Skip to content
2026

Now taking on 4 new clients this year — white-glove onboarding, month to month.

Book a call
HomeGlossaryElectronic Protected Health Information (ePHI)
Glossary

Electronic Protected Health Information (ePHI)

ePHI is individually identifiable health information that a HIPAA-covered organization or its vendor creates, stores, sends or receives in electronic form.

Definition

What is Electronic Protected Health Information?

Electronic Protected Health Information (ePHI) is protected health information that is created, received, stored, or transmitted in electronic form. Protected health information, under HIPAA, is any information about a person's health condition, the care they received, or the payment for that care that can be tied to the individual. When that information sits in an electronic health record, an email, a billing system, a scanned PDF, a text message, or a backup, it is ePHI, and the HIPAA Security Rule governs how it must be protected.

Information counts as identifiable when it includes or can be linked to details such as a name, a date of birth, an address, a phone number, a Social Security number, a medical record number, or a photograph. The rules apply to covered entities, meaning providers, health plans, and clearinghouses, and to their business associates: any vendor that handles ePHI on their behalf, including an IT provider, a cloud backup service, a billing company, or a transcription firm. Each of those vendors must sign a business associate agreement and meet the same safeguards.

In a small practice ePHI tends to spread further than anyone intends. It lives in the practice management system, but also in the front desk's email, in photos on a clinician's phone, in spreadsheets used to track referrals, in voicemail transcripts, and on the laptop a departed employee never returned. The Security Rule expects the practice to know where all of it is, to control who can reach it, to encrypt it where practical, to log access, and to be able to restore it after a failure. A breach of ePHI, including a ransomware event, triggers notification duties to patients and to the Department of Health and Human Services.

NetSys supports medical and dental practices in the New York area in locating and securing ePHI, using the controls already available in Microsoft 365 wherever possible: encryption of mail and files, conditional access, device management through Intune, and data loss prevention policies that catch a patient record sent to the wrong address. The HIPAA compliance service page describes the approach, and Joel Baum writes about the Security Rule and what it asks of a small practice.

Why it matters for a small business

If your business touches patient information in any digital form, ePHI rules apply to you, even if you are the IT vendor or the billing service rather than the clinic. Knowing where the data lives is the first and hardest step; most practices are surprised by how many places it turns up. The obligations that follow, from access controls to breach notification, are written in the HIPAA Security Rule, and enforcement actions against small providers have followed lost laptops and unencrypted email. Treating ePHI as a defined inventory rather than a vague category is what makes compliance manageable.

Common Questions

Electronic Protected Health Information (ePHI): FAQs

What counts as electronic protected health information under HIPAA?

Any information about a person's health, or the care and billing that go with it, when it can be linked to that person and exists in electronic form. That includes records in an EHR, emails mentioning a patient's condition, scanned intake forms, billing files, appointment reminders sent by text, and backups of all of the above. If the same information is de-identified, meaning names, dates of birth, addresses, and other identifiers have been removed under the HIPAA standard, it is no longer ePHI. Paper records are protected health information but fall outside the Security Rule.

Is email considered ePHI?

An email is ePHI whenever its contents identify a patient and say something about their health or their bills, which covers most messages a practice sends about a specific person. Sending such a message to an outside address without encryption is a common cause of reportable breaches. Microsoft 365 can encrypt messages automatically when they contain patient identifiers, and a data loss prevention policy can block the ones sent to the wrong recipient. Internal mail between staff in the same tenant is encrypted in transit by default.

Who is responsible for protecting ePHI, the practice or the IT company?

Both. The practice, as the covered entity, holds the primary obligation under HIPAA and must have a signed business associate agreement with any vendor that handles its ePHI. The IT company, as a business associate, is directly liable under the Security Rule for the safeguards it controls, such as backup encryption or administrator access. In practice the two divide the work in writing: the provider secures the systems, and the practice trains its staff and owns the risk analysis. Neither side can delegate its own duties away.

Reading this because of a questionnaire or a renewal?

Get the controls, not just the definition.

A NetSys engineer can tell you in fifteen minutes whether you have this covered, and what it would take if you do not. Month to month, no long-term contract.