What is ePHI?
Protected health information (PHI) that is stored, accessed, or transmitted electronically is specifically referred to as ePHI (electronic protected health information), which mandates technical, administrative, and physical safeguards.
Zoho Tables provides the following features to help your organization handle ePHI responsibly:
Mark ePHI fields to identify and distinguish sensitive health data.
Restrict ePHI field data to prevent unauthorized access.
Administer roles and permissions to control who can view, edit, or export ePHI.
What you'll need
An active Zoho Tables account
At least one base that contains or will contain ePHI data
Portal Owner or Manager access to configure field-level settings
Zoho Tables plan | Can enable ePHI? |
Free | No |
Professional | Yes |

Who has access?
User role | Access |
Owner and Portal Manager | Can mark/unmark fields as ePHI and manage all ePHI settings in admin page |
Workspace Manager, Base Manager, and Editor | Can mark/unmark fields as ePHI if granted access |
Data Maintainer, Commenter, and Viewer | Cannot mark/unmark fields as ePHI or modify any ePHI settings |
Go to the portal listings page and choose the more options button next to your portal.
From the list of options, choose Admin Console.
Locate ePHI and toggle it to enable.
Review the configuration and set your privacy:
Choose the user roles that can mark, unmark, and modify PHI fields in a base.
Limit how the data is being used—be it sharing or copying, you set the boundaries.
Manage the restrictions applied to data sharing via automation and integration.
Zoho Tables tracks the activity in every element inside the product, so audit logging is automatically activated for your organization by default.
Note: Only Owners and Portal Managers in the Zoho Tables Admin Console can enable ePHI at the account level.Once ePHI is enabled at the account level, you can mark individual fields in your bases as containing health information. This flags the field as containing protected health information and automatically enables protection and restriction as chosen in the Admin Console for that field.
To mark an existing field as ePHI:
Navigate to the table where you want to mark the field as containing PHI.
Click the dropdown arrow on the field header you want to mark.
From the list of options, choose Mark as Health Info.
Or choose Edit from the options in the dropdown, and enable the Contains health information toggle in the field configuration panel. The changes are auto-saved.
To mark a new field as ePHI while creating it:
Open the relevant base and click the + icon in the field header row to add a new field, or click Manage Fields from the right side of the view bar and select + Add Fields.
Choose your desired field type and configure its properties.
In the field settings panel, enable the Contains health information (ePHI) toggle.
Click Create to add the field to the table.
Once a field is marked as ePHI:
Only users with the appropriate role and access permissions can mark or unmark the field as containing health information.
All access and modifications to the fields are captured in the activity log in the Admin Panel.
Note: Only 20 fields per table can be marked as containing PHI.