Skip to content
compliancebase
HIPAATopics — PHI and ePHI Scope

PHI vs. ePHI

PHI and ePHI Scope

HIPAA · 45 CFR Part 164 · Last verified August 2026

Objective

Distinguish protected health information from its electronic subset so privacy obligations and Security Rule technical safeguards are applied to the correct data and media.

Points of focus

  • Identify health information linked to an individual
  • Trace when PHI is created, received, maintained, or transmitted electronically
  • Include nonproduction copies, metadata, and derived data in scope decisions

Implementation notes

Tag fields and events at ingestion, map derived and copied data through logs, support tools, analytics, and backups, and configure lower environments to use synthetic rather than live ePHI. Operationalize identify health information linked to an individual in ticketing, IdP, or GRC workflows with named owners — not only in a static policy PDF. Retain data classification standard with phi and ephi examples with reviewer identity, population scope, dates, and remediation outcomes auditors can sample. A recurring failure mode is that teams classify only diagnosis fields and overlook identifiers attached to service use Revisit after material architecture, vendor, data-flow, or leadership changes and document the decision.

Audit tip: Sample data classification standard with phi and ephi examples with dates and named reviewers. Be ready to walk through how you detect and correct: teams classify only diagnosis fields and overlook identifiers attached to service use

Evidence auditors typically request:

  • Data classification standard with PHI and ePHI examples
  • ePHI data-flow and storage inventory
  • Discovery scan or sampling results for logs and support systems

Common gaps

  • Teams classify only diagnosis fields and overlook identifiers attached to service use
  • Production is scoped but copied ePHI in tickets and analytics is not

Cross-Framework Mapping

FrameworkRequirementImplementation note
HIPAAPHI vs. ePHIThis control
SOC 2CC6.1, CC7.2SOC 2 evidence can support the safeguard, but HIPAA scope and Required/Addressable analysis remain distinct.
ISO 27001A.5.15, A.8.15ISO controls offer reusable operational evidence without replacing the Security Rule analysis.
GDPRArticle 32Article 32 overlaps for ePHI that is also EU personal data, subject to each law's scope.

Primary sources

Frequently Asked Questions

PHI and ePHI Scope applies to the systems and commitments in your Security Rule scope. Translate the requirement into concrete operating workflows — identify health information linked to an individual — with evidence stored where auditors and customers can sample it.

Lead with data classification standard with phi and ephi examples and pair it with ephi data-flow and storage inventory. Samples should show who performed the control, when, against which population, and what changed as a result.

Teams often fail because teams classify only diagnosis fields and overlook identifiers attached to service use Close the loop with dated operating records and test the control on a realistic production path.

Control operation can often be shared across SOC 2, ISO 27001, GDPR, and HIPAA — but each framework uses different vocabulary and accountability. Maintain an explicit crosswalk rather than assuming equivalence.

Review at least annually and after material product, vendor, or data-flow changes. High-risk or privileged paths may need quarterly sampling even when the criterion does not prescribe a cadence.

Framework versions referenced in this page:

  • HIPAA45 CFR Part 164

Last verified: August 2026 · Primary sources linked above