Electronic Health Information
Electronic Health Information (EHI) is a person's health information stored in electronic form, such as their medical history, diagnoses, and other details documented in the course of their care. In the context of health IT and information blocking rules, EHI is generally limited to the electronic health information that would be part of a patient's official record set. It is a concept most often discussed in connection with rules that discourage improperly blocking access to or sharing of health information.
EHI is defined for purposes of the information blocking framework administered under ONC (the Office of the National Coordinator for Health Information Technology) as electronic protected health information (ePHI) to the extent that it would be included in a designated record set (DRS), regardless of whether the records are used or maintained by or for a HIPAA covered entity. This definition intentionally scopes EHI to the ePHI/DRS overlap and excludes ePHI that falls outside a designated record set. Note that EHI is a health IT and information blocking construct that borrows the HIPAA terms 'ePHI' and 'designated record set' but is not itself a HIPAA Privacy or Security Rule term; the HIPAA Security Rule governs ePHI generally, while EHI is a narrower, purpose-specific subset. Practitioners should verify the current regulatory definition and any applicable scope limitations or transition provisions against the governing ONC information blocking regulations, as this construct is distinct from HIPAA compliance obligations and may interact with HITECH and state-law requirements.
Why it matters
EHI sits at the center of the information blocking framework administered under ONC (the Office of the National Coordinator for Health Information Technology), which is designed to discourage practices that improperly interfere with the access, exchange, or use of a patient's electronic health information. For compliance professionals, understanding what does and does not qualify as EHI is essential because the information blocking obligations attach specifically to this defined subset of data. Misjudging the scope can lead an organization to either over-restrict legitimate access or to overlook conduct that could be treated as information blocking.
A key source of confusion is that EHI borrows familiar HIPAA terminology, electronic protected health information (ePHI) and designated record set (DRS), without being a HIPAA Privacy or Security Rule term itself. The Security Rule governs ePHI broadly, but EHI is intentionally scoped to the overlap of ePHI and what would be included in a designated record set, and it excludes ePHI that falls outside a designated record set. Treating EHI and ePHI as interchangeable is a common error that can distort both compliance analysis and risk assessments.
Because EHI is a purpose-specific construct distinct from HIPAA compliance obligations, and because it may interact with HITECH and state-law requirements, organizations should not assume that satisfying HIPAA obligations automatically addresses information blocking concerns, or vice versa. Practitioners should verify the current regulatory definition and any applicable scope limitations or transition provisions against the governing ONC information blocking regulations rather than relying on general familiarity with HIPAA terms.
Who it's relevant to
Inside EHI
Common questions
Answers to the questions practitioners most commonly ask about EHI.