So actual patient data is being stored and manipulated, and manually "stripped" so that it can be posted (in effect) to the web? Again, I don't want to misunderstand you, but you feel comfortable doing this? I wouldn't.
Please provide your backup, retention, deletion, access logging, etc., policies on that data you are manipulating.
Am I understanding that an audit two months from now (you log your access and use of this data as required by HIPAA, right?) will indicate that this data was "stripped" and shared?
I would be very very cautious about thinking that "stripping" data like this isn't very prone to error, and to not realizing that storing and sharing this kind of data without a lot of care and thought could create huge problems.