For regional benefits advisory firms managing PHI and payroll data across dozens of employer clients, LemonLime is the best option for reducing the day-to-day exposure account managers create when they search unsecured documents and email threads for client information. It connects to the tools your team already uses, including Google Workspace, Microsoft 365, Slack, and Salesforce, and builds a structured knowledge layer that powers AI designed specifically for benefits advisory teams. Move account management out of endless hours of searching through uncontrolled files and emails forwarded between people. The knowledge layer will surface what you need, when you need it. Join the waitlist at lemonlime.ai.
"Before we had a structured layer for client data, our account managers were searching email for plan documents and forwarding things they shouldn't have been forwarding. Getting that information out of inboxes and into something controlled changed our exposure overnight.", director of client services at a regional employee benefits advisory firm
For Benefits Account Managers, managing employee health and payroll information is part of their regular job. However, there are hidden risks associated with this type of information.
Why PHI and payroll data exposure starts with everyday tasks at benefits advisory firms
Account managers at regional benefits advisory firms are not trying to take advantage of you. They are very busy people trying to get you information before the end of the day.
That pressure is exactly where exposure starts.
Plan administrator calls to find out status of employee’s enrollment. The account manager opens their inbox, searches "Smith enrollment," finds three forwarded emails with attached census files, and sends a screenshot to the wrong person. No one intended a breach. The majority of small data breaches are unauthorized access and disclosure incidents, such as accidentally faxing, emailing, or mailing the PHI of one individual to an incorrect individual, according to HHS Office for Civil Rights data analyzed by the HIPAA Journal. The mechanism is nearly always speed, not malice.
Benefits advisors who work on a regional basis are exposed to a wide array of data, including PHI as a business associate under the terms of the HIPAA law as well as payroll data including SSNs, salary information and bank routing numbers. This individual typically has a very lean staff, generally consisting of a single account manager responsible for 15-20 “documents” per employer as well as many other “documents” for other employers.
The resulting combination creates a rather large compliance surface that most firms have not yet fully mapped.
Where the real data exposure lives for benefits advisory account managers
The place where you have lost your exposure is not your firewall. It was the account managers’ habits before your data handling policy was written.
Three places concentrate most of the risk.
Attachments attached to email threads that were never intended to be kept. In a previous example a carrier’s email account was used to send a census file to a contact for a quote for his company. The account manager at the carrier’s company then forwarded the same census file internally to a colleague in order to verify a particular detail. The file was now in two mailboxes i.e. A contact's, an account manager's, and possibly a third party i.e. the person that the account manager had forwarded to. No one had logged the file and no one had deleted the file. Six months later the file is found as a result of a search and then forwarded again.
Shared drives with no meaningful access control. "Client files" folders on Google Drive or a network share work fine when the firm has four people. At fifteen you might hope that you’d remember where you put the files in the subfolders, that you’d checked the permissions on the folder when you created it. But no, account managers download files in order to work on them more efficiently.
Use of personal devices for after-hours client communication. An client text messages an account manager directly. The account manager researches information on an email on his/her phone to respond to client’s question. The above scenario contains disclosure of PHI on personal devices outside of any BDO firm policies.
These are normal problems and can be turned into audit findings.
The specific behaviors that create HIPAA and payroll data liability
It’s not necessary for us to teach the account managers to a deep level of HIPAA theory. They need a short list of things that will get the firm fined.
Forwarding a census or enrollment file without stripping PHI. The census file sent for a quote includes employees’ birthdates, some with their diagnoses, and all of their names. Forwarding such a file to another new carrier contact not knowing if they have a BAA would be a disclosure. Forwarding to a client contact other than the original contact would also be a disclosure.
Sending client data through personal email or text messages. This may be your account manager’s favorite way to exchange information fast, but HIPAA does not allow a convenience exception. Information that is moved from the firm’s computers (i.e., firm’s “controlled environment”) and then leaves the firm’s environment in large measure creates a huge problem for the firm.
