Zoho Tables helps you protect sensitive health information by allowing you to mark fields as health information and control how that data can be accessed, copied, used, and shared.
From the Compliance section in the Admin Console, you can enable ePHI, control who can configure health information fields, and choose the actions that should be restricted for protected data.
Portal Owners and Portal Managers can enable and configure ePHI settings from the Admin Console.
Once enabled, you can configure access restrictions and data protection policies.
Control who can use Mark as Health Info for fields in your portal.
Choose one of the following options:
This setting controls who can configure a field as health information. It does not determine whether users can view or use the data in those fields.
Choose which actions should be restricted for fields configured as health information.
Policy: Prevent field data from being included when the base is downloaded.
When enabled, data from these fields is excluded when the base is downloaded.
Policy: Prevent cut and copy actions on field data.
When enabled, users cannot cut or copy data from these fields.
Policy: Prevent health information from being copied when records, fields, tables, or bases are duplicated.
When enabled, protected data is not carried over when supported records, fields, tables, or bases are duplicated.
Policy: Prevent field data from being used in Reports.
When enabled, these fields cannot be used to display protected data in Reports.
Policy: Prevent field data from appearing in link, lookup, rollup, formula, and keyword extraction fields.
When enabled, protected data cannot be surfaced through these field types.
Policy: Prevent field data from being sent through automation actions.
When enabled, protected data cannot be included when automation actions send or process data.
Control how health information is handled when it is shared with external services and integrations.
Policy: Prevent field data from being shared with integrated apps.
When enabled, protected data cannot be shared with connected applications through supported integrations.
Policy: Prevent field data from being sent through APIs and third-party integrations such as Zoho Flow and Zapier.
When enabled, protected data cannot be sent through supported APIs or third-party integration services.
After enabling ePHI and configuring the required access restrictions and data protection policies, click Save to apply your settings.
Your selected policies will then apply to fields configured as health information in the portal.