§164.312(c)(1)
Integrity of ePHI
HIPAA · 45 CFR Part 164 · Last verified August 2026
Objective
Protect ePHI from improper alteration or destruction and use appropriate mechanisms to authenticate it where risk warrants.
Points of focus
- Prevent unauthorized modification or deletion of ePHI
- Detect integrity failures across storage and transfer
- Apply authentication mechanisms based on risk
Implementation notes
Validate inbound records, constrain write paths through service identities, log before-and-after changes for sensitive fields, and verify integrity during backup restore and partner-file processing. Operationalize prevent unauthorized modification or deletion of ephi in ticketing, IdP, or GRC workflows with named owners — not only in a static policy PDF. Retain database authorization and change-audit evidence with reviewer identity, population scope, dates, and remediation outcomes auditors can sample. A recurring failure mode is that an integration can overwrite clinical data without validation or actor attribution Revisit after material architecture, vendor, data-flow, or leadership changes and document the decision.
Audit tip: Sample database authorization and change-audit evidence with dates and named reviewers. Be ready to walk through how you detect and correct: an integration can overwrite clinical data without validation or actor attribution
Evidence auditors typically request:
- Database authorization and change-audit evidence
- Checksums, signatures, or validation controls for ePHI exchange
- Backup immutability and restore verification records
Common gaps
- An integration can overwrite clinical data without validation or actor attribution
- Backups complete successfully but restored records are never checked for integrity
Cross-Framework Mapping
| Framework | Requirement | Implementation note |
|---|---|---|
| HIPAA | §164.312(c)(1) | This control |
| SOC 2 | CC6.1, CC7.2 | SOC 2 evidence can support the safeguard, but HIPAA scope and Required/Addressable analysis remain distinct. |
| ISO 27001 | A.5.15, A.8.15 | ISO controls offer reusable operational evidence without replacing the Security Rule analysis. |
| GDPR | Article 32 | Article 32 overlaps for ePHI that is also EU personal data, subject to each law's scope. |
Primary sources
- HHS HIPAA Security Rule: 45 CFR Part 164 — Security and Privacy Rules; topic: §164.312(c)(1)