Where Are You Allowed to Store Files Containing ePHI?

Under HIPAA, you can store electronic protected health information almost anywhere ePHI can technically live — on-premise servers, cloud platforms, laptops, phones, external drives, backup tapes — provided the storage location is covered by a documented risk analysis and protected by the administrative, physical, and technical safeguards the Security Rule requires. HIPAA does not publish an approved list of vendors, products, or media types. It sets standards for confidentiality, integrity, and availability, and any location that meets those standards is fair game.

The real question is not where the data sits. It’s what surrounds it.

The Test Every Storage Location Has to Pass

Before choosing a storage method, HIPAA requires a documented risk analysis. This isn’t a best practice suggestion; it’s a required implementation specification under the Security Management Process standard. The analysis has to identify every place ePHI lives in the organization — servers, workstations, laptops, cloud accounts, backup tapes, mobile devices, email inboxes — and evaluate the likelihood and impact of threats to each.1HHS.gov. Guidance on Risk Analysis

Once you know where the data is and what threatens it, the Security Rule requires three categories of safeguards for each location:2HHS.gov. Summary of the HIPAA Security Rule

  • Administrative safeguards: the policies, workforce training, security officer designation, incident response, and contingency planning that govern how people handle ePHI.
  • Physical safeguards: facility access controls, workstation security, and device and media controls covering the hardware itself.3eCFR. 45 CFR 164.310 – Physical Safeguards
  • Technical safeguards: access controls with unique user IDs, audit logging, integrity protections, authentication, and transmission security.4eCFR. 45 CFR 164.312 – Technical Safeguards

A storage location is allowed if all three categories of safeguards are in place around it. A location isn’t allowed because any one of them is missing. That framework is what makes almost anywhere permissible in principle and disqualifies many common choices in practice.

On-Premise Servers and Network Drives

Storing ePHI on servers and network drives inside your own facilities is permissible when the full range of safeguards is applied. Physical security is the starting point: server rooms with controlled access, visitor logs, and environmental protections against fire, flood, and power loss. On the technical side, the server environment needs access controls tied to unique user accounts, audit logging, encryption of stored data, and integrity checks.

On-premise storage demands particular attention to backup and disaster recovery. The Security Rule requires a contingency plan covering data backup, disaster recovery, and emergency mode operations. A single server holding the only copy of your ePHI is a fire or ransomware attack away from being unrecoverable. Offsite or geographically separated backups, themselves encrypted and covered by the same safeguards, are the standard approach.

Cloud Storage

Cloud storage is explicitly allowed under HIPAA, provided your organization signs a business associate agreement with the cloud service provider and otherwise complies with the Security Rule.5HHS.gov. Guidance on HIPAA and Cloud Computing HHS has published guidance confirming this directly.

The BAA has to include specific elements: limits on how the provider uses ePHI, a commitment to appropriate safeguards, a requirement to report unauthorized disclosures and breaches, assurances that subcontractors follow the same rules, and provisions for returning or destroying ePHI when the contract ends.6eCFR. 45 CFR 164.504 – Uses and Disclosures If the provider materially breaches the agreement, you’re required to take reasonable steps to fix the problem or terminate the relationship.7HHS.gov. Business Associates

One point catches organizations off guard: signing a BAA does not transfer your compliance responsibilities to the vendor. You still need to conduct your own risk analysis covering the cloud environment, understand what the provider does and does not protect, and implement safeguards on your end.5HHS.gov. Guidance on HIPAA and Cloud Computing The provider typically secures the underlying infrastructure; you remain responsible for how you configure access, manage user accounts, and handle the data within the platform.

Mobile Devices and Personal Electronics

Health care providers and business associates may use mobile devices to access ePHI stored in the cloud or on local systems, as long as appropriate safeguards protect both the device and the storage environment, and any necessary BAAs are signed with the third-party services involved.8HHS.gov. Do the HIPAA Rules Allow Health Care Providers to Use Mobile Devices to Access ePHI in a Cloud HIPAA doesn’t mandate or prohibit specific technologies; it requires you to analyze the risks your chosen technology creates and address them.

Personal phones, tablets, and laptops (a “bring your own device” or BYOD setup) multiply the risks. Personal devices may lack encryption, run outdated software, or be shared with family. A workable BYOD policy usually addresses device encryption, access controls, approved applications, automatic screen locks, remote wipe for lost or stolen devices, and clear rules about what happens when an employee leaves. The risk analysis should document specifically how ePHI is created, accessed, and stored on personal devices and what controls mitigate each threat.

Portable Physical Media

External hard drives, USB flash drives, backup tapes, and CDs can all store ePHI when the right protections are in place. The Security Rule requires device and media controls governing how these items enter, leave, and move within your facilities.3eCFR. 45 CFR 164.310 – Physical Safeguards That means locked storage, inventory tracking, and clear chain-of-custody documentation.

