Skip to main content
Patient Protect circular logo mark in purple and white used for site navigationPatient Protect

Free tool

Map how patient data moves through your practice.

Drag entities onto the canvas, draw connections between them, and the mapper automatically scores each data flow for HIPAA compliance risk. Missing BAAs, unencrypted transports, and non-compliant vendors surface instantly.

Free·No login required·Data stays in your browser·Export SVG & JSON

16

Entity types

Patient, EHR, Cloud, Telehealth, Vendors, and more

5

Risk levels

Minimal → Severe, auto-calculated per connection

4

Templates

Basic PHI, Telehealth, Cloud Migration, Full Practice

11

Transport methods

Encrypted API, VPN, SFTP, fax, USB, and more

Sample map

A completed flow for a solo dental practice.

Six operational entities, each with an auto-calculated risk score and BAA status. The mapper surfaces missing agreements and unencrypted transports the moment a connection is drawn.

Sample flow map

Practice

Solo dental practice · 1 location

Entities mapped

6

Findings

3 unsecured flows detected

Data flow

  Patient Portal
        |
        v   (HTTPS · encrypted)
      EHR  ---------------->  Cloud Storage
        |                          |
        |                          v   (SFTP · no BAA)
        |                     Billing Vendor
        v
  Practice Management

Entities & risk

Patient Portal2 / 5N/APatient-facing. TLS 1.3, session-scoped tokens.
EHR2 / 5On filePrimary system of record. Vendor BAA current, MFA enforced.
Cloud Storage4 / 5MISSINGBackup destination for imaging exports. No BAA under §164.308(b)(1).
Billing Vendor5 / 5MISSINGReceives claim files via SFTP. No BAA, no encryption verification.
Practice Management3 / 5On fileScheduling and intake. Local install, backups unverified.
Transcription Service4 / 5MISSINGReceives dictation audio via email. No BAA under §164.308(b)(1).

Three flows fail the Security Rule's business-associate requirement at 45 CFR §164.308(b)(1) — Cloud Storage, Billing Vendor, and Transcription Service are actively receiving ePHI without an executed BAA.

Sample data. Your live map populates as you drag entities onto the canvas below.

This mapper is designed for desktop environments.

You can still explore below, but drag-and-drop works best on a larger screen.

Loading data flow mapper…

Every unmonitored flow you just mapped is a violation waiting to happen.

How it works

Five minutes to a complete PHI flow diagram.

01

Add entities

Click any entity type in the sidebar — EHR, cloud storage, telehealth, billing vendors, or create your own.

02

Draw connections

Activate the Connect tool and drag from one node’s dot to another. Each connection represents a PHI data flow.

03

Review risk scores

Risk badges appear on every connection. Click one to set transport method, PHI data types, and see the detailed risk breakdown.

04

Export your map

Download as SVG for compliance documentation or JSON to reload later. Your work autosaves to the browser.

Why map data flows

HIPAA requires you to know where patient data goes. Most practices cannot answer that question.

The HIPAA Security Rule (45 CFR 164.312) requires covered entities to implement technical safeguards for all electronic protected health information. You cannot safeguard what you have not mapped. Vendors that create, receive, maintain, or transmit PHI on your behalf in a business-associate capacity generally require a signed BAA — an unsigned relationship in that category creates exposure. Unencrypted email carrying patient records may create an impermissible use or disclosure and may trigger breach analysis; the specific facts and configuration decide.

The ePHI Data Flow Mapper gives independent practices the same visibility that hospital systems pay five figures to maintain. Add your EHR, your cloud storage, your billing service, your telehealth platform — and see exactly which connections are secured and which are exposed.

Add a Patient Protect node to see how risk scores drop when PHI flows through a compliant security layer. This is not a sales trick — it is a direct illustration of what active breach prevention does to your compliance standing.

Ready to fix the gaps — not just see them?

The mapper shows you where patient data is exposed. Patient Protect closes the gaps with continuous monitoring, automated BAA tracking, and active breach prevention.

Part of the HIPAA Foundation · 15+ free tools

See the full collection
Map exposureFree · proprietary

Map exposure

You've mapped the flows. The platform enforces BAA scope against every vendor in the map and alerts when new unsecured flows appear.

Next in the sequence

Secure Infrastructure Checklist

Trace how patient information moves through employees, devices, vendors, and systems — then turn findings into sequenced work.