“Ephi” is almost always a typo for ePHI — electronic protected health information. ePHI is any individually identifiable health information that is created, stored, transmitted, or received in electronic form. The term comes from the HIPAA Security Rule, which sets national standards for protecting this data. If you have ever wondered what counts as ePHI and what does not, the answer is more specific than most people expect.
What Is ePHI in Healthcare? Definition and Examples
ePHI stands for electronic protected health information. It is a legal category, not a clinical one. The definition comes from the HIPAA Security Rule, which was published by the U.S. Department of Health and Human Services.
Under HIPAA, protected health information (PHI) is health data that can be linked to a specific person. It includes information about past, present, or future physical or mental health, the care a person received, or payment for that care. When that information is held or transmitted electronically, it becomes ePHI.
The word “electronic” covers more than most people assume. It includes data stored on servers, laptops, and phones. It also includes data sent by email, text message, or fax-to-computer systems. Any digital format counts.
Here is the part many people miss. ePHI is not limited to medical records. A billing spreadsheet, an appointment reminder text, or a photo of a wound taken on a work phone can all be ePHI if they identify a patient and relate to their health or care.
What counts as an identifier
HIPAA lists 18 identifiers that can turn health data into ePHI. These include:
- Name, address, and dates tied to a person (birth date, admission date, discharge date)
- Phone number, fax number, and email address
- Social Security number and medical record number
- Health plan beneficiary number and account number
- Device identifiers and serial numbers
- Web URLs, IP addresses, and full-face photos
- Any other unique code or characteristic that could identify someone
If health information includes even one of these identifiers and exists electronically, it is generally ePHI. Remove all 18 and the data is no longer considered ePHI. That process is called de-identification, and it has specific legal requirements.
What Are Examples of ePHI in Real Healthcare Settings?
ePHI shows up in far more places than a patient chart. The examples below reflect common clinical and administrative settings.
- Electronic health records (EHRs). A patient’s diagnosis, medication list, and lab results stored in a hospital system.
- Emails between clinicians. A doctor emailing a specialist about a named patient’s test results.
- Text messages. A nurse texting a colleague a patient’s room number and condition.
- Billing systems. Claims sent to an insurer that include a patient’s name, diagnosis code, and policy number.
- Wearable and remote monitoring data. Heart rate or glucose readings transmitted from a patient’s device to a clinic, if they identify the patient.
- Voicemails and call recordings. A recorded message that names a patient and describes their care.
- Photographs. A clinical image stored with a patient identifier attached.
One clarification worth making: not every health app or fitness tracker produces ePHI. If you use a consumer app on your own, outside a covered health plan or provider, that data usually falls outside HIPAA. The rules apply to covered entities and their business associates, not to you tracking your own steps.
Who Has to Protect ePHI Under HIPAA?
The HIPAA Security Rule applies to two main groups. The first is covered entities: health plans, most healthcare providers, and healthcare clearinghouses. The second is business associates — companies that handle ePHI on behalf of a covered entity, such as billing services, cloud storage vendors, and some IT contractors.
If you fall into either group, the Security Rule requires you to protect ePHI in three areas:
- Administrative safeguards. Policies, staff training, and risk assessments.
- Physical safeguards. Locked rooms, controlled access to servers, and device security.
- Technical safeguards. Access controls, encryption, audit logs, and automatic logoff.
Encryption deserves a note. The Security Rule does not mandate encryption in every case. It is one option for meeting the standard, described as “addressable” rather than strictly required. In practice, though, encryption matters a great deal. If encrypted ePHI is lost or stolen, it may not trigger the same breach notification requirements as unencrypted data. Many security professionals treat encryption as a baseline expectation even where the rule allows flexibility.
What Is the Difference Between PHI and ePHI?
PHI is the broader category. ePHI is a subset of PHI. The only difference is the format.
PHI covers health information in any form — paper records, spoken conversations, handwritten notes, and electronic files. ePHI is specifically the electronic version.
The distinction matters because different HIPAA rules apply to each. The Privacy Rule governs how PHI is used and disclosed in general. The Security Rule applies specifically to ePHI and focuses on how it is kept secure. A paper chart and a digital chart may hold the same information, but the digital one brings additional security obligations.
Here is a simple way to keep them straight. All ePHI is PHI. Not all PHI is ePHI.
Why Does ePHI Protection Matter?
Health data is among the most sensitive information a person has. A leaked diagnosis can affect a job, a relationship, or an insurance decision. That is why the rules around ePHI exist.
There is also a practical business reason. Breaches of ePHI can be costly. The HHS Office for Civil Rights investigates reported breaches and can issue fines. Reporting requirements mean that most breaches affecting a significant number of people must be publicly disclosed.
For patients, the takeaway is straightforward. When you share health information with a provider or insurer, federal rules require that the electronic version be safeguarded. You also have rights — including the right to request a copy of your records and to ask for certain restrictions on how your information is used.
For anyone working in healthcare, the takeaway is that ePHI is not just an IT concern. It is a shared responsibility that runs from the front desk to the server room.
How Is ePHI Different From Consumer Health Data?
This is where a lot of confusion lives. Many apps and devices collect health-related information. Most of them are not covered by HIPAA.
HIPAA applies to covered entities and their business associates. A general wellness app that you download on your own is usually not a covered entity. That means the data you enter may not be protected by HIPAA at all, even though it feels medical.
Some other laws may apply in certain situations, and some states have their own privacy rules. But the federal HIPAA protections that cover ePHI do not automatically extend to every health app on your phone.
This is a genuinely important distinction. It means the same heart rate reading could be protected in one setting and not in another, depending on who holds it and why.
What Are Common Misconceptions About ePHI?
A few myths come up often.
Myth: ePHI only means medical records. It is much broader. Billing data, appointment texts, and clinical photos can all qualify.
Myth: If data is not in a chart, it is not ePHI. Where the data lives does not decide the issue. Whether it identifies a patient and relates to their health does.
Myth: Deleted ePHI is gone. Deletion on a device does not always mean the data is unrecoverable, which is one reason proper data disposal procedures exist.
Myth: Only large hospitals need to worry. Small practices, solo providers, and business associates all carry obligations under the rules.
Understanding these points helps both patients and professionals avoid costly assumptions. The definition of ePHI is narrow in one sense — it must be electronic and identifiable — but wide in another, because it reaches into everyday tools like email and messaging.
Frequently Asked Questions
What does ePHI stand for in healthcare?
ePHI stands for electronic protected health information. It is any individually identifiable health data created, stored, or transmitted electronically, as defined by the HIPAA Security Rule.
What is an example of ePHI?
A patient’s diagnosis and medication list stored in an electronic health record is a common example. So is a clinician’s email about a named patient or a billing claim that includes a patient’s name and diagnosis code.
Is ePHI the same as PHI?
No. PHI is health information in any format, including paper and spoken words. ePHI is specifically the electronic version, so all ePHI is PHI but not all PHI is ePHI.
Does HIPAA protect health data in my fitness app?
Usually not. HIPAA applies to covered entities and their business associates, so a consumer app you use on your own typically falls outside its protections.

