Go back

The HIPAA gaps hiding in ordinary video workflows

Most HIPAA violations involving video content aren’t the result of anyone deliberately mishandling patient information. They’re the result of an ordinary production workflow, a screen recording, a training walkthrough, a quick demo clip, that picked up real protected health information along the way without anyone specifically noticing or flagging it.

Why these gaps are so easy to miss

A team producing training content is usually focused on whether the content is clear, accurate, and useful, not on scanning every frame for identifiers that might constitute PHI. This focus is entirely reasonable, it’s the point of the content, but it means HIPAA exposure tends to slip in through the parts of the workflow nobody is specifically watching: a screen recording capturing more of a real system than intended, a document used as source material that wasn’t fully reviewed for patient references, a live demo recorded in the moment without a script that had already been checked.

Gap one: screen recordings of real systems

A common source of accidental PHI exposure is a screen recording meant to demonstrate a process, how to navigate a scheduling system, how to complete a specific workflow step, that’s captured against a live, real environment rather than a sanitized test environment. Even if the presenter never mentions a patient by name, the recording itself can capture real names, dates, or other identifying details visible on screen, sometimes in a sidebar, a notification, or a background window nobody was paying attention to during recording.

Gap two: source documents that weren’t fully reviewed

Video content built from source material, a policy document, a case study, a process guide, inherits whatever’s in that source material. If the document was written for internal use and wasn’t specifically reviewed for PHI before being used as source material for a video, any real patient references it contains carry through into the generated content without a deliberate decision being made about it.

Gap three: live or unscripted recordings

Scripted content gets reviewed before recording, which creates a natural checkpoint for catching PHI before it’s captured. Live or unscripted recordings, an off-the-cuff walkthrough, a recorded meeting, a spontaneous demo, skip that checkpoint entirely, and PHI that comes up in the moment, someone referencing a real patient case conversationally, gets captured and preserved without the same deliberate review a scripted piece would go through.

Gap four: translated or derived versions that outlive the original’s review

Even when an original video is carefully reviewed for PHI, its translated versions, exports, or shared clips can drift from that reviewed state if edits happen after the fact without extending the same review to every derived version. A correction made to remove PHI from the primary version doesn’t automatically propagate to a translated version or an export that was already generated and distributed.

Gap five: assuming internal-only content is exempt

It’s a common misconception that HIPAA’s requirements are relaxed for content that stays entirely internal, never shared with anyone outside the organization. HIPAA’s requirements around PHI apply regardless of the content’s internal or external distribution, and treating internal training content as automatically lower-risk is a mistake that can leave a genuine gap unaddressed simply because nobody thought it needed the same scrutiny as customer-facing material.

A realistic example of how gap one plays out

Consider an IT team producing a short training video showing new hires how to navigate an internal scheduling tool. To make the walkthrough feel authentic, the presenter records their screen while using the live production system rather than setting up a sanitized test environment first, since spinning up a clean test instance felt like unnecessary extra work for what seemed like a routine training video. The recording captures the presenter clicking through several real patient appointments in the background as they demonstrate the navigation steps, each one briefly visible with a real name and appointment type. Nobody involved in producing or reviewing the video thought of it as containing PHI, since the focus was entirely on whether the navigation steps were clear, and the video gets published to the internal training library, complete with the visible patient details, without anyone specifically checking for exactly this kind of exposure before it went out.

How these gaps typically get caught, if they get caught at all

In organizations without a specific review step built into the video production workflow, these gaps often go uncaught entirely, simply because nobody was looking for them. Where they do get caught, it’s usually either through a deliberate compliance review before publishing, the ideal case, or after the fact, when someone notices real patient information in already-published content, a considerably worse position to discover the problem from.

Why a test environment is worth the extra setup time

The single most effective structural fix for gap one specifically is establishing a standing, sanitized test environment, populated with fake or clearly fictional data, that’s used by default for any screen recording meant for training or demonstration purposes. This removes the underlying risk entirely rather than relying on careful attention during recording or review afterward, since a test environment simply cannot expose real PHI no matter what gets captured on screen. The upfront setup cost is real, but it’s considerably smaller than the cost of discovering, and having to remediate, real PHI already published across a training library.

Building a review step into the workflow itself

The most reliable fix isn’t asking content creators to be more careful in general, it’s adding a specific, named review step, checking explicitly for PHI, before any healthcare-related video gets finalized and published. This review should cover the full range of gaps above: the source material, the recording itself, any translated or derived versions, and confirmation that the content was built from a sanitized or hypothetical scenario if real PHI genuinely isn’t needed.

Where Velo fits into this picture

Velo currently maintains SOC 2 and ISO 27001 compliance along with a GDPR-aligned Data Protection Addendum, but does not currently offer a Business Associate Agreement or HIPAA-specific certification. This makes the review discipline described above especially important for any healthcare organization using Velo, or any similarly positioned platform, for training and internal content: the safest default is keeping real PHI out of the workflow entirely, building content from de-identified or hypothetical scenarios instead, rather than relying on a platform-level compliance program that doesn’t currently extend to HIPAA.

Look for these gaps before they become a real incident

Every gap described here is catchable with a deliberate review step, and considerably harder to fix once content has already been published or shared. Build PHI review into your video workflow the same way you’d build any other compliance check into content production, as a required step, not an optional afterthought.

Try Velo for free · See how it works


About the author

Ritu Parakh is Growth Lead at Velo, the AI video messaging platform that turns a screen recording, a deck, or a URL into a polished, narrated video - and an editable written doc. She writes about video for demos, onboarding, training, and enablement. Connect on LinkedIn

Velo's current compliance program covers SOC 2, ISO 27001, and GDPR-aligned data handling, but does not currently include a Business Associate Agreement or HIPAA-specific certification. IT teams should confirm this directly before allowing real PHI into any video workflow, and default to de-identified or hypothetical content instead.

A screen recording of an actual clinical or administrative system, captured to demonstrate a process, that happens to show real patient names or details in the background, without the person recording it thinking of it as PHI.

Yes, if the workflow never introduces real, identifiable patient information into the content, sticking to de-identified or hypothetical scenarios instead.

A designated compliance or privacy reviewer, not just the individual content creator, since gaps are most reliably caught by someone specifically looking for them rather than someone focused on production quality.

Bring the video layer to your product team