One patient. Many systems. One healthcare provider's responsibility.
Follow one patient's information through appointment booking, registration, consultation, prescriptions, sample collection, laboratory processing, diagnostic images, billing, insurance, report delivery, referrals and long-term archives - and count every place it ends up, and where you lose control of it.
- 1
Appointment, enquiry & test booking control breaks
+4 places · 4 so farA patient calls, walks in, sends a WhatsApp message, books online, or is referred by a doctor, a hospital or an employer's health-check programme. Symptoms and test names are described before any patient record exists to hold them.
Where control breaks: Symptoms arrive on a personal phone before any record exists
Moving herePatient identity (new at this stage)Contact details (new at this stage)Family, caregiver & guardian details (new at this stage)Appointment & visit records (new at this stage)Clinical history & examination (new at this stage)Billing, payment & insurance (new at this stage)+1 moreDPDPAGive notice at the first point of contact, not at registration. Collect only what a booking needs - a clinical history is not required to reserve a slot - and keep enquiry channels inside systems you can search, restrict and delete from.
- 2
Registration, identity & consent control breaks
+3 places · 7 so farThe patient is registered and given an ID. Name, contact, age, address, an emergency or family contact and - very often by default - a full identity document copy are captured across a paper form, the software and a document folder at once.
Where control breaks: Identity is collected by default and matched by hand
Moving hereGovernment identity documents (new at this stage)Test orders & laboratory results (high-impact health data) (new at this stage)Patient identityContact detailsFamily, caregiver & guardian detailsAppointment & visit recordsDPDPAAsk for the minimum registration needs and stop retaining identity-document copies you cannot justify. Record who the patient authorises to receive their information as a separate, specific permission - not as a phone number in a contact field.
- 3
Consultation & clinical documentation
+4 places · 11 so farThe doctor takes a history, examines, records vitals and reaches a diagnosis. Notes are split across the clinical system, paper case sheets, the doctor's own laptop and, increasingly, an AI scribe that hears the whole consultation.
Moving hereDiagnosis & treatment (high-impact health data) (new at this stage)Prescriptions & medication (new at this stage)Clinical inferences & tool-generated findings· inferred (new at this stage)Patient identityAppointment & visit recordsClinical history & examination+1 moreDPDPAKeep clinical records in approved systems with role-based access, and approve any AI tool before it processes a consultation. Notes should be factual and clinical - and the patient must be able to have an inaccurate record corrected.
- 4
Prescriptions, test orders & referrals control breaks
+5 places · 16 so farA prescription is written, tests are ordered and the patient is referred onward - to an external lab, an imaging centre, a specialist or a pharmacy. Each of those carries a clinical reason out of the practice.
Where control breaks: A referral discloses far more history than the question needs
Moving herePhysical samples & requisitions (new at this stage)Patient identityContact detailsClinical history & examinationDiagnosis & treatment (high-impact health data)Prescriptions & medication+1 moreDPDPAShare the minimum the recipient needs to act: one test does not require a full history. Tell the patient where their information is being sent, and keep referrals inside recorded channels rather than forwarded chat messages.
- 5
Sample collection & imaging
+4 places · 20 so farA sample is drawn and labelled, or an image is taken. Physical specimens and image files are created that carry the patient's identity into places a database query will never reach.
Moving hereDiagnostic images & imaging reports (new at this stage)Patient identityDiagnosis & treatment (high-impact health data)Test orders & laboratory results (high-impact health data)Physical samples & requisitionsDPDPAA labelled sample and a stored image are personal data in a physical place. Label in the patient's presence, keep visible identifiers to the minimum, and define who may access imaging systems and for how long images are kept.
- 6
Home collection & field staff
+3 places · 23 so farA phlebotomist travels to the patient's home carrying their name, number, address, test list and often the clinical reason - on a field app, and frequently on a personal phone alongside a maps and route history.
Moving herePatient identityContact detailsAppointment & visit recordsClinical history & examinationTest orders & laboratory results (high-impact health data)Physical samples & requisitions+2 moreDPDPAA field worker is carrying patient data outside every system you control. Use managed devices, mask clinical detail where the visit does not need it, and remove patient contacts and route history when a collection closes or a staff member leaves.
