{"id":826,"date":"2026-08-17T04:39:54","date_gmt":"2026-08-17T04:39:54","guid":{"rendered":"https:\/\/www.osto.one\/resources\/?p=826"},"modified":"2026-08-17T04:39:54","modified_gmt":"2026-08-17T04:39:54","slug":"ephi","status":"publish","type":"post","link":"https:\/\/www.osto.one\/resources\/glossary\/ephi\/","title":{"rendered":"ePHI: Where Electronic Health Data Hides"},"content":{"rendered":"\n<!-- =========================================================================\n     OSTO GLOSSARY: ePHI\n     Shared glossary design system. Paste into one Custom HTML block. No H1.\n     ========================================================================= -->\n\n<style>\n.og{\n  --navy:#1c267a; --text:#0f1538; --muted:#0f1538; --light:#0f1538;\n  --border:#e7e9f2; --divider:#eceef5; --white:#ffffff;\n\n  --peri-50:#f4f5fd;  --peri-100:#e9ecfa; --peri-200:#cfd5f2; --peri-700:#4a52a8;\n  --sage-50:#f2f8f5;  --sage-100:#e3f0e9; --sage-200:#c3ddce; --sage-700:#3a6f5d;\n  --apri-50:#fdf6f0;  --apri-100:#fbe9dc; --apri-200:#f2cdb2; --apri-700:#a2603a;\n  --plum-50:#f8f3f9;  --plum-100:#f0e6f3; --plum-200:#dcc6e2; --plum-700:#6b4576;\n  --sky-50:#f1f7fb;   --sky-100:#e2eff7;  --sky-200:#bfd9e9;  --sky-700:#2f6a89;\n\n  --shadow:0 6px 22px rgba(15,21,56,.05);\n  --font:'Inter',-apple-system,BlinkMacSystemFont,'Segoe UI',Roboto,sans-serif;\n  font-family:var(--font); font-size:17px; line-height:1.75; color:var(--text);\n}\n.og p{margin:0 0 22px}\n.og h2{font-family:var(--font);font-size:clamp(25px,3vw,31px);font-weight:700;line-height:1.25;letter-spacing:-.5px;color:var(--navy);margin:52px 0 8px;scroll-margin-top:92px}\n.og h2::after{content:\"\";display:block;width:46px;height:5px;border-radius:3px;margin:12px 0 18px;background:var(--peri-200)}\n.og h2.c-sage::after{background:var(--sage-200)}\n.og h2.c-apri::after{background:var(--apri-200)}\n.og h2.c-plum::after{background:var(--plum-200)}\n.og h2.c-sky::after{background:var(--sky-200)}\n.og ul,.og ol{padding-left:22px;margin:0 0 24px}\n.og li{margin-bottom:9px}\n.og strong{font-weight:600}\n\n.og .dek{font-size:20px;line-height:1.6;color:var(--muted);margin:0 0 18px}\n.og .tags{margin:0 0 30px;padding:0;list-style:none;display:flex;flex-wrap:wrap;gap:8px}\n.og .tags li{margin:0}\n.og .tag{display:inline-block;font-size:12px;font-weight:600;letter-spacing:.7px;text-transform:uppercase;padding:6px 13px;border-radius:20px}\n.og .t-peri{background:var(--peri-100);color:var(--peri-700)}\n.og .t-sage{background:var(--sage-100);color:var(--sage-700)}\n\n.og .short{background:linear-gradient(135deg,var(--peri-100) 0%,var(--sage-100) 100%);border-radius:22px;padding:28px 32px;margin:0 0 30px}\n.og .short .k{font-size:13px;font-weight:700;letter-spacing:1.4px;text-transform:uppercase;color:var(--peri-700);margin:0 0 10px}\n.og .short p{font-size:19px;line-height:1.65;margin:0;color:var(--text)}\n\n.og .toc{background:var(--peri-50);border-radius:20px;padding:24px 28px;margin:0 0 34px}\n.og .toc .k{font-size:12px;font-weight:700;letter-spacing:1.3px;text-transform:uppercase;color:var(--peri-700);margin:0 0 12px}\n.og .toc ol{margin:0;padding-left:20px;columns:2;column-gap:34px}\n.og .toc li{margin-bottom:8px;break-inside:avoid;font-size:16px}\n.og .toc a{color:var(--navy);text-decoration:none;border-bottom:1px solid rgba(28,38,122,.22)}\n\n.og .callout{border-radius:4px;padding:24px 28px;margin:0 0 30px;background:var(--white);border:2px solid var(--navy)}\n.og .callout .k{font-weight:700;font-size:17px;margin:0 0 8px;color:var(--navy)}\n.og .callout p:last-child{margin-bottom:0}\n.og .callout.c-plum{background:var(--plum-50);border:none;border-radius:20px}\n.og .callout.c-plum .k{color:var(--plum-700)}\n\n.og figure{margin:0 0 30px}\n.og .sx{overflow-x:auto;-webkit-overflow-scrolling:touch;border-radius:20px;background:var(--white);box-shadow:var(--shadow)}\n.og .sx svg{display:block;width:100%;height:auto;min-width:600px}\n.og