Compliance frameworks
ePHI (Electronic Protected Health Information)
Electronic Protected Health Information is protected health information (PHI) that is transmitted by or maintained in electronic media, as defined in 45 CFR 160.103. PHI is individually identifiable health information held by a covered entity or business associate, with some statutory exclusions such as certain employment records. The HIPAA Security Rule applies specifically to ePHI. The 18 identifiers listed in 45 CFR 164.514(b)(2)(i), including names, small geographic subdivisions, dates more specific than the year, contact details, and biometric identifiers, are the ones that must be removed to de-identify data under the Safe Harbor method.
Sources
- 45 CFR 160.103, "Definitions" (eCFR; "electronic protected health information", "business associate")
- NIST CSRC Glossary: "Electronic Protected Health Information"
- 45 CFR 164.514, "Other requirements relating to uses and disclosures of protected health information" (eCFR; de-identification identifiers at (b)(2)(i))