Manage ePHI and Health Data Protection | Zoho Tables Help

Electronic Protected Health Information (ePHI)


Zoho Tables helps you protect sensitive health information by allowing you to mark fields as health information and control how that data can be accessed, copied, used, and shared.

From the Compliance section in the Admin Console, you can enable ePHI, control who can configure health information fields, and choose the actions that should be restricted for protected data.

Who can enable ePHI?

Portal Owners and Portal Managers can enable and configure ePHI settings from the Admin Console.

How to enable ePHI

  1. Go to My Portals.
  2. Find the portal you want to configure.
  3. Click the More icon next to the portal.
  4. Select Admin Console.
  5. Go to Compliance.
  6. Enable the ePHI toggle.

Once enabled, you can configure access restrictions and data protection policies.

Access restriction

Control who can use Mark as Health Info for fields in your portal.

Choose one of the following options:

  • None — No one can use Mark as Health Info for a field.
  • Managers and above — Portal, Workspace, and Base Managers can use Mark as Health Info for fields.
  • Editors and above — Portal, Workspace, and Base Editors can use Mark as Health Info for fields.

This setting controls who can configure a field as health information. It does not determine whether users can view or use the data in those fields.

Data Protection Rules

Choose which actions should be restricted for fields configured as health information.

Prevent downloads

Policy: Prevent field data from being included when the base is downloaded.

When enabled, data from these fields is excluded when the base is downloaded.

Prevent cut and copy

Policy: Prevent cut and copy actions on field data.

When enabled, users cannot cut or copy data from these fields.

Prevent duplication

Policy: Prevent health information from being copied when records, fields, tables, or bases are duplicated.

When enabled, protected data is not carried over when supported records, fields, tables, or bases are duplicated.

Prevent use in Reports

Policy: Prevent field data from being used in Reports.

When enabled, these fields cannot be used to display protected data in Reports.

Prevent use in derived fields

Policy: Prevent field data from appearing in link, lookup, rollup, formula, and keyword extraction fields.

When enabled, protected data cannot be surfaced through these field types.

Prevent use in automations

Policy: Prevent field data from being sent through automation actions.

When enabled, protected data cannot be included when automation actions send or process data.

Data Sharing & Integrations

Control how health information is handled when it is shared with external services and integrations.

Prevent sharing with integrated apps

Policy: Prevent field data from being shared with integrated apps.

When enabled, protected data cannot be shared with connected applications through supported integrations.

Prevent sharing through APIs and third-party integrations

Policy: Prevent field data from being sent through APIs and third-party integrations such as Zoho Flow and Zapier.

When enabled, protected data cannot be sent through supported APIs or third-party integration services.

Save your settings

After enabling ePHI and configuring the required access restrictions and data protection policies, click Save to apply your settings.

Your selected policies will then apply to fields configured as health information in the portal.

  1. Mark a field as health info
  2. Unmark a field as health info