Skip to main content
Category: De-identification and PHI Types

Electronic Media

Also known as: Digital Media
Simply put

Electronic media generally refers to devices and technologies that store or transmit information using electronic means. In common usage this includes things like television, radio, the internet, fax, and storage devices such as CDs and DVDs. Within HIPAA, the term has a narrower, specific regulatory meaning that differs from this general definition, so readers should verify the exact scope against the current HIPAA Security Rule text.

Formal definition

In general usage, electronic media are platforms or devices that use electronic or electromechanical means to store, distribute, or transmit information, encompassing formats such as radio, television, internet, fax, and storage media like CD-ROMs and DVDs. For HIPAA compliance purposes, note that 'electronic media' is a defined term under the HIPAA Administrative Simplification regulations and is central to the Security Rule's scope over electronic protected health information (ePHI); the regulatory definition is more specific than the general one presented in this evidence and typically covers electronic storage material and transmission media. Because the evidence packet here does not include the HIPAA regulatory text, practitioners should confirm the precise HIPAA definition and any applicable CFR citation against the current regulation before relying on it.

Why it matters

Within HIPAA, the term "electronic media" is not merely descriptive vocabulary; it is a defined term under the Administrative Simplification regulations and helps establish the scope of the HIPAA Security Rule. Because the Security Rule governs only electronic protected health information (ePHI), as distinct from the Privacy Rule, which covers PHI in all forms including oral and paper, understanding what qualifies as electronic media is foundational to determining which safeguards apply to a given piece of information. If information is created, received, maintained, or transmitted in electronic form, the Security Rule's administrative, physical, and technical safeguard requirements generally come into play.

The common, everyday meaning of "electronic media" (television, radio, internet, fax, CDs, DVDs) is broader and less precise than the meaning HIPAA assigns to the term. Compliance professionals who rely on the general definition risk either overstating or understating the reach of the Security Rule. For example, decisions about how portable storage devices, transmission channels, and disposal of media must be handled typically hinge on the specific regulatory scope rather than on the colloquial usage. Misjudging that scope can affect risk analysis, device and media controls, and breach determinations.

Because the evidence available here reflects general and legal-dictionary usage rather than the HIPAA regulatory text, practitioners should confirm the precise HIPAA definition and any applicable CFR citation against the current HIPAA Security Rule before relying on it. State law and the HITECH Act may also impose additional obligations beyond HIPAA, and HITRUST CSF controls addressing media handling are a private framework that does not by itself establish HIPAA compliance.

Who it's relevant to

Security Officers
Security officers rely on the definition of electronic media to scope the Security Rule's administrative, physical, and technical safeguards, including device and media controls governing storage, transmission, reuse, and disposal of ePHI. They should confirm the precise regulatory definition rather than the colloquial one, since it directly affects which assets fall within scope.
Privacy Officers
Privacy officers should note that the Security Rule (which turns on electronic media and ePHI) is narrower than the Privacy Rule, which covers PHI in all forms including oral and paper. Understanding this boundary helps them coordinate safeguards without conflating the two rules' scopes.
IT and Infrastructure Teams
IT teams manage the storage devices and transmission channels that may qualify as electronic media under HIPAA. They should verify the regulatory scope when designing controls for portable media, network transmission, and secure disposal, and should treat HITRUST CSF media controls as a framework aid rather than proof of HIPAA compliance.
Auditors and Compliance Consultants
Auditors evaluating Security Rule conformance need the precise HIPAA definition of electronic media to assess whether an organization's risk analysis and media handling controls cover the correct assets. They should verify definitions and any CFR citations against the current regulation and flag where state law or the HITECH Act may add requirements.

Inside Electronic Media

Electronic Storage Media
Devices and materials on which data are stored electronically, generally including hard drives, solid-state drives, magnetic tapes, disks, and other digital memory. When such media hold electronic protected health information (ePHI), they fall within the scope of the HIPAA Security Rule.
Transmission Media
The channels used to move electronic data from one point to another, such as the internet, extranets, leased lines, dial-up connections, and private networks. Physical media physically moved from one location to another are also typically included in this concept.
Relationship to ePHI
Electronic media becomes relevant to HIPAA specifically when it creates, receives, maintains, or transmits ePHI. The Security Rule governs only ePHI, so paper and oral forms of PHI are addressed under the Privacy Rule rather than through the concept of electronic media.
Removable and Portable Media
Portable devices such as USB drives, external hard drives, CDs, DVDs, and memory cards are commonly treated as electronic storage media and warrant particular attention because of their mobility and potential for loss or theft.
Certain Transmissions Generally Excluded
Certain transmissions, such as paper-to-paper faxes or voice communications via telephone, are generally not considered electronic media transmissions under the HIPAA definition because the information being exchanged did not exist in electronic form before the transmission. Readers should verify specific cases against the current regulatory text.

