Home Articles Get your free assessmentComing soon

Tag: confidentiality

  • The Most Sensitive File in the Building

    The Most Sensitive File in the Building

    A pastor sits down after a Thursday afternoon conversation and writes half a page of notes. A marriage in trouble. A relapse. A name and a date and enough detail to remember what to follow up on next month.

    The notes go into a Word document on the office laptop, in a folder called Care. The laptop is the one the whole staff borrows when theirs is charging. The folder syncs to the shared drive, because everything on that laptop syncs to the shared drive — that’s how it was set up years ago, and it was set up that way so nothing would ever be lost.

    Every person on staff can open that folder. Not one of them ever has. That isn’t a security control; it’s good manners.

    Elsewhere in the same building: benevolence applications with bank details and eviction notices in a cabinet that doesn’t lock, a text thread on a personal phone that contains a full disclosure of abuse, and a notes field in the church management software where somebody typed “husband’s drinking again — do not mention to the Wilsons” three years ago, not realizing that eleven volunteers can see it.

    This is the most sensitive information any church holds, and it is almost always the least protected.

    Confidentiality and security are two different things

    This distinction is worth slowing down for, because the two are constantly confused.

    Clergy confidentiality — often discussed alongside the clergy-penitent privilege, a legal rule about what a minister can be compelled to testify to in court — is a legal and ethical concept. It’s about who may lawfully demand the information, and what a minister is obliged to do with it. Its scope varies significantly by state, and denominations layer their own ordination vows and disciplinary standards on top. Some states affirm the privilege broadly, some limit it to confessional communications, and the Children’s Bureau’s fifty-state summary notes that in some states it is denied altogether.

    Data security is about who can physically or technically reach the file. Passwords, permissions, locks, encryption.

    Here is the load-bearing sentence: a note that is privileged in principle is still readable by anyone with the password. Privilege governs a courtroom. It does nothing whatsoever against a compromised email account, a laptop left in a car, or a volunteer clicking into a folder they shouldn’t have been able to open.

    A related confusion is worth clearing up. Churches often assume health-privacy law covers them. Generally it does not — the federal rule applies to health plans, health care clearinghouses, and health care providers who transmit certain information electronically in connection with standard transactions. A congregation offering pastoral care isn’t ordinarily any of those. There may be exceptions if your ministry operates a counseling center, employs licensed clinicians, or bills insurance, and that’s a question for your attorney. But do not assume a federal law is protecting these records. Usually nothing is except your own practices.

    And one thing that overrides all of it: mandatory reporting obligations exist, they vary, and in defined circumstances they take precedence over confidentiality. According to the Children’s Bureau’s summary of state statutes, members of the clergy are named as mandated reporters in 29 states and Guam, and seven jurisdictions — New Hampshire, North Carolina, Oklahoma, Rhode Island, Texas, West Virginia, and Guam — disallow the clergy-penitent privilege as grounds for failing to report suspected child abuse or neglect. Four states — Indiana, New Jersey, North Carolina, and Wyoming — require all persons to report regardless of profession. That summary is current through May 2023 and these laws change. Know your own state’s rule cold, in writing, before you need it. Ask a lawyer. This article is not legal advice.

    Decide what gets written down at all

    The most effective control here isn’t technical. It’s editorial.

    Before you write anything, ask: what do I actually need to remember, and what would harm this person if it were read by someone else? Those two answers overlap far less than people assume.

    A workable standard for care notes in a congregational setting:

    Write enough to follow up. Date, who you met with, that a conversation happened, and what you committed to do. “Met with R. Follow up in two weeks. Referred to counseling resource list.”

    Leave out the detail that isn’t yours to hold. The specifics of a disclosure, third parties’ names, diagnoses, financial particulars, anything about someone’s spouse or children who were not in the room. If you don’t need it to be a good pastor next month, it doesn’t need to exist on paper.

    Never write speculation, judgment, or diagnosis. Not because someone might sue, though they might, but because you’re recording a guess about a human being that will outlive your memory of how uncertain you were.

    Assume it will be read. By a successor, by a board in a conflict, by a court under subpoena, by an attacker in a breach. Write the note that you would be content to have read aloud.

    This is not an argument for keeping no records. Continuity of care matters, and a pastor who remembers nothing serves people badly. It’s an argument for writing the minimum that does the job.

    Where these files should actually live

    Out of the general shared drive. This is the single highest-value change most churches can make in an afternoon. The default setup at a small organization is one shared drive, open to all staff, because that was simplest to configure. Care notes and benevolence files need to come out of it into a separate location with its own permissions.

    Access granted to named people, not to “staff.” There is a real difference between a folder shared with the staff group and a folder shared with Pastor Miller and Pastor Ruiz. The first automatically includes every future hire, every intern, and the office volunteer who was added to the group last spring. The second doesn’t. Name the individuals.