Encryption matters most for portable media because these items are easy to lose or steal. A lost unencrypted USB drive holding patient records is one of the most common preventable HIPAA breaches. Encrypting the data means a lost device may not trigger breach notification at all.

Where ePHI Should Not Go

The Security Rule doesn’t publish a blacklist of prohibited locations. Any location that fails to meet the required safeguards is effectively off-limits. Several practices fail that test so consistently they deserve specific attention.

Consumer cloud services without a BAA. Standard personal email, free file-sharing platforms, and consumer-grade cloud storage accounts generally don’t offer BAAs. Storing ePHI in these environments violates HIPAA regardless of how strong the password is, because there’s no contractual obligation for the provider to protect the data or report breaches. Many major cloud providers do offer HIPAA-eligible tiers with BAAs, but you have to specifically select and configure those tiers.

Unencrypted email. HIPAA doesn’t expressly prohibit sending ePHI by email, but the transmission security standard requires you to guard against unauthorized access to ePHI sent over electronic networks.4eCFR. 45 CFR 164.312 – Technical Safeguards Standard email protocols don’t encrypt messages end to end. If you use email for ePHI, you need an encryption solution or must document why an alternative safeguard is equivalent.

Standard text messaging. Regular SMS lacks encryption, doesn’t guarantee delivery to the intended recipient, and the wireless carrier may store message content on its own servers. Some organizations approve texting after a risk analysis and after deploying a secure third-party messaging platform, but casual texting of patient information from a personal phone is a compliance failure waiting to happen.

Unencrypted laptops and portable devices. A laptop left in a car, an external drive forgotten at a coffee shop, a phone taken off a break room table. These incidents happen constantly, and without encryption, each one is a reportable breach.

Why Encryption Runs Through All of This

Encryption of ePHI at rest and in transit is classified as an “addressable” implementation specification, not a “required” one.4eCFR. 45 CFR 164.312 – Technical Safeguards Many organizations read “addressable” as “optional.” It isn’t. An addressable specification must be implemented if it’s reasonable and appropriate; if you decide it isn’t, you have to document why and implement an equivalent alternative measure.2HHS.gov. Summary of the HIPAA Security Rule

Encryption tools are widely available, affordable, and built into most modern operating systems and cloud platforms. Arguing that encryption is not reasonable and appropriate for a portable laptop, for instance, is an extremely hard position to defend in an investigation.

Encryption also carries a legal benefit. Under the HIPAA Breach Notification Rule, properly encrypted ePHI is considered “secured.” If an encrypted device is lost or stolen and the encryption key hasn’t been compromised, the incident doesn’t trigger breach notification requirements.9HHS.gov. Guidance to Render Unsecured Protected Health Information Unusable, Unreadable, or Indecipherable to Unauthorized Individuals That safe harbor makes encryption one of the most cost-effective protections available.

When Storage Media Reach End of Life

Storage rules don’t end when a device stops being used. The Security Rule requires policies for the final disposition of ePHI and for removing ePHI from electronic media before reuse. Both are required implementation specifications, not addressable ones.3eCFR. 45 CFR 164.310 – Physical Safeguards Simply deleting files or reformatting a drive isn’t enough, because standard deletion leaves recoverable data behind.

HHS identifies several appropriate disposal methods:10HHS.gov. May a Covered Entity Reuse or Dispose of Computers That Store Protected Information

  • Clearing: overwriting the media with non-sensitive data. Appropriate when the device will be reused inside the same organization.
  • Purging: degaussing to disrupt the stored data. Works on magnetic media like hard drives and backup tapes; doesn’t work on solid-state drives.
  • Destroying: physically shredding, pulverizing, melting, incinerating, or disintegrating the media. The most secure method, appropriate when the media won’t be reused.

You can hire a business associate to handle destruction, but you’ll need a BAA with that vendor and should verify their destruction methods and documentation.

A Rule Change That Could Tighten This

In December 2024, HHS published a proposed rule that would significantly strengthen the Security Rule if finalized. Among the changes: encryption of ePHI at rest and in transit would become a required specification rather than an addressable one, eliminating the current flexibility to document alternative measures. The proposal would also require organizations to maintain a technology asset inventory and network map showing how ePHI moves through their systems, updated at least every 12 months, and to establish written procedures for restoring critical systems and data within 72 hours of a loss.11HHS.gov. HIPAA Security Rule Notice of Proposed Rulemaking to Strengthen Cybersecurity As of early 2026 the rule has not been finalized, and the current Security Rule remains in effect. If the proposal becomes final, the flexibility around encryption at any storage location — the single most consequential compliance choice for most organizations — will disappear.