{"@context":"https://schema.org","@type":"Article","headline":"Electronic protected health information","description":"Learn how ABA practices identify electronic protected health information, map its lifecycle, distinguish related data, and assign HIPAA safeguards.","url":"https://finnihealth.com/resources/glossary/electronic-protected-health-information","datePublished":"2026-08-14T00:00:00.000Z","dateModified":"2026-08-14T00:00:00.000Z","author":{"@type":"Organization","name":"Finni Health Editorial Team"},"publisher":{"@type":"Organization","name":"Finni Health","url":"https://www.finnihealth.com"},"isPartOf":{"@type":"CollectionPage","name":"ABA and Practice Operations Glossary","url":"https://www.finnihealth.com/resources/glossary"},"breadcrumb":{"@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Resources","item":"https://www.finnihealth.com/resources"},{"@type":"ListItem","position":2,"name":"Glossary","item":"https://www.finnihealth.com/resources/glossary"},{"@type":"ListItem","position":3,"name":"Electronic protected health information","item":"https://finnihealth.com/resources/glossary/electronic-protected-health-information"}]}}
Glossary term

Electronic protected health information

Learn how ABA practices identify electronic protected health information, map its lifecycle, distinguish related data, and assign HIPAA safeguards.

6
min read
Updated
August 13, 2026
Sources checked
August 13, 2026
· View sources
Also called

electronic PHI ePHI

What is Electronic protected health information (ePHI), and what should an ABA practice owner know before applying it? Electronic protected health information (ePHI) is protected health information that a HIPAA covered entity or business associate maintains in or transmits by electronic media. Classification depends on the information, identifiability, holder, role, and medium. Owners should map every ePHI location, flow, vendor, user, safeguard, retention rule, and incident route.

Editorial approval scope: The team checked current source fidelity, scope boundaries, dates, arithmetic, reader usefulness, practical workflow, and general-information limitations.

ePHI has four linked classification questions

The current HHS Security Rule page says the rule protects ePHI created, received, used, or maintained by a covered entity or business associate. Apply four questions to each data flow.

  1. Entity and role: Is the holder acting as a HIPAA covered entity, business associate, or subcontractor for this activity?
  2. Health-information content: Does the information concern health or condition, health care, or payment for care?
  3. Identifiability: Does it identify a person, or is there a reasonable basis to believe it can identify the person?
  4. Electronic medium: Is the resulting PHI maintained in or transmitted by electronic media?

The HHS Security Rule summary describes ePHI as the electronic subset of PHI. The Security Rule does not govern PHI maintained or transmitted only on paper or verbally, although the Privacy and Breach Notification Rules can cover PHI in those forms.

Health data is not automatically ePHI

Current 45 CFR 160.103 contains the operative definitions and exclusions. A name in a scheduling record can be ePHI when it is linked to the provision of ABA care. A diagnosis, authorization number, session note, payment record, or video may also qualify when the remaining definition is met. A code or indirect combination can identify a person even when a name is absent.

HIPAA coverage also depends on who holds the data and in what role. HHS's covered-entity guidance explains that a health care provider is a covered entity only if it conducts specified standard transactions electronically. Business associates perform certain functions or services involving PHI for a covered entity. An entity outside those definitions is outside HIPAA for that role, yet state health, consumer-health, biometric, contract, employment, education, and general privacy rules may still protect the information.

Selected statutory exclusions matter. For example, the PHI definition excludes certain FERPA education records and employment records held by a covered entity in its role as employer. Classify the actual record and holder rather than labeling an entire database by its filename.

Map the whole electronic lifecycle

An ABA practice may hold ePHI in:

  • EHRs, session-note tools, data-collection systems, assessments, treatment plans, and recordings.
  • scheduling, intake, referral, authorization, claims, remittance, payment, and patient-balance systems.
  • email, text, portals, telehealth, call recordings, support tickets, file shares, exports, and spreadsheets.
  • phones, tablets, laptops, printers with storage, removable media, local caches, and backups.
  • identity, access, audit, analytics, interface, transcription, AI, and vendor systems when records or metadata identify care.

For each location, record the data owner, purpose, source, fields, individuals, users, permissions, system, device, vendor, integration, geography, backups, retention, destruction, incident route, and applicable business associate agreement. Include copies created by export, testing, support, migration, and disaster recovery.

Cloud storage and encryption do not change the label

HHS cloud-computing guidance says a cloud service provider that creates, receives, maintains, or transmits ePHI on behalf of a covered entity or business associate is itself a business associate, even if it stores encrypted data without the key. The regulated customer and cloud provider need the required agreement and must meet the duties that apply to their roles.

Encryption is a safeguard. It does not convert ePHI into de-identified information or eliminate business associate status. A signed business associate agreement also does not certify a product, make every use permissible, or finish the customer's risk analysis.

De-identification uses a defined HIPAA method

The HHS de-identification guidance describes two HIPAA methods: a qualified expert's documented determination that identification risk is very small, or Safe Harbor removal of specified identifiers plus no actual knowledge that the remaining information can identify the person. Properly de-identified data is no longer PHI under HIPAA, though a small, nonzero reidentification risk remains and other law or contracts may apply.

Removing a name, replacing it with a client ID, redacting a screenshot, or calling a record “synthetic” does not by itself meet either method. Purpose-built fictional data containing no real client information starts from a different provenance. Record how test and analytics data was created, who approved its use, and which restrictions remain.

Safeguards protect confidentiality, integrity, and availability

For regulated entities, the Security Rule requires reasonable and appropriate administrative, physical, and technical safeguards. A practice should connect its ePHI inventory to risk analysis, access authorization, authentication, audit controls, transmission security, device and media controls, backups, incident response, contingency plans, workforce training, and periodic evaluation.

Privacy and security answer different questions. Security protects the electronic information. Privacy rules govern permitted uses, disclosures, and individual rights. Clinical-record, payer, state, and professional requirements can add duties. Keep each source, owner, and decision path explicit.

A fictional inventory finds two missed systems

A fictional ABA practice reviews 12 systems. Its first inventory classifies nine as containing or using ePHI. Testing then finds identifiable portal screenshots in the support-ticket system and a transcription cache holding session audio, bringing the ePHI-system count to 11 of 12.

Nine of those 11 systems have a verified data owner, vendor role, agreement status, access map, retention rule, backup path, and incident route. Mapping completeness is 9 of 11, or 81.8%. The two incomplete systems stay open with owners and deadlines.

The twelfth system is a dedicated payroll application containing only workforce employment records held by the practice in its employer role. The practice records that classification and separately applies employment, security, contract, and state requirements. These results describe one inventory. They do not prove HIPAA compliance or establish that no additional copies exist.

Measures should retain unknown systems and data

Useful controls include:

  • systems classified by data and role divided by systems in the locked inventory.
  • ePHI systems with complete lifecycle maps divided by ePHI systems identified.
  • vendors with documented role and current agreement decision divided by vendors reviewed.
  • authorized accounts reviewed by deadline divided by accounts due for review.
  • tested ePHI flows matching the approved destination and fields divided by flows tested.
  • unknown stores, unapproved exports, and overdue remediation by count, severity, owner, and age.

Define the system, data flow, entity role, cutoff, source, numerator, denominator, exclusions, and evidence. Report unknowns separately. A high mapping percentage cannot repair a classification error or an inventory that omitted shadow systems.

Related terms

Sources

Beyond the glossary

Take the next step with clarity

Whether you are finding care, growing as a clinician, or building a stronger ABA practice, Finni brings the people, tools, and support together to help you move forward.

Start or grow your ABA practice with Finni