A master patient index (MPI) is a database that gives each patient one unique identifier.
Every clinical encounter, in every department and system, links back to that single verified identity record. A Ministry of Health poster in PubMed notes that up to 20% of registered patients are duplicated in most systems. It recommends search algorithms to reduce this. Without an MPI, one person can exist as several separate records in systems that never share data.
This guide covers how patient matching works, how an MPI differs from an enterprise master patient index (EMPI), and what HIPAA requires. It also sets out the habits that keep patient identity data clean in a small practice.
Key takeaways
A master patient index assigns each patient a unique medical record number (MRN) and links all encounters to one verified identity.
Duplicate patient records cause medication errors, misdiagnosis, and billing fraud exposure, and the MPI is the main defense against them.
An EMPI extends MPI logic across multiple facilities, while most small practices need a well-maintained single-facility MPI.
HIPAA treats MPI data as protected health information (PHI), so a third party that manages it needs a business associate agreement (BAA).
Pabau, the practice management system we build, keeps each patient on one client card, which helps you avoid duplicate profiles.
What is a master patient index in healthcare?
A master patient index is a register that holds one record per patient, each keyed to a unique medical record number (MRN). It maps every clinical encounter to that single identity. Hospitals and practices create an MPI entry when a patient first registers. Later visits, procedures, and billing events attach to the same MRN.
The MPI does not store clinical notes or lab results. It holds identity data, so every system in the organization knows that last Tuesday’s consultation and last month’s follow-up call belong to the same person.
Think of it as the spine of a health record system. EHRs, billing platforms, scheduling tools, and lab portals all need a consistent patient identity before they can exchange data safely. The MPI supplies that identity layer, while the clinical content sits in your wider medical records management setup.
How a master patient index works
When a patient registers, the system checks whether a matching identity already exists in the MPI. If it finds one, it returns the existing MRN and links the new encounter to it. If it finds none, it creates a new MRN. This check runs at every point of entry, from the reception desk and online booking to referral intake and emergency admission. The diagram below maps it.

The matching step is where the complexity lives. Two approaches handle it, and most modern systems combine them. Getting it right keeps appointments, notes, and invoices attached to one person, and good patient management software is built around that link.
Deterministic vs probabilistic patient matching
Deterministic matching requires an exact match on one or more defined fields before linking records. Probabilistic matching assigns a weighted score across multiple fields and links records when the combined score crosses a confidence threshold. Scores that land just below that threshold usually go to a staff member for review instead of linking automatically.
What information is stored in a master patient index?
The MPI holds the identity data needed to match a person across systems, not their clinical record. Standard fields include:
- Full legal name (including previous names)
- Date of birth
- Gender
- Address history
- Contact details (phone, email)
- Medical record number (MRN), one per facility
- National identifiers where applicable (Social Security number in the US, NHS number in the UK)
- Insurance or payer identifiers
- Next of kin or emergency contact
Some MPI implementations also hold a pointer to the patient’s primary care record, known allergies, and flags for sensitive record access. The depth varies by system. The purpose stays the same: give every connected application enough information to confirm it has the right person.
Master patient index vs enterprise master patient index
A master patient index operates within a single facility or organization. An enterprise master patient index (EMPI) spans multiple facilities, health systems, or care settings, and resolves patient identity across all of them.
Most independent practices and small groups do not need an EMPI. A well-maintained single-facility MPI, built into their practice management or EHR system, does the job. The EMPI question comes up when organizations merge or a practice joins a hospital network. It also arises when a regional health information exchange links records across covered entities.
Why duplicate patient records are dangerous
Duplicate patient records put patients at clinical risk. When two records exist for the same person, a clinician may act on an incomplete or outdated record without knowing the other one exists.
