Electronic Protected Health Information
Electronic Protected Health Information (ePHI) is protected health information that exists in electronic form, for example, health data that is created, received, stored, or sent using computers, networks, or other digital systems. It is generally the subset of protected health information that a HIPAA covered entity or business associate maintains or transmits electronically. Because ePHI is specifically electronic, it falls under the scope of the HIPAA Security Rule, which is the rule that addresses safeguards for health information in electronic form.
ePHI refers to information that comes within paragraphs (1)(i) or (1)(ii) of the regulatory definition of protected health information and that is created, received, maintained, or transmitted in electronic form by a HIPAA covered entity or business associate. As of the applicable regulatory text, ePHI is the category of PHI governed by the HIPAA Security Rule, which requires administrative, physical, and technical safeguards to protect its confidentiality, integrity, and availability; PHI in oral or paper form is outside the Security Rule's scope and is instead addressed by the HIPAA Privacy Rule. In related contexts, electronic health information (EHI) is considered ePHI to the extent it would be included in a designated record set. Practitioners should confirm the precise definitional cross-references and safeguard obligations against the current regulation, and note that the HITECH Act and state law may impose additional requirements.
Why it matters
Electronic Protected Health Information is the specific category of health information that triggers the HIPAA Security Rule. Because so much health data today is created, received, stored, or transmitted through computers, networks, and other digital systems, ePHI generally represents the bulk of the sensitive information that covered entities and business associates handle. Identifying what qualifies as ePHI is therefore the starting point for scoping an organization's Security Rule obligations, if data is not electronic PHI, the Security Rule's administrative, physical, and technical safeguards do not apply to it, though the Privacy Rule may still govern it in other forms.
Getting the boundaries of ePHI right matters because misclassifying data can leave gaps in a compliance program. Health information in oral or paper form falls outside the Security Rule and is instead addressed by the Privacy Rule, so organizations that treat all PHI identically may over- or under-invest their safeguards. Conversely, data that is created, received, maintained, or transmitted electronically by a covered entity or business associate, including electronic health information to the extent it would be included in a designated record set, falls squarely within Security Rule scope and must be protected for confidentiality, integrity, and availability.
Practitioners should also remember that the HITECH Act and state law may impose additional requirements beyond the HIPAA Security Rule, and that meeting a particular technical control does not by itself guarantee compliance or prevent all breaches. Because definitional cross-references and safeguard obligations can change, the precise scope of ePHI in any given situation should be confirmed against the current regulation rather than assumed from general summaries.
Who it's relevant to
Inside ePHI
Common questions
Answers to the questions practitioners most commonly ask about ePHI.