In July 2026, a malware-related cyberattack disrupted AnMed’s phone, internet, and computer systems. Some medical offices and imaging services temporarily closed, while appointments and elective procedures were canceled or postponed. The attack is yet another example of why healthcare cybersecurity isn’t just about preventing hackers from improperly disclosing protected patient data. Oftentimes, even if an investigation later finds that patient data was never accessible to attackers, unreachable systems still impact appointment schedules, referrals, test results, and care coordination. At the heart of the HIPAA Security Rule are three interrelated goals when it comes to cybersecurity namely confidentiality, integrity, and availability of electronic protected health information (ePHI). Together they’re known as the CIA triad.
We can look at each of these goals as they pertain to securing electronic health records, cloud-based platforms, medical devices and yes, even HIPAA compliant email. Each cybersecurity goal focuses on a different aspect of how healthcare data is stored, accessed and shared.
What is ePHI?
ePHI is protected health information that is maintained in or transmitted by electronic media. According to 45 CFR § 160.103, it may relate to an individual's health condition, provision of health care, or payment for health care that identifies the individual or by which the individual can be reasonably identified. Some examples include electronic health records (EHRs), laboratory systems, electronic medical imaging, billing systems, electronic prescriptions, and emails that contain PHI.
Information that is spoken or written on paper can still qualify as PHI, but if it is not transmitted or stored electronically, it is not considered ePHI.
One 2024 study on electronic health record integrity found that more than 94% of hospitals across the U.S. were using EHRs as early as 2017. Therefore, security around electronic information is very integrated into daily clinical and administrative tasks.
How does HIPAA define the confidentiality of ePHI?
According to 45 CFR § 164.304, the term confidential means information that is not disclosed to individuals who are not authorized to receive it.
Examples of confidentiality incidents include an employee viewing a record without a work-related reason, a provider mailing information to the wrong person, or an attacker taking over an email account. Confidentiality can also be affected if a system grants users greater access than necessary for their job functions.
Patients' willingness to disclose information can be impacted by confidentiality. Researchers in one study reviewed 7,738 US women and found that 10.8% withheld health information from providers due to concerns over privacy or security of their medical records. This was using data from the 2011–2018 Health Information National Trends Survey. Ultimately, stronger confidentiality practices can help patients communicate more openly, even if they cannot eliminate every security risk.
What is HIPAA definition of ePHI integrity?
HIPAA’s definition of integrity is that information has not been changed or destroyed in an unauthorized manner. The technical safeguards at 45 CFR § 164.312 specifically require covered entities to implement policies and procedures to ensure that electronic protected health information is not improperly altered or destroyed.
Malware that changes a file, unauthorized edits made by a person, and altered attachments can affect integrity. Sending outdated information or attaching a lab report for the wrong patient could create concerns about accuracy. Accuracy is part of integrity, but a simple documentation error may not necessarily be a violation of HIPAA.
A study that examined 776 cancer records notes the consequences of inaccurate information. Fifteen percent of the records contained documentation errors. The researchers were looking at the quality of clinical data, not HIPAA violations. However, the study notes why providers need accurate and legible information to facilitate care planning and communication.
How does HIPAA define availability of ePHI?
HIPAA’s definition of availability is that information is accessible and usable when needed by an authorized person. Covered entities must consider availability during normal operations and during ransomware attacks, power outages, equipment failures, natural disasters, and preventive maintenance.
HIPAA’s availability requirement is critical when clinicians need electronic information to make timely decisions. A JAMIA-indexed paper concludes that EHR downtime incidents “pose patient safety hazards.” The authors identified several opportunities to improve how healthcare organizations handle downtime.
Availability can be addressed through contingency plans, tested backups, emergency-access procedures, system redundancy, and documented responsibilities.
How do confidentiality, integrity, and availability relate to each other?
The three components defend separate but related aspects of ePHI. A document can stay confidential but become unusable if it’s corrupted. Systems can be available while still exposing patient data to unauthorized individuals. Patient data can even stay intact while ransomware locks clinicians out of files.
One NCBI study reviewing healthcare information-security law notes that breaches and security incidents can affect confidentiality, integrity, and availability. Therefore, organizations should examine the overall impact of a violation rather than treating each incident as solely a privacy issue.
Encryption offers a helpful example. According to the HHS cloud-computing guidance, encryption can help minimize the chances of unauthorized viewing. However, encryption by itself does not prevent hackers from corrupting stored information or guarantee that authorized users can access ePHI during an emergency.
How can covered entities and business associates protect confidentiality, integrity, and availability?
HIPAA’s Security Rule requires covered entities and business associates to implement administrative, physical, and technical safeguards. Organizations should start by performing a comprehensive risk analysis that identifies all ePHI they create, receive, maintain, or transmit.
A systematic review of EHR security looked at 25 publications. 20 of the included publications detailed certain security measures. The researchers organized the most commonly discussed measures into three main categories similar to those in HIPAA:
- Administrative safeguards: Risk management, workforce permissions, security training, incident-response planning, contingency operations, and business partner audits.
- Physical safeguards: Policies and procedures that restrict physical access to facilities, workstations, servers, laptops, and other areas where ePHI is stored or maintained.
- Technical safeguards: Technical security measures like access control, unique user identification, audit recording, automatic log off, encryption, and data transmission protection.
HIPAA compliant email can help healthcare organizations implement email safeguards from all three categories, but the right service should:
- Agrees to sign a business associate agreement.
- Restricts employee access based on their roles and responsibilities.
- Protects email accounts from takeover.
- Encrypts ePHI when necessary.
- Maintains records healthcare organizations can audit.
The 2026 Paubox Healthcare Email Security Report found that 170 healthcare-related email breaches were reported in 2025. Seventy four percent of the breached domains analyzed had poor DMARC protections. Keeping this in mind, DMARC alone doesn’t make your email HIPAA compliant. However, it can strengthen your security defenses when used with SPF, DKIM, inbound threat detection, and secure outbound delivery.
FAQs
When does electronically stored health information qualify as ePHI under HIPAA?
Information qualifies as ePHI when it is individually identifiable health information transmitted or maintained electronically by a HIPAA covered entity or business associate. Health information held only by an unaffiliated consumer application may fall outside HIPAA, although other federal or state privacy laws could apply.
Can an email subject line or attachment contain ePHI even if the message body does not?
Yes, a subject line, attachment, recipient address, or other email component can be ePHI when it connects an identifiable person to healthcare, treatment, or payment information. Healthcare organizations should therefore protect the entire email rather than encrypting only the message body.
Does encrypting ePHI mean it is no longer subject to HIPAA?
No, encrypted ePHI remains protected health information and continues to be subject to the HIPAA Security Rule. Proper encryption may render information unreadable to unauthorized people for breach-notification purposes, but it does not remove the organization’s other compliance obligations.