figcaption{font-size:14px;line-height:1.6;color:var(--muted);margin-top:12px}\n.og .swipe{display:none}\n\n.og table{width:100%;border-collapse:collapse;margin:0 0 28px;font-size:15px;background:var(--white);border-radius:18px;overflow:hidden;box-shadow:var(--shadow)}\n.og th{text-align:left;padding:14px 16px;font-weight:700;font-size:12.5px;letter-spacing:.8px;text-transform:uppercase}\n.og td{border-bottom:1px solid var(--divider);padding:13px 16px;vertical-align:top;line-height:1.6}\n.og tr:last-child td{border-bottom:none}\n.og .h-peri th{background:var(--peri-100);color:var(--peri-700)}\n.og .h-sage th{background:var(--sage-100);color:var(--sage-700)}\n.og .h-plum th{background:var(--plum-100);color:var(--plum-700)}\n\n.og .trio{display:grid;grid-template-columns:repeat(3,1fr);gap:14px;margin:0 0 28px}\n.og .tcard{border-radius:18px;padding:20px 22px}\n.og .tcard .n{font-size:16px;font-weight:700;margin:0 0 4px}\n.og .tcard .g{font-size:13px;font-weight:600;margin:0 0 10px;opacity:.8}\n.og .tcard p{font-size:14px;line-height:1.55;margin:0;color:var(--muted)}\n.og .tcard.a{background:var(--sky-50)}   .og .tcard.a .n,.og .tcard.a .g{color:var(--sky-700)}\n.og .tcard.b{background:var(--sage-50)}  .og .tcard.b .n,.og .tcard.b .g{color:var(--sage-700)}\n.og .tcard.c{background:var(--plum-50)}  .og .tcard.c .n,.og .tcard.c .g{color:var(--plum-700)}\n\n.og .pill{display:inline-block;font-size:11px;font-weight:700;letter-spacing:.8px;text-transform:uppercase;padding:5px 11px;border-radius:20px;white-space:nowrap}\n.og .p-req{background:var(--plum-200);color:#4d2f57}\n.og .p-exp{background:var(--sky-100);color:var(--sky-700)}\n.og .p-imp{background:#eef0f4;color:var(--muted)}\n.og .p-ask{background:var(--apri-100);color:var(--apri-700)}\n\n.og details{background:var(--white);border-radius:14px;margin:0 0 10px;box-shadow:0 2px 10px rgba(15,21,56,.04)}\n.og summary{cursor:pointer;padding:16px 20px;font-weight:600;font-size:17px;color:var(--navy);list-style:none;display:flex;justify-content:space-between;gap:16px;align-items:flex-start}\n.og summary::-webkit-details-marker{display:none}\n.og summary::after{content:\"+\";font-size:22px;line-height:1;color:var(--peri-700);flex:0 0 auto}\n.og details[open] summary::after{content:\"\\2013\"}\n.og details p{padding:0 20px 18px;margin:0;font-size:16px;line-height:1.7}\n\n.og .related{font-size:15px;color:var(--muted);border-top:1px solid var(--divider);padding-top:22px;margin-top:40px}\n\n@media(max-width:700px){\n  .og{font-size:16px}\n  .og .dek{font-size:18px}\n  .og .short p{font-size:17px}\n  .og .short,.og .toc,.og .callout{padding:22px 20px}\n  .og .toc ol{columns:1}\n  .og .trio{grid-template-columns:1fr}\n  .og .swipe{display:inline;font-weight:600;color:var(--peri-700)}\n  .og table{font-size:14px}\n  .og th,.og td{padding:11px 12px}\n}\n<\/style>\n\n<div class=\"og\">\n\n<p class=\"dek\">ePHI is protected health information in electronic form. It is the only category the HIPAA Security Rule applies to, which makes it the engineering team&#8217;s problem.<\/p>\n\n<ul class=\"tags\">\n  <li><span class=\"tag t-peri\">Glossary<\/span><\/li>\n  <li><span class=\"tag t-sage\">HIPAA<\/span><\/li>\n<\/ul>\n\n<div class=\"short\">\n  <p class=\"k\">The short answer<\/p>\n  <p>ePHI stands for electronic protected health information: any PHI that is created, received, stored or transmitted in electronic form. Paper charts and spoken conversations are PHI but not ePHI. The distinction matters because the Privacy Rule covers all PHI in any form, while the Security Rule with its technical, physical and administrative safeguards applies specifically to ePHI.<\/p>\n<\/div>\n\n<p>For a software company the practical consequence is simple. Almost everything you touch is ePHI, and almost every Security Rule obligation lands on your infrastructure.