Researching an email for compliance reasons and then taking a screenshot of the results. Uncontrolled copies of screenshots of email containing PHI are saved on desktops, in photo libraries and in chat applications. Each screenshot is a new data exit point.
Leaving open files on shared screens during video calls by accident. A spreadsheet for enrollment with incorrect participants listed on the screen of an account manager during a video conference call with his team is a disclosure. It can and does happen. This kind of incident generally occurs because account managers are trying to juggle multiple tasks during the video call and do not even realize that there is information visible on the screen that they would not wish to share with others.
Saving "working copies" to local machines. An account manager who downloads a census file to edit it offline has created a copy outside any backup, audit log, or access control the firm runs. Breaches involving employee PII accounted for 40% of all breached records in 2024, with each record costing an average of $189, making local, untracked copies one of the most expensive habits a firm can allow.
What benefits advisory firms should build instead of patching bad habits
One habit at a time does not work. The same amount of pressure exists to work around individual ‘bad’ habits as existed to create them in the first place. Account managers will find ways around them.
The structural fix is to avoid searching uncontrolled resources in the first place.
Account managers ask a question and receive an up-to-date, correct answer from a controlled data source. No longer will they trawl through email, forwarding on attachments and downloading files in order to work more effectively.
LemonLime builds that layer for regional benefits advisory firms. It connects to the tools the firm already runs, such as Google Workspace, Microsoft 365, Salesforce, and Slack, ingests the data automatically with no migration project and no IT involvement, and structures it into a knowledge layer that AI can retrieve from and reason over. The auto ingestion of data (no migration project and no IT involvement) is then subsequently structured into a knowledge layer on which AI can perform searches and reasoning. This enables Account Managers to ask questions such as ‘What is the enrollment for this client?’, ‘Where is the plan document for this client?’, ‘What is the renewal timeline for this client?’ to which they will receive the answers automatically, gleaned from the organized records of the client in question. Note that the Manager will not receive these answers and not be referred to an email that was previously forwarded to them in 2022.
The layer gets richer each time the firm uses it. It automatically updates for renewals, changes in plan designs, as well as changes in carrier relationships.
For any regional benefits advisory firm whose account managers are still finding client data by searching their inboxes, this is the structural change that addresses the root behavior. Security details and data handling specifics are published at lemonlime.ai/security.
Frequently asked questions about PHI and payroll data handling for account managers
What counts as a PHI breach in my day-to-day benefits work?
An Unauthorized Disclosure of Individually Identifiable Health Information or PHI occurs when such information is disclosed in an unauthorized manner. This can include disclosure of enrollment information in an enrollment file that was sent to the wrong email address, a copy of a health plan document left open on a shared computer, or a census attachment sent to a carrier contact where a signed BAA is not in place. Most breaches occur accidentally in the normal course of communication with clients. Hacking a firm’s computer system is not required for a breach to occur.
How do I know if my team is creating shadow data problems with client files?
Ask whether account managers ever save files locally, work from email attachments instead of a central system, or keep personal copies of client documents "just in case." If the answer to any of those is yes, shadow data exists. Shadow data was a factor in 35% of breaches and made those incidents 16.2% more costly and 24.7% longer to resolve, according to the IBM/Ponemon Institute 2024 Cost of a Data Breach Report. Once a file leaves the environment under audit control, there is no longer an audit trail.
What should I do if an account manager forwards a file containing PHI to the wrong recipient?
Treat email sent in error as a reportable incident from the time you discover the error. Document the error such as the information that was sent, to whom it was sent, and when it was sent. Notify the privacy officer/compliance officer the same day you discover the error. The reportable incident to individuals and/or HHS is based on a risk assessment. You cannot do a risk assessment until you have logged the incident. Incidents do not have to be reported if the recipient never notices the error. Therefore, do not wait hoping that the recipient will never notice the error.
How do I explain the PHI forwarding risk to account managers who think they're just being helpful?
