Is Epic's Patient Portal HIPAA Compliant for Session Replays with PHI?
Session Replay Risks in Healthcare
Session replay records how a user interacts with a portal—clicks, scrolls, page views, form inputs, and sometimes network requests or on-screen content. In a healthcare setting, those signals can expose Protected Health Information (PHI) such as test results, medication lists, and messages to clinicians.
The chief risks are PHI over-collection and unauthorized disclosure. Full-screen captures, keystroke logging, and unfiltered query strings can reveal identifiers and clinical details to parties outside your compliance boundary. Replay archives also become a new ePHI repository that must be protected, monitored, and governed.
Operational concerns include re-identification through device fingerprints, inadvertent sharing with analytics providers lacking a Business Associate Agreement (BAA), and expanded breach blast radius if replay stores tokens or cookies. Without rigorous controls, session replay can violate the HIPAA Privacy and Security Rules.
HIPAA Compliance Criteria for Session Replay
HIPAA does not ban session replay; it requires you to safeguard any captured PHI and limit its use to permissible purposes. Treat replay data as ePHI and apply the Privacy Rule’s minimum necessary standard alongside the Security Rule’s administrative, physical, and technical safeguards.
Administrative safeguards
- Perform a documented risk analysis focused on replay capture, storage, access, and data flows.
- Execute a BAA with the replay vendor and any subcontractors; define permitted uses, retention, and destruction.
- Train workforce members on proper use; restrict who may view replays and enforce sanctions for misuse.
- Establish incident response and breach notification procedures specific to replay archives.
Technical safeguards
- Encrypt data in transit and at rest; manage keys separately from stored recordings.
- Enforce Role-Based Access Control and Multifactor Authentication for anyone who can view or export replays.
- Maintain comprehensive audit controls, including Patient Portal Audit Logs correlated with replay viewer activity.
- Apply Data Masking Techniques, field-level redaction, and default-deny collection to exclude PHI by design.
- Limit retention to the minimum necessary window and disable capture on PHI-dense screens (e.g., results, messages).
Physical and operational safeguards
- Host within approved regions and secure environments; segregate replay storage from public networks.
- Use change control to vet any client-side script that could collect PHI.
- Continuously monitor access, generate alerts for anomalous downloads, and test masking before each release.
Epic MyChart Security Features
Epic’s patient portal (MyChart) provides enterprise security capabilities your organization can configure to support a compliant posture. Core controls typically include encryption, Role-Based Access Control for staff, and optional Multifactor Authentication for end users and administrators.
You also have extensive auditing options. Patient Portal Audit Logs can document sign-ins, feature use, and sensitive actions. When combined with replay tooling, you should record who viewed or exported a session and why, then reconcile those events with your portal’s audit trails.
Your team governs what third-party scripts are allowed in the portal experience. Load only vetted code within your BAA boundary, restrict network egress to approved domains, and apply a strict Content Security Policy at the web gateway to prevent unauthorized data exfiltration.
User Consent and Authorization Processes
For many organizations, limited session replay used for troubleshooting or quality improvement may fall under HIPAA operations. Even so, provide clear notice, allow opt-out where feasible, and document the purpose, scope, and retention of recordings.
When uses extend beyond treatment, payment, or operations—such as marketing or non-operational analytics—you should obtain a HIPAA Authorization. The authorization must describe what PHI is captured, who receives it (including any vendor under a BAA), and how long it will be retained.
Capture consent decisions in your Patient Portal Audit Logs, and display just-in-time prompts on pages where additional collection could occur. Make opting out frictionless and honor preferences consistently across web and mobile.
Ready to simplify HIPAA compliance?
Join thousands of organizations that trust Accountable to manage their compliance needs.
Business Associate Agreements for Vendors
Never deploy a session replay tool in healthcare without a signed Business Associate Agreement (BAA). The BAA should narrowly define allowed uses, prohibit secondary use or sale, and require subcontractors to meet the same standards.
- Security: encryption, Role-Based Access Control, Multifactor Authentication, and granular audit logs.
- Governance: retention limits, data localization if required, and validated destruction upon termination.
- Compliance: timely breach notification, right to audit, and obligations for vulnerability management.
- Data rights: no targeted advertising, tracking, or profiling beyond the minimum necessary operational scope.
Data Masking and PHI Exclusion Practices
Adopt a privacy-by-default capture model. Begin with a deny-all configuration, then allow only whitelisted UI elements or events. Do not record keystrokes for free-text fields, search boxes, messages, or identifiers; store high-level events instead of raw content.
- Field-level masking: tag inputs containing names, MRNs, insurance IDs, addresses, or credit card data to block capture.
- Network scrubbing: remove tokens, authorization headers, query strings, and payload fields that may carry PHI.
- Viewport controls: blur or block specific components (e.g., lab results, problem lists) and pause capture on sensitive routes.
- Upload and media handling: disable recording for file uploads, images, and attachments that could embed PHI.
- Testing: add automated privacy tests to your CI/CD pipeline to fail builds if new elements are not masked.
Epic's Data Sharing and Privacy Controls
Use Epic’s administrative settings and governance processes to keep data sharing intentional and auditable. Limit integrations to vendors under a BAA, document data flows, and apply least-privilege access for staff who troubleshoot patient issues with replay.
Enable short session timeouts, device sign-out options, and strong authentication policies to reduce exposure. Centralize logs: forward Patient Portal Audit Logs and replay viewer activity to your SIEM, alert on large exports, and review access regularly.
Establish retention aligned to medical operations and purge schedules. Where possible, store replay data in your controlled environment and restrict cross-border transfers. These controls, combined with strict masking, make session replay operationally useful while protecting PHI.
Conclusion
Epic’s patient portal can be part of a HIPAA-compliant session replay strategy when you confine collection to the minimum necessary, operate under a robust BAA, enforce MFA and RBAC, maintain thorough audit logs, and apply strong Data Masking Techniques. Without those safeguards, replay creates unacceptable PHI risk.
FAQs
Does Epic MyChart use session replay technology?
MyChart itself is not a session replay platform. Whether session replay is present depends on your organization’s configuration and any third-party tools you choose to integrate under a BAA.
How does Epic handle PHI during session replays?
Epic does not natively record replays of user sessions. If you add a replay tool, you are responsible for treating any captured data as PHI, enforcing masking and minimization, and storing it within your HIPAA compliance boundary.
What HIPAA safeguards must session replay tools have?
At minimum: a signed Business Associate Agreement (BAA), encryption in transit and at rest, Role-Based Access Control, Multifactor Authentication for replay viewers, comprehensive audit logging, strict Data Masking Techniques, minimal retention, and documented incident response.
Is user consent required for session replay in healthcare portals?
If replay is used strictly for treatment, payment, or operations, you may rely on HIPAA operations with clear notice and opt-out where feasible. For uses beyond TPO—such as marketing or unrelated analytics—you should obtain a HIPAA Authorization before collecting PHI.
Ready to simplify HIPAA compliance?
Join thousands of organizations that trust Accountable to manage their compliance needs.