<\/p>\n\n<div class=\"toc\">\n  <p class=\"k\">On this page<\/p>\n  <ol>\n    <li><a href=\"#subset\">Where ePHI sits inside PHI<\/a><\/li>\n    <li><a href=\"#lives\">Where ePHI actually lives<\/a><\/li>\n    <li><a href=\"#obligations\">What holding ePHI obliges you to do<\/a><\/li>\n    <li><a href=\"#mistakes\">Where teams lose track of it<\/a><\/li>\n    <li><a href=\"#osto\">How Osto secures ePHI<\/a><\/li>\n    <li><a href=\"#faq\">FAQ<\/a><\/li>\n  <\/ol>\n<\/div>\n\n<h2 id=\"subset\">Where ePHI sits inside PHI<\/h2>\n\n<figure>\n<div class=\"sx\">\n<svg viewBox=\"0 0 760 240\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" role=\"img\" aria-label=\"ePHI is a subset of PHI; the Privacy Rule covers all PHI while the Security Rule covers only ePHI.\">\n  <rect x=\"120\" y=\"34\" width=\"520\" height=\"150\" rx=\"20\" fill=\"#e9ecfa\"\/>\n  <text x=\"380\" y=\"62\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"14\" font-weight=\"700\" fill=\"#4a52a8\">PHI, in any form<\/text>\n  <text x=\"228\" y=\"94\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" fill=\"#0f1538\">Paper charts<\/text>\n  <text x=\"228\" y=\"116\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" fill=\"#0f1538\">Spoken conversations<\/text>\n  <text x=\"228\" y=\"138\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" fill=\"#0f1538\">Printed reports<\/text>\n\n  <rect x=\"330\" y=\"76\" width=\"286\" height=\"92\" rx=\"16\" fill=\"#1c267a\"\/>\n  <text x=\"473\" y=\"104\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"14\" font-weight=\"700\" fill=\"#ffffff\">ePHI<\/text>\n  <text x=\"473\" y=\"128\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" fill=\"#b9c1e6\">Databases, backups, logs, email,<\/text>\n  <text x=\"473\" y=\"146\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" fill=\"#b9c1e6\">laptops, cloud storage, messages<\/text>\n\n  <rect x=\"120\" y=\"198\" width=\"252\" height=\"30\" rx=\"9\" fill=\"#e3f0e9\"\/>\n  <text x=\"246\" y=\"218\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12\" font-weight=\"700\" fill=\"#3a6f5d\">Privacy Rule covers all of it<\/text>\n  <rect x=\"388\" y=\"198\" width=\"252\" height=\"30\" rx=\"9\" fill=\"#dfe3f5\"\/>\n  <text x=\"514\" y=\"218\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12\" font-weight=\"700\" fill=\"#1c267a\">Security Rule covers only ePHI<\/text>\n<\/svg>\n<\/div>\n<figcaption><span class=\"swipe\">Swipe to see the full diagram. <\/span>All ePHI is PHI. Not all PHI is ePHI.<\/figcaption>\n<\/figure>\n\n<h2 id=\"lives\" class=\"c-sage\">Where ePHI actually lives<\/h2>\n\n<p>The production database is the obvious place. The rest is where audits find problems.<\/p>\n\n<table class=\"h-sage\">\n  <thead>\n    <tr><th>Location<\/th><th>Why it gets missed<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td>Application and access logs<\/td><td>Written automatically, rarely reviewed, often retained far longer than the data itself<\/td><\/tr>\n    <tr><td>Database backups and snapshots<\/td><td>Copied to buckets that inherit different permissions from the primary<\/td><\/tr>\n    <tr><td>Support tickets and shared inboxes<\/td><td>Patients paste details in freely, and the help desk is rarely in scope documents<\/td><\/tr>\n    <tr><td>Chat tools and screenshots<\/td><td>An engineer pastes a record into a channel to debug it, and it stays there<\/td><\/tr>\n    <tr><td>Local machines and downloads<\/td><td>A CSV export for analysis lands in a downloads folder and is never removed<\/td><\/tr>\n    <tr><td>Non-production environments<\/td><td>Staging seeded from a production dump, with weaker access control<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<div class=\"callout\">\n  <p class=\"k\">Scope is defined by where the data is, not where you meant it to be<\/p>\n  <p>An inventory of ePHI locations is the first deliverable of a Security Rule <a href=\"https:\/\/www.osto.one\/resources\/glossary\/information-security-risk-assessment\/\">risk analysis<\/a>. You cannot protect a copy you have not found, and investigators will ask specifically about backups, logs and test data.