- 7
Transport, chain of custody & accession
+2 places · 25 so farSamples move from a collection point to the main laboratory through transport boxes, manifests and couriers, and are logged in at an accession desk. Identity and specimen travel together, and can come apart.
Moving herePatient identityContact detailsTest orders & laboratory results (high-impact health data)Physical samples & requisitionsDPDPAUse accession numbers rather than full identity on manifests and transport paperwork wherever the process allows, keep an auditable chain of custody, and set out responsibilities in writing where a courier moves samples for you.
- 8
Laboratory processing, devices, outsourcing & AI
+4 places · 29 so farThe sample is run on analysers, results land in the laboratory system, and some tests are sent onward to a reference or specialist lab. Devices, middleware, technician worksheets and AI tools each keep their own copy.
Moving herePatient identityClinical history & examinationDiagnosis & treatment (high-impact health data)Test orders & laboratory results (high-impact health data)Diagnostic images & imaging reportsPhysical samples & requisitions+1 moreDPDPAInventory what your instruments and their middleware retain, use named rather than shared logins, control vendor remote access, and define exactly which identifiers travel with an outsourced test and what happens to the sample afterwards.
- 9
Validation, report generation & correction control breaks
+5 places · 34 so farA result becomes a report: validated, interpreted, signed, sometimes corrected and re-issued. Draft, final and amended versions of the same report can exist at once, and an AI suggestion can quietly become a conclusion.
Where control breaks: Draft, final and corrected reports all exist at once
Moving herePatient identityClinical history & examinationDiagnosis & treatment (high-impact health data)Prescriptions & medicationTest orders & laboratory results (high-impact health data)Diagnostic images & imaging reports+2 moreDPDPAKeep one authoritative version with an auditable amendment history, require a human to validate anything a tool suggested, and make sure a corrected report reaches everyone who received the wrong one.
- 10
Report delivery, family & third-party sharing control breaks
+3 places · 37 so farThe report goes out - to the patient, a spouse or parent, a referring doctor, a hospital, an employer who paid for a health check, or an insurer. Often over WhatsApp, an open link, or a printout collected at a counter.
Where control breaks: The report is sent without knowing who will receive it
Moving herePatient identityFamily, caregiver & guardian detailsClinical history & examinationDiagnosis & treatment (high-impact health data)Test orders & laboratory results (high-impact health data)Diagnostic images & imaging reports+1 moreDPDPAVerify who is receiving a report before it is sent, and treat a family member as a recipient the patient must specifically authorise. Use channels that can be limited and logged, and record every disclosure you make to an employer or insurer.
- 11
Billing, insurance & TPA control breaks
+4 places · 41 so farThe visit or test is invoiced, paid and often claimed. Diagnosis codes, procedure descriptions and supporting clinical evidence travel to finance staff, insurers, third-party administrators and pre-authorisation portals.
Where control breaks: Diagnosis reaches finance staff, insurers and employers
Moving herePatient identityContact detailsFamily, caregiver & guardian detailsDiagnosis & treatment (high-impact health data)Test orders & laboratory results (high-impact health data)Diagnostic images & imaging reports+1 moreDPDPAKeep clinical detail off an invoice unless it is genuinely needed, separate financial access from clinical access, send a claim the minimum it requires rather than the full record, and hold financial records under their own retention rule.
- 12
Follow-up, chronic care & engagement
+2 places · 43 so farThe relationship continues: reminders, adherence checks, chronic-care programmes and wellness campaigns - increasingly segmented by the condition the patient was treated for.
Moving hereChronic-care & adherence profile· inferred (new at this stage)Health-based marketing segments· inferred (new at this stage)Patient identityContact detailsDiagnosis & treatment (high-impact health data)Clinical inferences & tool-generated findings· inferredDPDPAKeep care communication separate from marketing, use wording that does not disclose a condition to whoever picks up the phone, and let a patient step out of health-based segmentation without losing their clinical reminders.
- 13
Complaints, corrections & incidents control breaks
+2 places · 45 so farA patient disputes a result, asks for a correction, or a report reaches the wrong person. The request usually arrives in the channel it was raised in and stays there.