Here is what that looks like in practice:
- Medication errors: a prescriber reviewing the wrong record may miss a documented allergy or an existing prescription, leading to a dangerous interaction
- Misdiagnosis: test results and imaging from previous visits may be missing from the record the clinician opens, causing repeat procedures or missed diagnoses
- Billing fraud exposure: duplicate records create billing anomalies that can trigger payer audits and, where the overlap is systematic, fraud investigations
- Regulatory non-compliance: HIPAA gives patients the right to access and amend their records, and duplicates make those requests hard to fulfill
- Broken care continuity: referrals sent to specialists may arrive with incomplete histories if the referring system pulls from the wrong record
Estimates run from about 8% to as high as 20% of records in most systems (PubMed), depending on how consistently data entry standards are enforced. A working master patient index is the main structural control for keeping that rate close to zero.
The role of the master patient index in health information exchange
Health information exchanges (HIEs) are regional or national networks that let different healthcare organizations share patient data. Every participating organization has to agree on who a patient is before it can exchange their records. That agreement runs through an EMPI.
The US Department of Health and Human Services (HHS) has confirmed that a health information organization (HIO) may run one MPI for several covered entities. It has to act as a business associate under HIPAA to do so. In practice, the HIO needs a signed business associate agreement (BAA) with each covered entity whose patient data it indexes.
This is how statewide and regional patient identity networks operate. A regional HIO maintains the EMPI. Hospitals, practices, labs, and pharmacies contribute their local MPI data to it. When a patient presents at any participating facility, the HIO can resolve their identity and pull relevant records from across the network.
HIPAA, privacy, and the master patient index
Data held in a master patient index is protected health information (PHI) under HIPAA. Name, date of birth, address, contact details, and identifiers like the MRN all count as PHI once they are linked to a healthcare context. Standard HIPAA safeguards therefore apply: access controls, audit logging, minimum-necessary disclosure, and breach notification.
Practices comparing HIPAA compliance tools should check the MPI against the Security Rule’s technical safeguards. That means encryption at rest and in transit, role-based access, and audit trails that log who accessed or changed a patient record, and when.
Three specific obligations are worth flagging:
- Business associate agreements: if a third-party vendor manages your MPI or EMPI (common in cloud-based systems), a BAA is required before any PHI is processed
- Retention: many organizations keep the identity record indefinitely, and state law sets the minimum, so the MPI can still match a patient decades later
- Patient rights: patients may request access to their demographic information and corrections to inaccurate data. Your MPI system needs a workflow to handle those requests within HIPAA’s timeframes
Best practices for managing a master patient index
Most MPI problems trace back to three causes. Data entry at registration is inconsistent, deduplication is weak, and staff were never told why identity accuracy matters. The American Health Information Management Association (AHIMA) publishes guidance on patient identity integrity, and the practices below reflect it.
Five practices make a measurable difference, and keeping patient records current runs through all of them:
- Standardize data entry at registration. Define required fields, enforce format rules (date of birth as MM/DD/YYYY, not free text), and check entries against existing records before creating a new profile. Most duplicates are created at registration.
- Run scheduled deduplication audits. Monthly or quarterly batch reviews catch potential duplicates that slipped through registration controls. A simple query comparing last name, date of birth, and ZIP code surfaces many of them.
- Use probabilistic matching where data quality is inconsistent. Name changes, address updates, and data entry errors defeat exact-match logic. A weighted confidence score catches matches that deterministic rules would miss.
- Assign a named owner for MPI integrity. In larger practices this is a health information manager. In smaller practices it is often the practice manager. Without a named owner, deduplication tasks quietly slide down the list.
- Train front desk and admin staff on the consequences. Staff who know a duplicate record can cause a medication error take more care with data entry. A short session on why identity accuracy matters is often enough to change habits.
Pro Tip
Run a monthly report that flags patient profiles created in the same 30-day period with an identical date of birth and last name. This query surfaces potential duplicates for a single review session.
Master patient index software: What to look for
For most practices, the master patient index comes built into the EHR or practice management system rather than as a standalone product. When you evaluate how a platform handles patient identity, these features separate adequate from reliable:
- Matching algorithm quality: does the system use probabilistic matching, or exact-match logic alone? Exact-match-only systems produce more duplicates in practices with high patient volumes or complex demographics.
- Duplicate detection at point of entry: the system should flag a potential match before a new record is created, not after. Merging records after creation is slow and error-prone.
