Industry

Time tracking for healthcare teams: HIPAA, blur, and what to check.

August 2026 · The TimeNova team

Medical billing companies, telehealth support desks, revenue cycle teams, and healthcare BPOs all have the same problem: the work happens inside systems full of patient data, and the business still needs to know how the work is going. A time tracker that captures screens can help with the second part while quietly wrecking the first, because every readable screenshot of an EHR is protected health information sitting in a new place. Here is how to think about monitoring in a healthcare setting, and what to test before trusting any vendor with it.

A screenshot of PHI is PHI

HIPAA does not care that the image was taken for productivity reasons. If a captured frame shows a patient name next to a diagnosis code, that frame is PHI, and everywhere it travels, the vendor's servers, a manager's browser, an export folder, is now part of your compliance surface. The mistake teams make is evaluating the tracker as an HR tool and never asking the storage question. Ask it first: what exactly leaves the workstation, where does it live, and who can see it?

Blur has to happen before upload, or it is theatre

Most monitoring tools offer some form of screenshot blurring. The question that separates them is where the blur runs. If frames are uploaded readable and blurred on the vendor's server, the readable version existed outside your control, was transmitted, and may be logged, cached, or retained; a breach at the vendor is a breach of patient data. Blur applied on the employee's machine, before anything is uploaded, means a readable frame of the EHR never leaves the building. Push vendors on the failure case too: if the blur step fails, is the frame uploaded raw, or not uploaded at all? Only the second answer is safe. This is how TimeNova does it: blur is a hard gate on the device, and a frame that cannot be blurred is not sent.

Minimum necessary applies to monitoring

The minimum necessary principle is usually discussed about chart access, but it applies just as well here: collect the least detail that answers the management question. Hours, attendance, and app-level usage answer most questions without capturing screen contents at all. If you need screens, blurred frames still show whether the day looks like work while keeping text unreadable. Detail settings matter too: a tracker that stores full URLs can be storing patient identifiers that appear in query strings, so make sure URL parameters are stripped before they are stored, or keep browser detail at the domain level. The right configuration is the least you can get away with, tightened per team.

The BAA question sorts vendors quickly

If captured material can contain PHI, your vendor is handling PHI on your behalf, which is what a business associate agreement exists for. Asking a monitoring vendor whether they will sign a BAA is a fast filter: some will, some go quiet, and the ones who say you do not need one because it is only screenshots have answered a different and more worrying question. If a vendor cannot support the compliance conversation, configure so PHI never reaches them at all: blur on, domain-level detail only, query strings stripped. This is not legal advice; run the specifics past your compliance officer, who will have opinions about retention windows too.

Fairness is not a luxury in clinical-adjacent work

Healthcare support work is high-burnout, and surveillance pressure makes it worse. The same design choices that protect patients also protect the team: people should know exactly what is captured and be able to read their own data, phone-heavy roles should not be punished by keyboard-based activity scores, and a quiet stretch on a patient call must count as work, because it is. A monitoring rollout that the team reads as a trap will cost you nurses' aides, billers, and coordinators who are expensive to replace, and it corrupts the data with workarounds besides.

The healthcare evaluation checklist

TimeNova blurs on the device before upload as a hard gate, can strip URL query strings before anything is stored, can keep browser detail at domain level, and shows every desktop-app user their own data. From $9 per user per month, 2 months free on annual. Start a 14-day free trial.