Where control breaks: Corrections and wrong-recipient incidents stay in the chat
Moving herePatient identityDiagnosis & treatment (high-impact health data)Test orders & laboratory results (high-impact health data)Messages, calls & report copiesDPDPARun a formal register for access, correction and grievance requests, link every correction back to the master record with its history preserved, and treat a wrong-recipient disclosure as an incident with a recorded response.
- 14
Archive, retention, sample disposal & deletion control breaks
+3 places · 48 so farLong after the episode of care, the patient still exists in the clinical system, the laboratory system, imaging archives, analyser memory, email, WhatsApp, doctor devices, the reference lab, backups, paper racks and stored specimens.
Where control breaks: Deleting the record reaches almost none of the copies
Moving herePatient identityGovernment identity documentsClinical history & examinationDiagnosis & treatment (high-impact health data)Test orders & laboratory results (high-impact health data)Diagnostic images & imaging reports+2 moreDPDPAWrite retention rules per record type, separate what you are required to keep from what is merely never deleted, and build an erasure path that reaches devices, vendors, communication channels, backups and physical samples - or record honestly why it cannot.
Top risk hotspots - where control usually breaks
The 8 places patient data most often slips out of your control. Each links to the matching check in the readiness assessment.
- Hotspot 1 Critical risk
The result goes out to whatever number is on the record - a WhatsApp message, an unauthenticated download link by SMS, an email attachment, or a printout handed to whoever comes to the counter. The number frequently belongs to a spouse or parent, the handset is often shared, and the link can be forwarded by anyone who has it.
Why this matters
This is the sector's signature exposure: the practice's most sensitive artefact leaves the building at exactly the moment nobody checks identity. A pregnancy, an HIV status, a mental-health referral or a cancer finding can reach a family member the patient had not told - and unlike almost every other mistake on this map, a wrong send cannot be recalled.
Fix: Verify the recipient against the record before anything is sent, make the authenticated portal the default channel, use expiring links where a link is unavoidable, require identity at counter collection, and log every delivery so a wrong send can be traced and contained.
Check this in the assessment - Hotspot 2 Critical risk
Patients describe their condition, photograph old prescriptions and forward previous reports to the number the practice advertises - which is very often a staff member's own handset rather than a business account. Relatives message on the patient's behalf, and that number quietly becomes the one results are later sent to.
Why this matters
Health information is disclosed before there is any patient record to govern it, into a channel with no access control, no retention rule and no export. When a patient asks what you hold about them, this channel cannot be searched; when the staff member leaves, the entire history walks out with the phone.
Fix: Move enquiries onto an official business number that routes into the practice system, forbid patient conversations on personal handsets, give notice at first contact, set a deletion rule for media, and record separately who the patient authorises to receive information.
Check this in the assessment - Hotspot 3 Critical risk
A full Aadhaar or insurance card is photocopied at registration because it has always been asked for, and the patient is matched to an existing record by eye across a paper form, a scan and a screen. Similar names, a shared family mobile number or a mistyped date of birth create a second profile for the same person.
Why this matters
Two harms compound here. Identity documents nobody could justify collecting are retained indefinitely - and duplicate or wrongly merged records are precisely the condition in which one patient's result gets attached to another patient's name, which is a clinical safety failure as much as a privacy one.
Fix: Define the minimum registration set and stop retaining identity-document copies you cannot justify, confirm against more than one identifier before matching, run duplicate detection, restrict who can merge records, and audit every merge.
Check this in the assessment - Hotspot 4 Critical risk
A preliminary result is released, a validated version replaces it, and sometimes an amended version replaces that - but each was a separate file that had already been sent to a patient, a referring doctor or an insurer before the next one existed. Alongside this, an AI-suggested finding passes into the report without a documented human check.
Why this matters
Someone is acting on a superseded result: a treating doctor prescribing against a value that has since been corrected, or a patient told something that is no longer true. And a tool-generated interpretation that nobody separately verified becomes, in the record, indistinguishable from a clinical conclusion.
Fix: Keep one authoritative version with a visible amendment history, require documented human validation before release, and make issuing a correction automatically notify every recipient the earlier version reached.
