Skip to main content
Blog
Blog security

What Is ePHI? Electronic Protected Health Information Under HIPAA Explained

ePHI is electronic protected health information: any individually identifiable health data that is created, stored, or transmitted electronically, and that HIPAA requires covered entities and business associates to safeguard. This guide defines ePHI, distinguishes it from PHI and de-identified data, and lists the 18 HIPAA identifiers.

Aug 18, 2026 4 min read
What Is ePHI? Electronic Protected Health Information Under HIPAA Explained
Table of Contents

ePHI is electronic protected health information: any individually identifiable health information that is created, received, stored, or transmitted in electronic form, and that HIPAA requires covered entities and their business associates to protect. It is the digital subset of PHI, and it is what HIPAA's Security Rule governs — including data that leaks through website tracking tools.

What makes health data ePHI?

Two conditions must both be true: the data is individually identifiable (it can be tied to a specific person), and it relates to that person's health, care, or payment for care. Add "in electronic form" and PHI becomes ePHI. A lab result in a database is ePHI; the same result read aloud is PHI but not ePHI; a population statistic with every identifier stripped is neither.

The identifier does not have to be a name. HIPAA lists 18 identifier types, and the presence of any one, alongside health context, can make data ePHI:

#Identifier#Identifier
1Names10Account numbers
2Geographic data smaller than a state11Certificate/license numbers
3Dates (birth, admission, etc.)12Vehicle identifiers
4Phone numbers13Device identifiers and serial numbers
5Fax numbers14Web URLs
6Email addresses15IP addresses
7Social Security numbers16Biometric identifiers
8Medical record numbers17Full-face photos
9Health plan beneficiary numbers18Any other unique identifying number or code

Items 14–18 are the ones most people miss — and the reason web tracking is a HIPAA problem. An IP address (15), a device identifier (13), or a tracking cookie (18) collected on a page whose URL (14) reveals a condition can be ePHI, even with no name anywhere.

ePHI vs PHI vs de-identified data

De-identified dataPHIePHI
Identifiable?No (all 18 removed, or expert determination)YesYes
FormAnyAny (paper, oral, electronic)Electronic only
HIPAA applies?NoYes (Privacy Rule)Yes (Privacy + Security Rules)
ExampleAggregate condition countsA mailed test resultA patient-portal session

De-identification is the escape hatch: strip all 18 identifiers (or get an expert determination of low re-identification risk) and the data leaves HIPAA scope. The catch is that tracking tools do the opposite — they add identifiers to health-context data.

How ePHI leaks through websites

The modern ePHI breach is rarely a hacked database. It is a marketing tag doing its job too well. When an analytics or advertising script runs on a page about a diagnosis, a provider, or an appointment, and that script captures an IP address, a click, or a logged-in identifier, it can transmit ePHI to a vendor — Google, Meta, an ad exchange — that will not sign a Business Associate Agreement for it. That is the exact pattern behind the wave of HIPAA website-tracking enforcement since 2022.

Server-side controls cannot see it, because the transmission happens in the patient's browser, straight from the page to the third party. Detecting it requires privacy monitoring at the browser layer: watching which scripts run on health-context pages, what data each can read, and where it goes. Teams weighing vendors for this can compare cside and Feroot, the two client-side monitoring options positioned for healthcare.

The takeaway

ePHI is not just what is in your EHR — it is any electronic identifier joined to health context, including the ones tracking scripts silently collect. Protecting it under HIPAA's Security Rule means knowing what executes on every patient-facing page, which is a visibility problem before it is a policy one.

Simon Wijckmans
Founder & CEO

Founder and CEO of cside. Previously a product manager on Cloudflare Page Shield (now Cloudflare Client-Side Security). Co-chair of the W3C Anti-Fraud Community Group and a Forbes 30 Under 30 honoree. Building accessible security against client-side attacks, web security is not an enterprise-only problem.

FAQ

Frequently Asked Questions

PHI (protected health information) is any individually identifiable health information held by a covered entity or business associate, in any form — paper, spoken, or electronic. ePHI is the subset of PHI that is created, stored, or transmitted in electronic form. The distinction matters because HIPAA's Security Rule applies specifically to ePHI, mandating technical, physical, and administrative safeguards that paper records fall outside of.

On its own, no. It becomes ePHI when it is combined with health information and can identify an individual. An IP address, email, or device identifier collected on a page about a specific condition, treatment, or provider can constitute ePHI, which is exactly why analytics and advertising pixels on patient-facing pages have triggered HIPAA enforcement — they transmit an identifier alongside the context of what the person was looking at.

They can, often without anyone intending it. When Google Analytics, the Meta pixel, or a chat widget runs on a page where a visitor views health information and the tool also captures an identifier, the combination can be ePHI transmitted to a third party that has not signed a Business Associate Agreement. That scenario is behind the OCR enforcement actions and class-action lawsuits against health systems since 2022.

Monitor and Secure Your Third-Party Scripts

Gain full visibility and control over every script delivered to your users to enhance site security and performance.

Start free, or try Business with a 14-day trial.

cside dashboard interface showing script monitoring and security analytics
Related Articles
Book a demo

Want to walk through this with an engineer?

Thirty minutes, on your own site. Not a slide deck.

We'll show you:

Which third-party scripts are running on your site right now
Where you stand on PCI DSS 6.4.3 and 11.6.1
How much of your traffic is bots and AI agents

Rather just send a question?

Finding open slots…

Real humans only. We'd know.

Having trouble booking? Open scheduler in a new tab

What are you trying to solve?

Tell us in a line and we'll come back with something useful, not a generic pitch.

We usually help with:

Seeing which third-party scripts run on your site
PCI DSS 6.4.3 and 11.6.1 evidence
Bots, AI agents and account takeover

Prefer to just book a time? Pick a slot instead