- EHR integration: the MPI layer should pass a resolved identity cleanly to clinical documentation, billing, and scheduling. That way every downstream system works from the same patient.
- Audit trail: every change to a patient identity record should be logged with a timestamp and user ID. This is both a HIPAA requirement and a practical governance tool.
- Merge and unmerge workflows: when duplicates turn up, the system should support a documented merge process. It should also let you reverse a merge if two records were wrongly linked.
- Scalability: a system that resolves identity well at 500 patients should still do so at 50,000. Check whether matching performance degrades at scale.
How Pabau handles patient identity and record integrity
Pabau is an all-in-one practice management system built for aesthetic, medical, and wellness practices. Its medical records software keeps each patient on one client card. The whole clinical team sees treatment history, forms, and follow-up messages in one place. Role-based access controls and encryption limit that record to authorized staff.
The MPI principle carries straight over to a single practice: search existing patients before creating a new profile, so every encounter attaches to one record. Ask to see that registration step during your demo, including how the team handles a suspected duplicate.
Pabau’s digital intake forms capture patient demographics in the same structured fields at every touchpoint, including self-serve online booking. Your front desk no longer types identity data free-form on different days, which is where many duplicates start.
If you run several locations, ask how patient records are shared across sites in your setup before you migrate. That answer decides whether a patient who visits two of your sites stays one record.
Keep one clean record for every patient
Pabau’s client records help you avoid duplicate profiles and give your whole team a single trusted view of every patient.
Conclusion
Treat duplicate records as a patient safety problem, and treat the master patient index as the control that stops them. In a single practice, that control is mostly discipline: standard fields at registration, a search before every new profile, and a monthly duplicate review.
The trade-off is a few seconds at the desk against hours of clean-up later. Merging two records after a missed allergy is far harder than checking a date of birth at check-in.
Want registration, intake, and patient records in one system? Book a demo to see how Pabau keeps each patient’s history on a single record.
Continue your research
Comparing systems that hold patient identity? Best patient management software reviews nine systems on records, intake, and scheduling.
Storing patient details in a CRM? HIPAA compliant CRM explains what a CRM needs before it can hold PHI.
Training the front desk on privacy? Patient confidentiality covers what it means in day-to-day practice and how to protect it.
Planning how records are stored and organized? Medical records management walks through how practices store, organize, and protect patient records.
Cleaning up the records you already have? Keeping patient records accurate shows how to keep records accurate, safe, and audit-ready.
Frequently asked questions
What is a master patient index (MPI) and what does it do?
A master patient index is a database that assigns each patient a unique medical record number. It links every clinical encounter, across departments and systems, to a single verified identity. It prevents duplicate records, supports accurate billing, and gives clinicians confidence that the record they are viewing is complete.
What is the difference between a master patient index and an enterprise master patient index (EMPI)?
A master patient index operates within a single facility. An enterprise master patient index (EMPI) spans multiple facilities or an entire health system. Small and independent practices typically need a single-facility MPI, while hospital networks and health information exchanges use an EMPI to resolve identity across organizations.
Can a health information organization manage a master patient index on behalf of multiple covered entities?
Yes, provided it acts as a business associate under HIPAA. The US Department of Health and Human Services has confirmed that a health information organization (HIO) may run an MPI for several covered entities. A signed business associate agreement (BAA) is required with each one before any protected health information is processed.
How long should master patient index data be retained?
Many organizations keep the identity record indefinitely, and state law sets the minimum. Keeping it lets the MPI match a returning patient years later, even after older clinical records are destroyed under a retention policy.
Is a master patient index required for HIPAA compliance?
No, HIPAA does not mandate a master patient index by name. Its requirements for access controls, audit logging, and patients’ rights to access and correct their records are hard to meet without one. An MPI is the standard way healthcare organizations meet those obligations in practice.
What master patient index software should small practices look for?
Small practices rarely need standalone MPI software. The MPI function should be built into their EHR or practice management platform. Look for duplicate detection at the point of registration, probabilistic matching support, full audit trails, and a documented merge workflow for resolving duplicates once identified.