    Paper goes in a locking cabinet, and the key is controlled. Benevolence applications in particular — they routinely contain bank account numbers, Social Security numbers, pay stubs, and eviction notices, which is a more complete identity-theft package than most churches hold anywhere else.

    Set a retention limit and honor it. Decide how long care notes and benevolence files are kept, write it down, and destroy them on schedule. Records you no longer hold cannot be exposed, subpoenaed, or misread by a successor. What the right period is depends on your state, your denomination’s polity, your insurer, and whether any licensed counseling is involved — ask your attorney for the number, then follow it.

    Multi-factor authentication on the accounts that can reach any of this. MFA is the extra code or tap after the password. It’s free on Microsoft 365 and Google Workspace, and Microsoft’s own research finds it blocks more than 99.2% of account compromise attacks. If a folder is worth restricting, the account that can open it is worth protecting.

    Email, texting, and the notes field nobody thinks about

    Email is a filing cabinet you don’t control. A message about a member’s situation is copied into the sender’s sent folder, the recipient’s inbox, both mailboxes’ backups, and the provider’s servers. It stays there for years. If either account is ever compromised — the most common single security incident at any organization — the attacker gets not just the mailbox but the searchable history of everything the church knows about its people.

    If you must send something by email, keep the substance out of the subject line. Subject lines appear in notification previews on lock screens, on shared reception monitors, in mobile summaries, and in any forwarded thread. “Re: Thursday” is a fine subject line. “Re: Dana’s rehab intake” is a broadcast.

    Better: send “Can we talk about a pastoral matter today?” and have the conversation by voice.

    Texting is worse, and it’s what people actually use. A pastoral text thread sits on a personal phone with no organizational control at all. It appears in lock-screen previews. It’s visible to anyone who picks up the phone, including a spouse or a child. It backs up to a personal cloud account. And when that pastor leaves the church, the entire history leaves with them, on their device, permanently. Text to arrange a meeting. Don’t text the meeting.

    The church management software notes field is far more visible than people think. Almost every ChMS — church management software, the system that holds your directory, attendance, and giving — has a general notes or comments field on each person’s record. Staff type sensitive things into it because it’s convenient and it feels private.

    It usually isn’t. Depending on how your permissions are configured, that field may be visible to every staff member, every group leader, every volunteer with a login, and anyone who can run an export. Go look today: log in as a volunteer-level user, or ask one to show you their screen, and see exactly what a group leader can read on a member’s record. Most churches are surprised. Then either lock the field down properly or stop using it for anything but logistics.

    Two situations to plan for now

    When a staff member leaves. This is the moment the whole problem becomes visible. Their church account gets disabled — but the notes in their personal notebook go home in a box. The care history in their text messages leaves on their phone. The documents in their personal Dropbox stay in their personal Dropbox.

    Handle it at the front end rather than the back: make it clear from the first week of employment that ministry records belong to the ministry and live in ministry systems. Then, at departure, walk through it explicitly — accounts disabled, church files returned or transferred to the named successor, personal-device copies deleted, paper handed over. Have the conversation warmly and have it anyway, including when someone leaves on the best possible terms.

    When a device is lost. A laptop in a stolen car, a phone left in an airport. If care notes were on it, the question is whether anyone can read them.

    Two settings make the answer no, and both are free and already built in. Full-disk encryption — BitLocker on Windows, FileVault on Mac — scrambles everything on the drive so it’s unreadable without the login. On phones and tablets it’s on by default as long as you have a passcode. And remote wipe, which lets an administrator erase a device that’s gone. Turn both on across every device that touches ministry records, today, before you need them.

    If a device is lost, change the passwords for every account that was signed in on it, sign out all active sessions, and tell someone immediately. If information about people was exposed, notification requirements exist in every state and vary considerably — that’s a call to your attorney, promptly.

    What to do this week

    Open your shared drive and look at who can see the folder containing care notes, benevolence applications, or anything similar. If the answer is “everyone on staff,” move that folder somewhere with permissions granted to two or three named people. Fifteen minutes.

    Then log in to your church management software as a volunteer-level user and read what they can see on a member’s record. If the notes field is exposed, you’ve just found this week’s second job.

    MissionDefend’s free assessment asks straightforward questions about how your organization handles member data, accounts, email, and donations — no jargon — and returns a baseline score with the highest-value fixes ranked in order.

    No spam and no sales calls — just one email when it’s live.


    MissionDefend provides cybersecurity readiness assessments and educational guidance for churches and nonprofits. It is not a penetration test, a security audit, legal advice, or an incident response service.

    Sources: U.S. Department of Health and Human Services, Children’s Bureau, Mandatory Reporting of Child Abuse and Neglect: State Statutes; U.S. Department of Health and Human Services, Covered Entities and Business Associates; Microsoft, mandatory multifactor authentication guidance; National Conference of State Legislatures, Security Breach Notification Laws.