<\/p>\n<\/div>\n\n<h2 id=\"obligations\" class=\"c-apri\">What holding ePHI obliges you to do<\/h2>\n\n<div class=\"trio\">\n  <div class=\"tcard a\">\n    <p class=\"n\">Three safeguard families<\/p>\n    <p><a href=\"https:\/\/www.osto.one\/resources\/glossary\/administrative-safeguards\/\">Administrative<\/a>, <a href=\"https:\/\/www.osto.one\/resources\/glossary\/physical-safeguards\/\">physical<\/a> and <a href=\"https:\/\/www.osto.one\/resources\/glossary\/technical-safeguards\/\">technical<\/a> controls, each with its own standards.<\/p>\n  <\/div>\n  <div class=\"tcard b\">\n    <p class=\"n\">A documented risk analysis<\/p>\n    <p>Required, not optional. It drives which addressable specifications you implement and how.<\/p>\n  <\/div>\n  <div class=\"tcard c\">\n    <p class=\"n\">Agreements down the chain<\/p>\n    <p>Every vendor that touches ePHI needs a <a href=\"https:\/\/www.osto.one\/resources\/glossary\/business-associate-agreement\/\">BAA<\/a>, including your subcontractors.<\/p>\n  <\/div>\n<\/div>\n\n<h2 id=\"mistakes\" class=\"c-plum\">Where teams lose track of it<\/h2>\n\n<table class=\"h-peri\">\n  <thead>\n    <tr><th>Pattern<\/th><th>Fix<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td>Logs capturing request bodies containing patient records<\/td><td>Redact at the logging layer, not after the fact<\/td><\/tr>\n    <tr><td>Production data copied into staging for realistic testing<\/td><td>Synthetic or de-identified fixtures instead<\/td><\/tr>\n    <tr><td>Analytics or monitoring vendors receiving identifiers<\/td><td>Confirm coverage under a BAA, or stop sending the field<\/td><\/tr>\n    <tr><td>Old backups outside the retention policy<\/td><td>Enforce lifecycle expiry on the bucket, not by memory<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<h2 id=\"osto\">How Osto secures ePHI<\/h2>\n\n<p>The Security Rule asks for controls that are ordinary engineering practice done properly. Osto runs them: <a href=\"https:\/\/www.osto.one\/resources\/glossary\/mfa\/\">authentication and access control<\/a>, <a href=\"https:\/\/www.osto.one\/resources\/glossary\/encryption-at-rest-and-in-transit\/\">encryption at rest and in transit<\/a>, <a href=\"https:\/\/www.osto.one\/resources\/glossary\/siem\/\">audit logging and monitoring<\/a>, <a href=\"https:\/\/www.osto.one\/resources\/glossary\/dlp\/\">file access DLP<\/a>, endpoint control and <a href=\"https:\/\/www.osto.one\/resources\/glossary\/cspm\/\">cloud posture management<\/a> that flags a backup bucket left open. Evidence maps to the HIPAA safeguards in the same platform.<\/p>\n\n<!-- ============ CTA ============ -->\n<div style=\"background:linear-gradient(135deg,#1c267a 0%,#3f4796 48%,#6b4576 100%);border-radius:22px;padding:38px 34px;margin:40px 0 12px;box-shadow:0 10px 26px rgba(28,38,122,.2);text-align:center;\">\n  <p style=\"display:inline-block;background:rgba(255,255,255,.16);color:#ffffff;font-family:'Inter',-apple-system,sans-serif;font-size:11px;font-weight:700;letter-spacing:1.2px;text-transform:uppercase;padding:6px 14px;border-radius:20px;margin:0 0 16px;\">Free security assessment<\/p>\n  <p style=\"color:#ffffff;font-family:'Inter',-apple-system,sans-serif;font-size:26px;line-height:1.3;font-weight:700;letter-spacing:-.4px;margin:0 0 12px;\">Every copy of ePHI, protected the same way<\/p>\n  <p style=\"color:#cfd3ea;font-family:'Inter',-apple-system,sans-serif;font-size:16px;line-height:1.65;margin:0 auto 26px;max-width:520px;\">Databases, backups, logs and laptops. Osto secures the places ePHI actually lives, not just the ones on the diagram.