I am requesting the ability to restrict the export of patient data separately from view permissions. This is a critical security feature and should be prioritized. Currently, all staff and providers who can view a form/treatment note can also export in CSV file all of the PHI in that form/treatment note . There is no setting to prevent or modify this. Role-based restrictions are available for many other features (e.g., appointments, claims, client lists), while this critical aspect of data security remains unprotected. While staff might need to view certain forms to provide care, exporting data is a different level of access that should be more tightly controlled . The current set-up opens the door to potential misuse and violations of both HIPAA and patient privacy. Implementing this feature aligns with best practices in healthcare, where the ability to export data in easily usable formats is tightly controlled to protect patient privacy. This urgent enhancement would significantly improve data security and ensure practices using IntakeQ/PracticeQ can manage patient privacy confidently in compliance with HIPAA.