Glossary

What is ePHI?

Electronic protected health information is protected health information that is transmitted or maintained in electronic media, and it is the specific category the HIPAA Security Rule applies to.

ePHI is not a different kind of information. It is the same protected health information, distinguished by where it lives, and the distinction exists so that one set of rules can be written about hard drives, networks and access controls rather than about filing cabinets. The Privacy Rule governs PHI in any medium. The Security Rule governs this subset.

The Security Rule’s general requirement is short and worth reading once: confidentiality, integrity and availability of all ePHI a covered entity or business associate creates, receives, maintains or transmits. Availability sits in there alongside confidentiality, which is the half most security conversations skip — a system nobody can get into during an incident has failed the standard too.

Below that requirement, the specifications are marked either "required" or "addressable", and the difference is routinely misreported. Required means implement it. Addressable means assess whether it is reasonable and appropriate in your environment and, if it is not, document why and implement an equivalent alternative. Encryption of ePHI is addressable, not required. That is not a licence to skip it — it is why "we use encryption" answers a narrower question than the person asking usually intends.

Two specifications are worth naming because they are the ones consumer messaging tools cannot satisfy at all. Unique user identification is required: every person touching ePHI needs their own identity in the system. Audit controls are a standard in their own right: the system must record and examine activity. A thread on a personal phone has neither.

In an ABA clinic specifically.

Every parent update, photo, daily note and internal handover message in an ABA clinic is ePHI the moment it is typed. That is what puts audit controls, unique logins and the ability to revoke a departing technician’s access into scope — and what a group chat, however encrypted, structurally cannot provide.

Questions people ask about ePHI.

What does ePHI mean?

Electronic protected health information: protected health information that is transmitted by, or maintained in, electronic media. It is defined by cross-reference in 45 CFR 160.103 and it is the category the HIPAA Security Rule at 45 CFR Part 164 Subpart C applies to.

Does HIPAA require encryption of ePHI?

Not outright. Encryption appears in the Security Rule as an addressable implementation specification, both for data at rest and for transmission security. Addressable means you must assess whether it is reasonable and appropriate, implement it if it is, and if it is not, document that reasoning and put an equivalent alternative in place. In practice, for a clinic sending child updates over the public internet in 2026, there is no defensible analysis that lands on "not appropriate".

Is a text message ePHI?

If it contains protected health information, yes — it is PHI in electronic form. That brings the Security Rule with it: access control, unique user identification, audit controls, and a way to remove access. Ordinary SMS provides none of those to your practice, and the carrier is not your business associate.

Are push notifications ePHI?

The payload is, if it contains anything identifying plus anything clinical. This is a real and commonly missed exposure, because a notification is rendered on a lock screen by the operating system and passes through a third-party delivery service on the way. The safe pattern is a payload that says a message is waiting and nothing about who or what, with the content fetched only after the recipient authenticates.

What are the technical safeguards for ePHI?

Five standards at 45 CFR 164.312: access control, audit controls, integrity, person or entity authentication, and transmission security. Within them, unique user identification and an emergency access procedure are required; automatic logoff, encryption and decryption, integrity controls and transmission encryption are addressable. Audit controls and authentication are standards with no optional wording at all.

Written by Abdihafid, a behavior technician working in an in-person ABA clinic. This is a plain-language explanation for people evaluating software, not legal advice, and it is not a substitute for your own compliance counsel.

Other terms

Sources

The definitions on this page are quoted from the regulation itself rather than from a summary of it, linked below with the date we last read them there. This is a plain-language explanation for people evaluating software, not legal advice.

  1. [1] 45 CFR 160.103Definitions — “Electronic protected health information” · checked August 31, 2026
  2. [2] 45 CFR 164.306Security standards: General rules, paragraph (a)(1) · checked August 31, 2026
  3. [3] 45 CFR 164.312Technical safeguards, paragraph (e)(2)(ii) · checked August 31, 2026
  4. [4] 45 CFR 164.312Technical safeguards, paragraph (b) · checked August 31, 2026

Show us what you are using now.

Fifteen minutes. If what you have works for your caseload, we will tell you to keep it.