Common questions

Answers to the questions practitioners most commonly ask about Electronic Media.

Does 'electronic media' only refer to hard drives and servers?
No. Under the HIPAA Security Rule, electronic media is broader than fixed storage like hard drives and servers. It generally encompasses electronic storage material on which data is or may be recorded electronically, as well as transmission media used to exchange information already in electronic storage. This can include portable and removable media in addition to internal storage. Because the term has a specific regulatory meaning that is broader than common usage, you should confirm the precise scope against the current regulatory text rather than assuming it maps to any single category of device.
Do the electronic media rules apply to all forms of protected health information?
No. The concept of electronic media, and the Security Rule requirements built around it, apply specifically to electronic protected health information (ePHI). PHI in oral or paper form falls under the HIPAA Privacy Rule rather than the Security Rule's media-related safeguards. This distinction matters: transmissions of information not already in electronic form, such as paper-to-paper faxes or voice by telephone, are generally treated differently from electronic media transmissions. For PHI in non-electronic forms, look to Privacy Rule obligations instead.
How should we handle electronic media before disposal or reuse?
The Security Rule addresses media disposal and reuse through its physical safeguards, which generally call for policies and procedures governing the removal of ePHI from electronic media before the media is reused, and for the final disposition of ePHI and the hardware or media on which it is stored. Organizations typically implement sanitization or destruction procedures appropriate to the media type. Because implementation specifications can be required or addressable, and 'addressable' does not mean optional, you should document your chosen approach and rationale, and verify current requirements against the applicable regulatory text.
Do we need to track and inventory electronic media that contains ePHI?
Movement and accountability of electronic media are generally addressed within the Security Rule's physical safeguards, which contemplate maintaining records of the movements of hardware and media and the person responsible, as well as making backups before moving equipment. Many organizations maintain a media inventory as a practical way to support these expectations and their overall risk analysis. Confirm the specific implementation specifications and whether they are required or addressable against the current regulatory text, and note that documenting your approach is generally advisable.
How do portable devices such as laptops and USB drives fit into electronic media obligations?
Portable and removable devices that store ePHI generally fall within the scope of electronic media and are therefore subject to the Security Rule's administrative, physical, and technical safeguards, informed by your organization's risk analysis. Because such devices are more easily lost or stolen, many organizations apply controls such as access management, media accountability, and encryption. Note that encryption is treated as an addressable implementation specification under the Security Rule, which does not make it optional; where not implemented, an equivalent alternative or a documented justification is generally expected.
Does managing electronic media according to the Security Rule mean we have met our breach and vendor obligations too?
No. Handling electronic media under the Security Rule addresses safeguarding ePHI, but it is separate from Breach Notification Rule obligations, which govern what happens if unsecured PHI is compromised, and from the business associate framework, under which obligations attach to vendors through business associate agreements. A covered entity's or business associate's media practices are one component of compliance, not a substitute for these other requirements. In addition, state law or the HITECH Act may impose further obligations, and adopting a framework such as the HITRUST CSF does not by itself establish HIPAA compliance.

Common misconceptions

Electronic media only refers to storage devices like hard drives and USB drives.
The concept generally encompasses both electronic storage media and transmission media. Transmission channels such as the internet, private networks, and physically transported media are typically included alongside storage devices.
Any transmission involving a phone or fax machine counts as electronic media under HIPAA.
Certain transmissions, such as paper faxes and voice telephone calls, are generally excluded when the information did not exist in electronic form before transmission. Practitioners should confirm particular scenarios against the current definition in the regulatory text.
All electronic media in an organization is automatically subject to the HIPAA Security Rule.
The Security Rule applies to electronic media specifically when it creates, receives, maintains, or transmits ePHI. Media that never touches ePHI is not brought into scope by the Security Rule, though other obligations or policies may still apply.

Best practices

Maintain an inventory that identifies where electronic storage and transmission media create, receive, maintain, or transmit ePHI, so that Security Rule obligations can be applied to the correct systems.
Apply appropriate technical safeguards, such as encryption for data at rest and in transit, keeping in mind that some Security Rule implementation specifications are addressable rather than optional and require documented decisions.
Give particular attention to portable and removable media, including tracking, access controls, and physical safeguards, given the elevated risk of loss or theft.
Establish and follow media reuse and disposal procedures so that ePHI is rendered unusable, unreadable, or indecipherable before media is repurposed or discarded.
Address business associate relationships through business associate agreements when vendors handle media containing ePHI, since obligations attach through defined relationships rather than to every party that touches data.
Verify the specific inclusions, exclusions, and safeguard requirements against the current HIPAA regulatory text and consider whether state law or the HITECH Act imposes additional requirements beyond HIPAA.