<\/p>\n  <a href=\"https:\/\/osto.one\/contact\/\" style=\"display:inline-block;background:#ffffff;color:#1c267a;font-family:&#039;Inter&#039;,-apple-system,sans-serif;font-weight:700;font-size:16px;text-decoration:none;border-bottom:none;padding:14px 30px;border-radius:12px;margin:0 6px 10px;\" target=\"_blank\" rel=\"noopener\"><span style=\"color:#1c267a;\">Get a free security assessment<\/span><\/a>\n  <a href=\"https:\/\/osto.one\/book-demo\/\" style=\"display:inline-block;background:transparent;color:#ffffff;font-family:&#039;Inter&#039;,-apple-system,sans-serif;font-weight:600;font-size:16px;text-decoration:none;border:1.5px solid rgba(255,255,255,.5);border-radius:12px;padding:13px 28px;margin:0 6px 10px;\" target=\"_blank\" rel=\"noopener\"><span style=\"color:#ffffff;\">Book a platform walkthrough<\/span><\/a>\n  <p style=\"color:#b3b8d8;font-family:'Inter',-apple-system,sans-serif;font-size:13px;margin:14px 0 0;\">Encryption, access and logging &middot; Cloud posture included &middot; One platform, everything<\/p>\n<\/div>\n\n\n<h2 id=\"faq\">Frequently asked questions<\/h2>\n\n<details>\n  <summary>What does ePHI stand for?<\/summary>\n  <p>Electronic protected health information. It is PHI that is created, received, maintained or transmitted in electronic form, and it is the category the HIPAA Security Rule governs.<\/p>\n<\/details>\n\n<details>\n  <summary>What is the difference between PHI and ePHI?<\/summary>\n  <p><a href=\"https:\/\/www.osto.one\/resources\/glossary\/protected-health-information\/\">PHI<\/a> covers health information in any form, including paper and speech. ePHI is the electronic subset. The Privacy Rule applies to all PHI; the Security Rule applies only to ePHI.<\/p>\n<\/details>\n\n<details>\n  <summary>Are application logs ePHI?<\/summary>\n  <p>They are if they contain identifiers alongside health context, which request logs and error traces frequently do. Logs are in scope for the Security Rule and need the same access control and retention discipline as the database.<\/p>\n<\/details>\n\n<details>\n  <summary>Does ePHI have to be encrypted?<\/summary>\n  <p>Encryption is an addressable specification rather than a flat requirement. You must implement it or document why an equivalent alternative is reasonable. In practice, encrypting ePHI is the expected answer and unencrypted data drives most breach penalties.<\/p>\n<\/details>\n\n<details>\n  <summary>Is ePHI in a cloud provider still your responsibility?<\/summary>\n  <p>Yes. The provider is a business associate and needs a BAA, but you remain accountable for configuration, access control and monitoring of your own environment.<\/p>\n<\/details>\n\n<p class=\"related\"><strong>Related glossary terms:<\/strong> PHI &middot; HIPAA Security Rule &middot; Technical Safeguards &middot; Business Associate Agreement &middot; Encryption at Rest and in Transit &middot; DLP<\/p>\n\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>ePHI is protected health information in electronic form. It is the only category the HIPAA Security Rule applies to, which\u2026<\/p>\n","protected":false},"author":8,"featured_media":827,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[180],"tags":[324,326,325],"class_list":["post-826","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-glossary","tag-ephi","tag-phi-vs-ephi","tag-what-is-ephi"],"_links":{"self":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/826","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/comments?post=826"}],"version-history":[{"count":1,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/826\/revisions"}],"predecessor-version":[{"id":828,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/826\/revisions\/828"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media\/827"}],"wp:attachment":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media?parent=826"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/categories?post=826"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/tags?post=826"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}