-compliant vendors surface instantly.
16
Entity types
Patient, EHR, Cloud, Telehealth, Vendors, and more
5
Risk levels
Minimal → Severe, auto-calculated per connection
4
Templates
Basic PHI, Telehealth, Cloud Migration, Full Practice
11
Transport methods
Encrypted API, VPN, SFTP, fax, USB, and more
Sample map
A completed flow for a solo dental practice.
Six operational entities, each with an auto-calculated risk score and BAA status. The mapper surfaces missing agreements and unencrypted transports the moment a connection is drawn.
Practice
Solo dental practice · 1 location
Entities mapped
6
Findings
3 unsecured flows detected
Data flow
Patient Portal
|
v (HTTPS · encrypted)
EHR ----------------> Cloud Storage
| |
| v (SFTP · no BAA)
| Billing Vendor
v
Practice ManagementEntities & risk
Three flows fail the Security Rule's business-associate requirement at 45 CFR §164.308(b)(1) — Cloud Storage, Billing Vendor, and Transcription Service are actively receiving ePHI without an executed BAA.
Sample data. Your live map populates as you drag entities onto the canvas below.
This mapper is designed for desktop environments.
You can still explore below, but drag-and-drop works best on a larger screen.
Loading data flow mapper…
Every unmonitored flow you just mapped is a violation waiting to happen.
How it works
Five minutes to a complete PHI flow diagram.
Add entities
Click any entity type in the sidebar — EHR, cloud storage, telehealth, billing vendors, or create your own.
Draw connections
Activate the Connect tool and drag from one node’s dot to another. Each connection represents a PHI data flow.
Review risk scores
Risk badges appear on every connection. Click one to set transport method, PHI data types, and see the detailed risk breakdown.
Export your map
Download as SVG for compliance documentation or JSON to reload later. Your work autosaves to the browser.
Why map data flows
HIPAA requires you to know where patient data goes. Most practices cannot answer that question.
The HIPAA Security Rule (45 CFR 164.312) requires covered entities to implement technical safeguards for all electronic protected health information. You cannot safeguard what you have not mapped. Vendors that create, receive, maintain, or transmit PHI on your behalf in a business-associate capacity generally require a signed BAA — an unsigned relationship in that category creates exposure. Unencrypted email carrying patient records may create an impermissible use or disclosure and may trigger breach analysis; the specific facts and configuration decide.
The ePHI Data Flow Mapper gives independent practices the same visibility that hospital systems pay five figures to maintain. Add your EHR, your cloud storage, your billing service, your telehealth platform — and see exactly which connections are secured and which are exposed.
Add a Patient Protect node to see how risk scores drop when PHI flows through a compliant security layer. This is not a sales trick — it is a direct illustration of what active breach prevention does to your compliance standing.
Ready to fix the gaps — not just see them?
The mapper shows you where patient data is exposed. Patient Protect closes the gaps with continuous monitoring, automated BAA tracking, and active breach prevention.
Part of the HIPAA Foundation · 15+ free tools
See the full collectionMap exposure
You've mapped the flows. The platform enforces BAA scope against every vendor in the map and alerts when new unsecured flows appear.
Next in the sequence
Secure Infrastructure ChecklistTrace how patient information moves through employees, devices, vendors, and systems — then turn findings into sequenced work.