Check this in the assessment - Hotspot 5 Critical risk
One test request goes out with the full case history, prior reports and the working diagnosis attached - typically as a WhatsApp message or an email to a lab, an imaging centre or a specialist, with no record kept of what was sent or to whom.
Why this matters
The recipient is a separate organisation that now holds a complete clinical picture it never needed, keeps it permanently, and is under no written obligation about what happens to it next. The patient is almost never told the disclosure took place, so they cannot object to it or trace it later.
Fix: Send only the clinical indication the recipient needs to act on, use a recorded channel rather than a forwarded chat, tell the patient where their information is going, keep a register of referral destinations, and put confidentiality and retention terms in writing with regular partners.
Check this in the assessment - Hotspot 6 Critical risk
Claims and pre-authorisations are filed with diagnosis codes and full supporting reports uploaded as evidence. Invoices print the procedure or test name. Corporate health-check results go back to the employer that paid for them, and rejected claim files sit in the portal indefinitely.
Why this matters
The patient's condition travels well beyond the people treating them - to billing staff who only needed an amount, to insurers and administrators the practice cannot audit or delete from, and to an employer who has no clinical relationship with their employee at all. Paying for a test is not the same as being entitled to the result.
Fix: Upload the minimum a claim requires rather than the whole report, separate financial access from clinical access, keep clinical detail off invoices where it is not needed, agree in writing exactly which summary an employer receives, tell patients before you disclose, and log every disclosure.
Check this in the assessment - Hotspot 7 High risk
A patient asks to see their records, disputes a result or reports that their report went to the wrong person. The request arrives on WhatsApp or at the desk, someone deals with it verbally, and the master record is never amended - nor are the people who already received the wrong version.
Why this matters
A correction that is agreed but not made leaves the wrong information in circulation and in every copy already sent. And because nothing was logged, the practice cannot show what it was asked, what it did, or how quickly - which is the record that matters most when a patient escalates.
Fix: Run one register for every access, correction, erasure and grievance request with an owner and a closure date, link each correction back to the master record with its history preserved, notify everyone who received the superseded version, and treat a wrong-recipient disclosure as an incident with a recorded response.
Check this in the assessment - Hotspot 8 Critical risk
Removing a patient from the clinical or laboratory system leaves them intact in nightly backups, years of email, the WhatsApp history, the doctor's laptop, the shared drive, the imaging archive, analyser memory, the reference lab, the insurer's file, the paper racks and the specimen still in the freezer.
Why this matters
This is the question the whole map exists to answer. If a patient asked you tomorrow to find every copy of their data, the honest answer for most practices is that they do not know where the copies are - and of the ones they can name, most they cannot reach.
Fix: List every place patient data lands, write a retention rule per record type, separate what you are genuinely required to keep from what is merely never deleted, build an erasure path that reaches devices, vendors, chats, backups and physical samples - and record honestly where it cannot reach and why.
Check this in the assessment
How to read this journey
Pick your model
Switch between Integrated clinic + diagnostics, Standalone clinic and Diagnostic laboratory to see the journey each kind of practice actually runs. This is not a filter over one journey - a standalone clinic has no analysers and refers testing out, a laboratory has no consultation but adds collection, transport and instruments, and the integrated model runs both. The stage count and the place-counter recalculate for the model you choose.
When it leaves you
A violet left edge and a tag mark everything outside your practice - referring doctors, hospitals, external labs and imaging centres, reference laboratories, insurers and TPAs, employers who paid for a health check, device and AI vendors, couriers, and the family member who receives the report. Once data lands there your control is indirect: it runs through your contract and instructions, not your admin panel. Risk is shown separately, as an amber or red fill - so an outside system can be low risk, and a phone at your own reception desk can be the worst thing on the page.
Where control breaks
Red flags mark the hotspots - the eight places clinics and labs most often lose control of patient data, from symptoms arriving on a personal phone before any record exists, to a report sent to a number nobody verified, to a specimen still sitting in a freezer under someone's name. Tap any system to see what it holds and how to fix it.
Now check whether your controls hold up
The map shows where patient data travels in a typical clinic or diagnostic lab. The 3-minute readiness scan checks whether your practice has the controls that matter at each hotspot - and the Discovery tool builds your own data inventory.
Educational reference model - not legal advice, and not a scan of your actual systems.