Join our Newsletter — 33% off our NHI Course
Governance, Ownership & Risk

Shadow Notes

← Back to Glossary
By NHI Mgmt Group Updated September 19, 2026 Domain: Governance, Ownership & Risk

Shadow notes are patient or operational records created outside approved clinical systems. They may be used to avoid slow workflows or rigid logging rules, but they create governance and security risk because information can end up in unmanaged locations. That makes oversight, retention, and privacy controls much harder to enforce.

What Shadow Notes Are in Practice

Shadow notes are usually a response to friction, not malice. Clinicians or operational staff create them when approved systems are too slow, too rigid, or too hard to access during real work, so the note becomes a workaround for capturing information that still feels urgent.

That workaround changes the security posture of the record. Once notes are created outside approved clinical systems, they may fall outside normal access controls, search, audit trails, retention rules, and data loss prevention controls. The result is not just a documentation gap, but a governance gap that can persist long after the note was written.

Why Shadow Notes Matter for Governance

Shadow notes are a classic example of records that are “present” operationally but invisible administratively. They may live in email, chat, local files, personal devices, paper scans, or unapproved apps, which means the organisation may not know where the information resides or who can see it.

That creates uncertainty around ownership, retention, legal hold, and deletion. If the note contains patient details, operational decisions, or incident context, the organisation may be unable to prove that it handled the record according to policy. The same issue also weakens continuity, because other staff may never see the information when they need it.

For a broader control perspective, the problem aligns with the same record-control and auditability concerns that underpin NIST Cybersecurity Framework 2.0 and the confidentiality, audit, and configuration disciplines in NIST SP 800-53 Rev 5 Security and Privacy Controls.

Common Patterns and Failure Modes

Shadow notes often emerge where the approved workflow is slower than the work itself. That can happen during shift handoffs, urgent exceptions, outage handling, temporary service interruptions, or when a system is usable but too cumbersome for quick note-taking.

The security failure is usually not the existence of the note alone, but the loss of system-enforced safeguards around it. A note in an unmanaged location can be copied, forwarded, synced, backed up, or retained indefinitely without the same oversight expected in the primary system of record.

This is why unmanaged record-keeping often overlaps with broader privacy exposure and secret-sprawl concerns. The same operational habit that creates shadow notes can also create unmanaged sensitive data outside the place where policy and monitoring are strongest, which is why NIST’s privacy guidance and the principle of controlled data handling are relevant reference points. In practice, the most direct control mapping is the obligation to keep sensitive records discoverable, governed, and auditable.

Where the note contains regulated or sensitive data, the privacy boundary matters as much as the storage location itself. A note that bypasses the official record path can become hard to classify, hard to search, and hard to delete, which is a familiar failure pattern in many data-governance incidents.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0 and NIST SP 800-63 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0GV — GovernShadow notes create governance and oversight gaps around unmanaged records.
PR.DS — Data SecurityShadow notes can place sensitive information in unmanaged locations outside normal protections.
DE.CM — Continuous MonitoringUnmanaged notes reduce visibility into where sensitive information resides and who accesses it.
Recommendation — Assign ownership for shadow-note controls and enforce approved-record governance across workflows. Protect shadow-note data with approved storage, access, and retention controls. Monitor for unapproved record storage and unmanaged sharing paths.
NIST SP 800-63IAL — Identity Proofing and Authentication AssuranceWhen shadow notes contain sensitive operational or patient data, controlled access depends on strong identity assurance.
AAL — Authenticator Assurance LevelsApproved systems need strong authentication so staff are not pushed toward unmanaged note-taking workarounds.
FAL — Federation Assurance LevelsFederated access affects whether staff can reach the official system quickly enough to avoid shadow notes.
Recommendation — Use strong identity assurance for the systems that hold governed records. Require strong authenticators for access to the sanctioned record system. Set federation assurance to support fast access to the approved record platform.

Practitioner Guidance

Why practitioners should care: Shadow notes are usually a symptom of workflow design, not just user behaviour. If staff repeatedly work around the approved system, the organisation should treat that as a signal that the formal process is not matching operational reality.

Common misunderstanding: The issue is not solved by reminding people to “use the system” if the system is slow or impractical. Durable reduction usually comes from making the approved path easier than the workaround, while still preserving the record, retention, and oversight requirements that matter for safety and governance.

Practitioner takeaway: The key question is not only where the note was written, but whether the organisation can still govern it as a record after the fact.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 19, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org