I was reviewing a dental practice's risk analysis last year when the office manager pointed at a paper chart and asked, "This is ePHI too, right?" She'd been treating every piece of patient information the same way — electronic or not — and while her caution was admirable, her confusion was creating real problems. Her team was applying Security Rule safeguards to filing cabinets and ignoring actual electronic vulnerabilities on their network. If you've ever stared at an exam question asking which of the following is not electronic PHI, you've bumped into the same confusion. And getting it wrong doesn't just cost you a test score — it can cost your organization millions.
Why the ePHI Distinction Matters More Than You Think
The HIPAA Security Rule applies specifically to electronic protected health information — ePHI. Not paper records. Not verbal conversations. The Privacy Rule covers all forms of PHI, but the Security Rule's administrative, physical, and technical safeguards are laser-focused on data that is created, stored, transmitted, or received in electronic form.
When your workforce can't tell the difference, they misallocate resources. They encrypt a paper memo instead of locking down a shared drive. Or worse, they assume a voicemail containing a diagnosis isn't covered by any rule at all. The Office for Civil Rights (OCR) at HHS doesn't accept confusion as an excuse. Just look at their published enforcement actions — misunderstanding what constitutes ePHI is a thread running through dozens of settlements.
So Which of the Following Is Not Electronic PHI?
Here's the direct answer. You'll typically see a question like this on a HIPAA training quiz or certification exam:
- A) A patient's lab results stored in an EHR system
- B) A digital X-ray saved on a clinic's server
- C) A handwritten prescription handed directly to a patient
- D) A billing record transmitted electronically to a health plan
The answer is C — a handwritten prescription handed directly to a patient. It's PHI, absolutely. But it's not electronic PHI. It was never created, stored, or transmitted electronically. The Security Rule doesn't apply to it. The Privacy Rule does.
Options A, B, and D all involve health information in electronic form tied to an identifiable individual. That makes them ePHI, subject to every technical and administrative safeguard the Security Rule demands.
The Two-Part Test for ePHI
Every piece of ePHI must meet two criteria simultaneously:
- It's individually identifiable health information — data that relates to a person's health condition, treatment, or payment for healthcare, combined with identifiers like name, date of birth, Social Security number, or medical record number.
- It exists in electronic form — created, received, stored, or transmitted using electronic media. This includes hard drives, cloud servers, email, USB drives, EHR systems, and even text messages.
If either element is missing, it's not ePHI. A lab result on paper? PHI, not ePHI. An anonymized data set on a server with all 18 identifiers removed under the Safe Harbor method? Not PHI at all — so not ePHI either.
Common Examples That Trip People Up
Voicemails
A voicemail left on a digital answering system that stores the message as a file on a server? That's ePHI if it contains identifiable health information. A live phone conversation that's never recorded? Not ePHI. The medium matters.
Faxes
A traditional analog fax that prints on paper at the receiving end is generally not considered ePHI during transmission — it's treated more like a paper record. But an electronic fax (eFax) that arrives as a PDF in an email inbox? That's ePHI from the moment it hits the server.
Photographs on a Smartphone
A clinician snaps a photo of a wound on their personal phone. The photo shows the patient's face or is linked to their chart. That image file sitting on the phone's storage is ePHI. I've seen this one cause real enforcement headaches, especially when the phone is lost or stolen.
Paper Records Scanned Into a System
The original paper chart isn't ePHI. The moment a staff member scans it and saves the file to a shared drive or uploads it to an EHR, it becomes ePHI. The same information, two different regulatory frameworks depending on the medium.
The $3 Million Lesson From Cottage Health
In 2019, Cottage Health System agreed to a $3,000,000 settlement with OCR after ePHI of over 62,500 patients was exposed online. The root cause? A server configuration error made electronic patient records accessible on the internet without authentication. This wasn't a paper-records problem. This was a failure to apply Security Rule safeguards — access controls, audit logs, encryption — to ePHI stored on electronic systems.
If Cottage Health's team had treated that data like paper charts, they wouldn't have implemented technical safeguards. But the data was electronic, and the Security Rule demanded protections they didn't deliver. Understanding what qualifies as ePHI isn't academic — it determines which safeguards you're legally required to implement. You can review the full details of OCR's enforcement history on the HHS enforcement highlights page.
Why Your Workforce Gets This Wrong
In my experience, the confusion comes from three places:
1. Conflating PHI with ePHI. Staff hear "protect patient information" and apply it uniformly. They don't realize the Security Rule and Privacy Rule have different scopes and different requirements.
2. Ignoring transitional moments. Information changes categories. A paper record becomes ePHI the second it's scanned. A verbal order becomes ePHI the second it's entered into an EHR. Staff need to understand these transitions.
3. Outdated training. If your training materials haven't been updated to reflect current technology — cloud storage, telehealth platforms, mobile health apps — your staff is working with a 2012 mental model in a 2026 world.
This is exactly why regular, role-specific HIPAA training matters. A front-desk employee who handles intake on a tablet faces different ePHI risks than a billing specialist who transmits claims electronically. Both need to know what ePHI is, but they need to apply that knowledge differently. Our HIPAA training catalog covers these role-specific scenarios in detail.
What the Security Rule Actually Requires for ePHI
Once you've correctly identified something as ePHI, the HIPAA Security Rule under 45 CFR Part 164, Subpart C kicks in. Here's what your covered entity or business associate must implement:
- Administrative safeguards: Risk analyses, workforce training, access management policies, contingency plans.
- Physical safeguards: Facility access controls, workstation security, device and media controls.
- Technical safeguards: Access controls (unique user IDs, automatic logoff), audit controls, integrity controls, transmission security (encryption).
None of these apply to a handwritten note passed between two nurses. All of them apply the moment that same note is typed into a patient portal. The format determines the rule. The rule determines the safeguard.
How to Cement This Knowledge Across Your Organization
Here's what I recommend to every compliance officer I work with:
Run quarterly scenario drills. Give staff five examples and ask them to categorize each as PHI, ePHI, or neither. Make it fast, practical, and discussion-based. You'll be shocked at how many seasoned employees get it wrong.
Update your training annually. Technology changes fast. If your training doesn't cover cloud-based EHRs, telehealth recordings, or wearable health devices, it's already obsolete. Browse the complete HIPAA training catalog at HIPAACertify.com for courses built around current workflows and real-world scenarios.
Document everything. When OCR investigates, they ask for proof of training, not proof of good intentions. Every drill, every quiz, every signed acknowledgment goes in the file.
The Bottom Line on ePHI Identification
A handwritten prescription handed to a patient is PHI. It's not ePHI. That single distinction determines whether the Security Rule's technical safeguards apply. Getting this wrong means either over-investing in the wrong protections or — far more dangerously — leaving electronic health data exposed because your team didn't recognize it as ePHI in the first place.
Every breach notification, every OCR investigation, every seven-figure settlement starts somewhere. Often, it starts with a staff member who couldn't answer the question: which of the following is not electronic PHI? Make sure your team can.