If they are used to store protected health information it’s the practice’s duty to make sure they comply with HIPAA regulations. So for example can’t leave that file cabinet unlocked out in the front lobby.
When I was looking to make an app for a clinic they had to do a security review of the app. If the data wasn’t encrypted at rest it was a no-go. There are entire data companies sprouting out to address this issue. I think TrueVault is a Y-Combinator alum.