- › A federal product-safety agency is demanding that major health systems hand over detailed, personally identifiable emergency-room records for every patient.
- › Data outlives the reason it was collected. Records gathered to treat a patient become a resource that a regulator, a litigant, or an attacker can later reach for.
- › You cannot be compelled to produce, subpoenaed for, or breached out of data you never kept. Minimization is the one control that removes the exposure instead of guarding it.
- › Treat every dataset as a standing liability: know what you hold, why you still hold it, and what would happen if someone you did not anticipate demanded or stole it.
- › Collect less, retain on a clock, de-identify early, and map your data to its purpose, so the record that leaves your control is the smallest one that still does the job.
There is a story this week that sounds like a bureaucratic footnote and is actually a clear lesson about data. A small federal agency, the one whose job is protecting people from dangerous lawn mowers and faulty coffeemakers, is demanding that some of the largest health systems in the country turn over detailed, personally identifiable medical records for every emergency-room patient they see. Not aggregate injury counts. Not de-identified statistics. Named, identifiable records of who came into the ER and why.
Set aside for a moment whether that demand is lawful or wise, because that fight will play out in courts and comment periods. The part worth every operator’s attention is simpler and applies far beyond hospitals. Those records were created for one reason, to treat a patient in front of a clinician, and years later they are wanted for an entirely different one. The data outlived its purpose, and now someone the hospital never anticipated is reaching for it.
Data Does Not Stay in the Box You Collected It For
Every organization tells itself a story about why it holds the data it holds. We keep customer addresses to ship orders. We keep call recordings to train support. We keep the ER intake because a patient needed care. The story is always about the original purpose, and the story is always incomplete, because data does not stay inside the reason you gathered it.
Once a record exists, it becomes available to purposes you did not plan for. A regulator can demand it. A litigant can subpoena it in a lawsuit that has nothing to do with why you collected it. A new executive can decide to monetize it. A government agency can requisition it for a mission unrelated to the one that generated it. And an attacker can steal it and use it in ways no one in your building ever imagined. The record you created to do one small, legitimate job sits in your systems as a standing resource that other people, with other motives, can draw on.
This is the quiet truth underneath the hospital story. The health system did nothing wrong by treating patients and keeping records of it. That is the job. The exposure came into being the moment those records existed and persisted, because a persistent, identifiable dataset is a thing the world can come and ask for. Purpose limitation, the principle that data should be used only for the reason it was collected, is a fine legal ideal, and it is not self-enforcing. The data itself does not know what it was for.
The Only Record No One Can Take Is the One You Never Kept
Here is the shift in thinking that turns this from a privacy lecture into a security control. In security we spend most of our effort guarding things: access controls, encryption, monitoring, all of it aimed at protecting data we hold. Those controls are necessary and they all share one weakness, which is that they protect data that still exists and can therefore still be reached, whether by a court order your legal team cannot refuse or by an attacker who gets past the guard.
There is one move that removes the exposure instead of guarding it. You cannot be compelled to produce a record you never created. You cannot be subpoenaed for a field you did not retain. You cannot suffer a breach of data that is not in your systems. Data minimization, the discipline of collecting less and keeping it for less time, is the one control that takes the exposure off the board. Every other safeguard reduces the odds that someone reaches the data. Minimization changes whether the data is there to reach at all.
I want to be careful, because minimization is easy to say and genuinely hard to do. Businesses collect data because data is useful, and the instinct to keep everything “just in case” is strong and often rewarded. The point is not to collect nothing. The point is to make the amount and lifespan of what you hold a deliberate decision tied to a purpose, so that your systems are not quietly accumulating a decade of identifiable records that no longer serve any function except to be demanded or stolen.
Treat Every Dataset as a Standing Liability
The practical reframe is to stop thinking of your data purely as an asset and start also accounting for it as a liability, because it is both. An asset earns its keep. A liability is a cost you carry until you retire it. Most organizations track the asset side carefully and the liability side not at all, which is how you end up holding sensitive records whose only remaining property is risk.
Know what you hold and why you still hold it. You cannot minimize what you have not mapped. The uncomfortable first step is an honest inventory of the personal and sensitive data across your systems, and for each category, a plain answer to why it is still there. A field that no current process uses is not a convenience you are keeping. It is a liability you have not yet noticed. This is the same visibility discipline that underpins any real understanding of exposure, the data equivalent of the asset discovery in our work on the self-sovereign identity trade-offs: you cannot govern what you cannot see.
Put every category of data on a retention clock. The default state of most data is to persist forever, because deleting things takes effort and keeping them takes none. Flip that. Give each category of data a retention period tied to its purpose, and enforce deletion when the clock runs out. The record you disposed of on schedule is a record that was not in your systems when the demand or the breach arrived.
De-identify as early as the purpose allows. A great deal of data is collected identifiable when it does not need to stay that way. If you keep ER visits to study injury patterns, the study rarely needs the patient’s name attached forever. Stripping identity early, and doing it properly given how much modern re-identification can reverse, means that even when the dataset is demanded or taken, what leaves is far less damaging. The regulators drafting stricter tests for when data counts as truly anonymous are circling the same point: de-identification is a spectrum, and where you sit on it decides your exposure.
Assume the demand will come from a direction you did not plan for. The hospitals in this story surely modeled HIPAA, breaches, and malpractice discovery. I doubt many modeled a product-safety agency requisitioning their entire ER intake. The lesson is not to predict the specific demand. It is to hold your data as though some unanticipated party will eventually want it, because on a long enough timeline one of them does. Data collected for the narrowest purpose and kept for the shortest time is the data that survives that surprise best.
Why This Is a Converged Security Problem
I write about converged security because the old walls between physical, digital, and privacy risk do not describe how organizations actually get hurt, and this is a clean example. A demand for ER records is a legal event, a privacy event, and a data-security event at once, and it lands on data governance, which most companies file under compliance and never treat as the security control it is.
The organizations that handle this well have stopped drawing a hard line between “keeping data safe” and “keeping less data.” They understand that the size and age of their data holdings is itself an attack surface, one that grows silently with every record retained past its usefulness. Shrinking it is the same instinct that drives good external attack surface management, pointed inward: the exposure you remove is worth more than the exposure you defend, because it cannot come back on a bad day.
None of this is an argument against collecting data or against the genuine good that comes from studying it, including the injury data at the center of this very story. It is an argument for holding data the way you would hold anything else that carries both value and risk: deliberately, with a purpose, and with a plan to let it go when the purpose is served.
The Record You Never Kept
The hospitals will fight this demand, and however it resolves, the lesson underneath it does not depend on the outcome. Data outlives its reason. The record you create today to do one small job will still be sitting in your systems years from now, and the world will have changed, and someone with a motive you cannot foresee may come asking for it or come taking it.
You cannot control who asks. You can control what is there to be asked for. The most durable protection for a piece of sensitive data is not a stronger lock on the vault. It is the decision, made deliberately and enforced on a schedule, that the data does not need to be in the vault at all.
If you want to understand what sensitive data your organization is holding, why, and what your exposure would be if someone demanded or stole it, that is the work we do. Start with our free Human Attack Surface Score, or contact Grab The Axe and we will map the data you are carrying and the liability that comes with it.
A PhD candidate in Health Psychology and former Corrections Officer, Jeff founded GTA to dismantle passive security models. He focuses on the 'Human Zero-Day', mitigating executive burnout and decision fatigue before they become security breaches.
View Author Page →