Skip to content
compliancebase
HIPAA164.312 — Integrity of ePHI

§164.312(c)(1)

Integrity of ePHI

HIPAA · 45 CFR Part 164 · Last verified August 2026

Objective

Protect ePHI from improper alteration or destruction and use appropriate mechanisms to authenticate it where risk warrants.

Points of focus

  • Prevent unauthorized modification or deletion of ePHI
  • Detect integrity failures across storage and transfer
  • Apply authentication mechanisms based on risk

Implementation notes

Validate inbound records, constrain write paths through service identities, log before-and-after changes for sensitive fields, and verify integrity during backup restore and partner-file processing. Operationalize prevent unauthorized modification or deletion of ephi in ticketing, IdP, or GRC workflows with named owners — not only in a static policy PDF. Retain database authorization and change-audit evidence with reviewer identity, population scope, dates, and remediation outcomes auditors can sample. A recurring failure mode is that an integration can overwrite clinical data without validation or actor attribution Revisit after material architecture, vendor, data-flow, or leadership changes and document the decision.

Audit tip: Sample database authorization and change-audit evidence with dates and named reviewers. Be ready to walk through how you detect and correct: an integration can overwrite clinical data without validation or actor attribution

Evidence auditors typically request:

  • Database authorization and change-audit evidence
  • Checksums, signatures, or validation controls for ePHI exchange
  • Backup immutability and restore verification records

Common gaps

  • An integration can overwrite clinical data without validation or actor attribution
  • Backups complete successfully but restored records are never checked for integrity

Cross-Framework Mapping

FrameworkRequirementImplementation note
HIPAA§164.312(c)(1)This control
SOC 2CC6.1, CC7.2SOC 2 evidence can support the safeguard, but HIPAA scope and Required/Addressable analysis remain distinct.
ISO 27001A.5.15, A.8.15ISO controls offer reusable operational evidence without replacing the Security Rule analysis.
GDPRArticle 32Article 32 overlaps for ePHI that is also EU personal data, subject to each law's scope.

Primary sources

Frequently Asked Questions

Integrity of ePHI applies to the systems and commitments in your Security Rule scope. Translate the requirement into concrete operating workflows — prevent unauthorized modification or deletion of ephi — with evidence stored where auditors and customers can sample it.

Lead with database authorization and change-audit evidence and pair it with checksums, signatures, or validation controls for ephi exchange. Samples should show who performed the control, when, against which population, and what changed as a result.

Teams often fail because an integration can overwrite clinical data without validation or actor attribution Close the loop with dated operating records and test the control on a realistic production path.

Control operation can often be shared across SOC 2, ISO 27001, GDPR, and HIPAA — but each framework uses different vocabulary and accountability. Maintain an explicit crosswalk rather than assuming equivalence.

Review at least annually and after material product, vendor, or data-flow changes. High-risk or privileged paths may need quarterly sampling even when the criterion does not prescribe a cadence.

Framework versions referenced in this page:

  • HIPAA45 CFR Part 164

Last verified: August 2026 · Primary sources linked above