What is Electronic protected health information (ePHI), and what should an ABA practice owner know before applying it? Electronic protected health information (ePHI) is protected health information that a HIPAA covered entity or business associate maintains in or transmits by electronic media. Classification depends on the information, identifiability, holder, role, and medium. Owners should map every ePHI location, flow, vendor, user, safeguard, retention rule, and incident route.
Editorial approval scope: The team checked current source fidelity, scope boundaries, dates, arithmetic, reader usefulness, practical workflow, and general-information limitations.
ePHI has four linked classification questions
The current HHS Security Rule page says the rule protects ePHI created, received, used, or maintained by a covered entity or business associate. Apply four questions to each data flow.
- Entity and role: Is the holder acting as a HIPAA covered entity, business associate, or subcontractor for this activity?
- Health-information content: Does the information concern health or condition, health care, or payment for care?
- Identifiability: Does it identify a person, or is there a reasonable basis to believe it can identify the person?
- Electronic medium: Is the resulting PHI maintained in or transmitted by electronic media?
The HHS Security Rule summary describes ePHI as the electronic subset of PHI. The Security Rule does not govern PHI maintained or transmitted only on paper or verbally, although the Privacy and Breach Notification Rules can cover PHI in those forms.
Health data is not automatically ePHI
Current 45 CFR 160.103 contains the operative definitions and exclusions. A name in a scheduling record can be ePHI when it is linked to the provision of ABA care. A diagnosis, authorization number, session note, payment record, or video may also qualify when the remaining definition is met. A code or indirect combination can identify a person even when a name is absent.
HIPAA coverage also depends on who holds the data and in what role. HHS's covered-entity guidance explains that a health care provider is a covered entity only if it conducts specified standard transactions electronically. Business associates perform certain functions or services involving PHI for a covered entity. An entity outside those definitions is outside HIPAA for that role, yet state health, consumer-health, biometric, contract, employment, education, and general privacy rules may still protect the information.
Selected statutory exclusions matter. For example, the PHI definition excludes certain FERPA education records and employment records held by a covered entity in its role as employer. Classify the actual record and holder rather than labeling an entire database by its filename.
Map the whole electronic lifecycle
An ABA practice may hold ePHI in:
- EHRs, session-note tools, data-collection systems, assessments, treatment plans, and recordings.
- scheduling, intake, referral, authorization, claims, remittance, payment, and patient-balance systems.
- email, text, portals, telehealth, call recordings, support tickets, file shares, exports, and spreadsheets.
- phones, tablets, laptops, printers with storage, removable media, local caches, and backups.
- identity, access, audit, analytics, interface, transcription, AI, and vendor systems when records or metadata identify care.
For each location, record the data owner, purpose, source, fields, individuals, users, permissions, system, device, vendor, integration, geography, backups, retention, destruction, incident route, and applicable business associate agreement. Include copies created by export, testing, support, migration, and disaster recovery.
Cloud storage and encryption do not change the label
HHS cloud-computing guidance says a cloud service provider that creates, receives, maintains, or transmits ePHI on behalf of a covered entity or business associate is itself a business associate, even if it stores encrypted data without the key. The regulated customer and cloud provider need the required agreement and must meet the duties that apply to their roles.
Encryption is a safeguard. It does not convert ePHI into de-identified information or eliminate business associate status. A signed business associate agreement also does not certify a product, make every use permissible, or finish the customer's risk analysis.
De-identification uses a defined HIPAA method
The HHS de-identification guidance describes two HIPAA methods: a qualified expert's documented determination that identification risk is very small, or Safe Harbor removal of specified identifiers plus no actual knowledge that the remaining information can identify the person. Properly de-identified data is no longer PHI under HIPAA, though a small, nonzero reidentification risk remains and other law or contracts may apply.
Removing a name, replacing it with a client ID, redacting a screenshot, or calling a record “synthetic” does not by itself meet either method. Purpose-built fictional data containing no real client information starts from a different provenance. Record how test and analytics data was created, who approved its use, and which restrictions remain.
Safeguards protect confidentiality, integrity, and availability
For regulated entities, the Security Rule requires reasonable and appropriate administrative, physical, and technical safeguards. A practice should connect its ePHI inventory to risk analysis, access authorization, authentication, audit controls, transmission security, device and media controls, backups, incident response, contingency plans, workforce training, and periodic evaluation.
Privacy and security answer different questions. Security protects the electronic information. Privacy rules govern permitted uses, disclosures, and individual rights. Clinical-record, payer, state, and professional requirements can add duties. Keep each source, owner, and decision path explicit.
A fictional inventory finds two missed systems
A fictional ABA practice reviews 12 systems. Its first inventory classifies nine as containing or using ePHI. Testing then finds identifiable portal screenshots in the support-ticket system and a transcription cache holding session audio, bringing the ePHI-system count to 11 of 12.
Nine of those 11 systems have a verified data owner, vendor role, agreement status, access map, retention rule, backup path, and incident route. Mapping completeness is 9 of 11, or 81.8%. The two incomplete systems stay open with owners and deadlines.
The twelfth system is a dedicated payroll application containing only workforce employment records held by the practice in its employer role. The practice records that classification and separately applies employment, security, contract, and state requirements. These results describe one inventory. They do not prove HIPAA compliance or establish that no additional copies exist.
Measures should retain unknown systems and data
Useful controls include:
- systems classified by data and role divided by systems in the locked inventory.
- ePHI systems with complete lifecycle maps divided by ePHI systems identified.
- vendors with documented role and current agreement decision divided by vendors reviewed.
- authorized accounts reviewed by deadline divided by accounts due for review.
- tested ePHI flows matching the approved destination and fields divided by flows tested.
- unknown stores, unapproved exports, and overdue remediation by count, severity, owner, and age.
Define the system, data flow, entity role, cutoff, source, numerator, denominator, exclusions, and evidence. Report unknowns separately. A high mapping percentage cannot repair a classification error or an inventory that omitted shadow systems.
Related terms
Sources
- U.S. Department of Health and Human Services, The Security Rule
- U.S. Department of Health and Human Services, Summary of the HIPAA Security Rule
- Electronic Code of Federal Regulations, 45 CFR 160.103 Definitions
- U.S. Department of Health and Human Services, Covered Entities and Business Associates
- U.S. Department of Health and Human Services, Guidance on HIPAA and Cloud Computing
- U.S. Department of Health and Human Services, Guidance Regarding Methods for De-identification of PHI
Take the next step with clarity
Whether you are finding care, growing as a clinician, or building a stronger ABA practice, Finni brings the people, tools, and support together to help you move forward.
Start or grow your ABA practice with Finni