PHI vs. ePHI
PHI and ePHI Scope
HIPAA · 45 CFR Part 164 · Last verified August 2026
Objective
Distinguish protected health information from its electronic subset so privacy obligations and Security Rule technical safeguards are applied to the correct data and media.
Points of focus
- Identify health information linked to an individual
- Trace when PHI is created, received, maintained, or transmitted electronically
- Include nonproduction copies, metadata, and derived data in scope decisions
Implementation notes
Tag fields and events at ingestion, map derived and copied data through logs, support tools, analytics, and backups, and configure lower environments to use synthetic rather than live ePHI. Operationalize identify health information linked to an individual in ticketing, IdP, or GRC workflows with named owners — not only in a static policy PDF. Retain data classification standard with phi and ephi examples with reviewer identity, population scope, dates, and remediation outcomes auditors can sample. A recurring failure mode is that teams classify only diagnosis fields and overlook identifiers attached to service use Revisit after material architecture, vendor, data-flow, or leadership changes and document the decision.
Audit tip: Sample data classification standard with phi and ephi examples with dates and named reviewers. Be ready to walk through how you detect and correct: teams classify only diagnosis fields and overlook identifiers attached to service use
Evidence auditors typically request:
- Data classification standard with PHI and ePHI examples
- ePHI data-flow and storage inventory
- Discovery scan or sampling results for logs and support systems
Common gaps
- Teams classify only diagnosis fields and overlook identifiers attached to service use
- Production is scoped but copied ePHI in tickets and analytics is not
Cross-Framework Mapping
| Framework | Requirement | Implementation note |
|---|---|---|
| HIPAA | PHI vs. ePHI | This control |
| SOC 2 | CC6.1, CC7.2 | SOC 2 evidence can support the safeguard, but HIPAA scope and Required/Addressable analysis remain distinct. |
| ISO 27001 | A.5.15, A.8.15 | ISO controls offer reusable operational evidence without replacing the Security Rule analysis. |
| GDPR | Article 32 | Article 32 overlaps for ePHI that is also EU personal data, subject to each law's scope. |
Primary sources
- HHS HIPAA Security Rule: 45 CFR Part 164 — Security and Privacy Rules; topic: PHI vs. ePHI