Electronic Media
Electronic media generally refers to devices and technologies that store or transmit information using electronic means. In common usage this includes things like television, radio, the internet, fax, and storage devices such as CDs and DVDs. Within HIPAA, the term has a narrower, specific regulatory meaning that differs from this general definition, so readers should verify the exact scope against the current HIPAA Security Rule text.
In general usage, electronic media are platforms or devices that use electronic or electromechanical means to store, distribute, or transmit information, encompassing formats such as radio, television, internet, fax, and storage media like CD-ROMs and DVDs. For HIPAA compliance purposes, note that 'electronic media' is a defined term under the HIPAA Administrative Simplification regulations and is central to the Security Rule's scope over electronic protected health information (ePHI); the regulatory definition is more specific than the general one presented in this evidence and typically covers electronic storage material and transmission media. Because the evidence packet here does not include the HIPAA regulatory text, practitioners should confirm the precise HIPAA definition and any applicable CFR citation against the current regulation before relying on it.
Why it matters
Within HIPAA, the term "electronic media" is not merely descriptive vocabulary; it is a defined term under the Administrative Simplification regulations and helps establish the scope of the HIPAA Security Rule. Because the Security Rule governs only electronic protected health information (ePHI), as distinct from the Privacy Rule, which covers PHI in all forms including oral and paper, understanding what qualifies as electronic media is foundational to determining which safeguards apply to a given piece of information. If information is created, received, maintained, or transmitted in electronic form, the Security Rule's administrative, physical, and technical safeguard requirements generally come into play.
The common, everyday meaning of "electronic media" (television, radio, internet, fax, CDs, DVDs) is broader and less precise than the meaning HIPAA assigns to the term. Compliance professionals who rely on the general definition risk either overstating or understating the reach of the Security Rule. For example, decisions about how portable storage devices, transmission channels, and disposal of media must be handled typically hinge on the specific regulatory scope rather than on the colloquial usage. Misjudging that scope can affect risk analysis, device and media controls, and breach determinations.
Because the evidence available here reflects general and legal-dictionary usage rather than the HIPAA regulatory text, practitioners should confirm the precise HIPAA definition and any applicable CFR citation against the current HIPAA Security Rule before relying on it. State law and the HITECH Act may also impose additional obligations beyond HIPAA, and HITRUST CSF controls addressing media handling are a private framework that does not by itself establish HIPAA compliance.
Who it's relevant to
Inside Electronic Media
Common questions
Answers to the questions practitioners most commonly ask about Electronic Media.