← All Glossary Pages

Glossary

What Is ePHI? Electronic Protected Health Information Explained

ePHI means protected health information that a covered entity or business associate creates, receives, maintains, or transmits in electronic form. It includes electronic patient information held in systems, devices, applications, and services. The HIPAA Security Rule protects its confidentiality, integrity, and availability through administrative, physical, and technical safeguards.

Last reviewed:

What does ePHI mean?

ePHI is protected health information (PHI) that is maintained in or transmitted by electronic media. Under the Security Rule, it covers electronic PHI handled by covered entities and business associates, including information in electronic health records, email, cloud services, imaging systems, and other systems used for healthcare operations.

The Security Rule focuses on electronic PHI. HHS distinguishes it from PHI kept only on paper or communicated orally; those forms may still be covered by the Privacy Rule, but they are outside the Security Rule’s ePHI scope.

Sources: HHS Summary of the HIPAA Security Rule

What information can be ePHI?

ePHI may include individually identifiable health information about a person’s health, care, or payment when a covered entity or business associate maintains or transmits it electronically. Examples can include diagnoses, treatment notes, appointment details, billing records, images, messages, and identifiers, but the exact scope depends on the information and the handling context.

The Privacy Rule defines PHI broadly as individually identifiable health information held or transmitted by a covered entity or business associate in any form or medium, subject to exclusions. The electronic form is what brings that subset into the Security Rule.

Sources: HHS Summary of the HIPAA Privacy Rule · HHS Summary of the HIPAA Security Rule

What safeguards protect ePHI under the HIPAA Security Rule?

Regulated entities must use reasonable and appropriate administrative, physical, and technical safeguards to protect ePHI. The Security Rule’s objectives include preserving confidentiality, integrity, and availability; protecting against reasonably anticipated threats and hazards; and preventing impermissible uses or disclosures. The safeguards should fit the entity’s environment and risks.

HHS describes the Security Rule as flexible, scalable, and technology neutral. A practice should examine the systems and workflows that handle its ePHI, then select and document safeguards that address the risks in that environment.

Sources: HHS Summary of the HIPAA Security Rule

How is ePHI different from PHI?

PHI can exist in electronic, paper, or oral form under the Privacy Rule. ePHI is the electronic subset protected by the Security Rule when it is created, received, maintained, or transmitted by a regulated entity. A practice therefore needs to consider both rules when information moves between electronic systems, paper workflows, and conversations.

A paper chart and an electronic health record may contain similar health information, but the rules apply through different scopes. The Security Rule addresses safeguards for the electronic form; the Privacy Rule addresses protected health information more broadly.

Sources: HHS Summary of the HIPAA Security Rule · HHS Summary of the HIPAA Privacy Rule

Frequently asked questions

Does ePHI include information stored by a cloud EHR?

Generally, yes. If a covered entity or business associate creates, receives, maintains, or transmits PHI through an electronic cloud service, that information falls within the ePHI scope of the Security Rule. The practice should also assess the cloud provider relationship and applicable contractual obligations.

Does the HIPAA Security Rule apply to paper records?

The Security Rule protects ePHI, the electronic subset of PHI. Paper and oral information may still be protected health information under the Privacy Rule, but paper-only records are not ePHI merely because they contain health information.