Definition
ePHI is protected health information that is created, received, maintained, or transmitted in electronic form by a covered entity or business associate.
In practice
- A diagnostic image in a PACS, its backup copy, and an authorized support export may all require analysis.
- An API payload can be ePHI even when it is never written to a long-lived database.
Who this applies to
- Covered entities
- Business associates
- Engineering, IT, security, and operations teams handling electronic health information
What the rule asks for
- Identify systems and media that create, receive, maintain, or transmit ePHI.
- Protect confidentiality, integrity, and availability with administrative, physical, and technical safeguards.
- Include copies, exports, logs, backups, and hosted services in the analysis when they contain ePHI.
How teams put it into practice
- Build a data-flow inventory rather than relying on the primary database schema.
- Label ePHI paths through endpoints, queues, analytics, support tools, and disaster recovery.
- Apply retention and deletion decisions to all copies and derived operational records.
Common mistakes
- Excluding email, screenshots, logs, or mobile caches from the ePHI inventory.
- Confusing encryption with the complete Security Rule analysis.
- Failing to identify who can access ePHI in support and emergency workflows.
Questions that come up
Is ePHI different from PHI?
ePHI is the electronic subset of PHI. The distinction matters because the HIPAA Security Rule specifically addresses electronic protected health information.
References
- Security Rule HHS Office for Civil Rights