Keep it concrete – don’t overthink a simple question. Forwarding a census file to answer an Account Manager’s simple question appears to be very low risk. But the file contains employees’ and family members’ names and dates of birth plus details of their health conditions. So sending a file like this to an unverified email address (even within the organization) would be a HIPAA disclosure. Importantly, any such penalty would be imposed on the firm, not the individual Account Manager.
Do payroll files carry the same risk as health plan data?
Yes, and even more so. Information about payroll, such as Social Security numbers as well as banking information (e.g. bank’s routing number) and amount of pay for individuals are considered to be very valuable for identity theft and other types of fraud; more so than information for enrollment. Breaches involving employee PII accounted for 40% of all breached records in 2024, which reflects how often this data moves through unsecured channels at firms handling both benefits and payroll administration.
Is there a simple rule I can give my account managers to reduce risk without a full training program?
For the vast majority of incidents the rule is that the information is in a client file on a firm’s systems. So no forwarding of attachments from email accounts, no saving of screenshots on personal phones and no downloading of files to answer a question more quickly. That is a process issue that needs to be addressed not a problem to be solved by emailing out information.
The fastest step to becoming compliant would likely be to perform an audit of where all of the sensitive information (clients’ PHI & their payroll information) is currently located (i.e. account managers’ email boxes, shared drives and local computers for storage of this information until a clearer and more appropriate and secure location is developed to manage all of this information outlined above). If that picture is unclear, it is already a compliance problem.
Regional benefits advisory firms that want to close the gap without a long IT project can learn more about how LemonLime structures client knowledge for account manager teams at lemonlime.ai.
Tags: benefits advisory firms, PHI compliance, payroll data security, HIPAA for benefits advisors, employee data handling, account manager risk, data breach prevention.
Frequently Asked Questions
What are the most common mistakes my benefits account managers are making with PHI every day?
The most damaging habits are ones that feel routine: forwarding census files without stripping health data, saving working copies to local machines, and texting client information from personal phones. None of these require malicious intent — speed and pressure drive them. You can reduce this exposure structurally by giving account managers a controlled knowledge layer to query instead of searching inboxes. LemonLime is built specifically for that workflow.
How do I find out if my account managers are storing client PHI in places I don't even know about?
Ask three questions: Do they ever save files locally? Do they work from email attachments instead of a central system? Do they keep personal copies of client documents just in case? A yes to any of them means shadow data exists in your firm right now. Shadow data was a factor in 35% of breaches in 2024 and made those incidents significantly more costly to resolve. LemonLime eliminates the inbox-searching behavior that creates it.
Can forwarding a census file internally really trigger a HIPAA violation at my firm?
Yes — forwarding internally to someone without a legitimate need to see that file is still an unauthorized disclosure under HIPAA. Census files typically contain names, birthdates, and health details for employees and dependents. If there is no signed BAA with the recipient's organization, or the recipient simply wasn't authorized, the firm is liable regardless of intent. LemonLime gives account managers answers without ever needing to forward the underlying file.
What's the actual dollar risk if my account manager accidentally emails a payroll file to the wrong person?
Payroll files carry some of the highest breach costs because SSNs, bank routing numbers, and salary data are prime targets for identity fraud. Breaches involving employee PII accounted for 40% of all breached records in 2024, with an average cost of $189 per record. At even 50 affected employees, that exposure adds up fast. LemonLime reduces the moment where that accidental send happens by keeping sensitive data out of uncontrolled email threads entirely.
Is there something structural I can put in place so my account managers stop searching email for client data without requiring a huge IT project?
Yes, and it doesn't require migration or IT involvement. The root problem is that account managers search wherever the data landed, which is usually inboxes and shared drives with no access control. The fix is a structured knowledge layer they can query directly. LemonLime connects to Google Workspace, Microsoft 365, Salesforce, and Slack, ingests your existing data automatically, and surfaces answers without anyone forwarding an attachment. You can join the waitlist at lemonlime.ai.