Skip to main content

PHI Management

# System Settings
Last updated: 04/14/2026

Configure Protected Health Information (PHI) masking parameters and manage sensitive data display policies.

Overview

The PHI Management page allows administrators to configure masking parameters for Protected Health Information (PHI) and manage how sensitive data is displayed across the platform. This ensures compliance with privacy regulations such as HIPAA, GDPR, and local data protection laws.

Access this page via System SettingsPHI Management.


PHI Masking Parameters

Configure how sensitive data fields are masked or displayed to users based on their roles and permissions.

FieldDescription
Enable PHI MaskingMaster toggle to activate or deactivate PHI masking across the platform. When disabled, all users with appropriate permissions can view unmasked PHI data.
Default Masking PolicySelect the default masking behavior for new PHI fields: Full Mask (completely hidden), Partial Mask (show first/last characters only), or Role-Based (determined by user role).
Mask CharacterChoose the character used to replace masked data (e.g., *, #, ). Default is asterisk (*).

Field-Specific Configuration

Define masking rules for specific types of sensitive data fields.

Field TypeConfiguration Options
Personal IdentifiersConfigure masking for SSN, passport numbers, driver's license, and other government IDs. Options include: show last 4 digits only, show first 3 and last 4, or full mask.
Contact InformationSet masking rules for phone numbers, email addresses, and physical addresses. Phone numbers can show area code only; emails can show domain only.
Medical Record NumbersDefine how medical record identifiers are displayed. Options include partial display with configurable visible segments.
Dates of BirthConfigure date masking: show year only, show month/year only, or shift dates by a random offset while maintaining relative age calculations.
Financial InformationSet masking for insurance IDs, account numbers, and billing information. Typically shows last 4 digits only.

Role-Based Access Control

Control which user roles can view unmasked PHI data.

SettingDescription
Unmasking RolesSelect user roles that are permitted to view unmasked PHI data (e.g., Principal Investigator, Study Coordinator with elevated permissions).
Audit Unmasking ActionsEnable detailed audit logging when users with unmasking permissions view sensitive data. All unmasking events are recorded with timestamp, user ID, and field accessed.
Temporary UnmaskingAllow authorized users to temporarily unmask PHI for a specific session or time period (e.g., 15 minutes), after which data is automatically re-masked.

Display Policies

Configure how masked data appears to end users.

FeatureDescription
Show Mask IndicatorDisplay a visual indicator (e.g., eye icon with slash) next to masked fields to inform users that data is hidden.
Tooltip on HoverShow a tooltip explaining why data is masked and what role is required to view it when users hover over masked fields.
Export BehaviorDefine how masked data is handled in exports: Export Masked (maintain masking in exports), Export Unmasked (for authorized roles only), or Exclude PHI (remove PHI fields from exports entirely).

Compliance & Audit

Compliance Tip: PHI masking is required for compliance with HIPAA Privacy Rule, GDPR Article 9 (special categories of personal data), and Vietnam Decree 13/2023/NĐ-CP on personal data protection. Ensure masking policies are documented and reviewed annually.


Saving Changes

Click Submit to save your PHI management configuration.

Important: Changes to PHI masking policies take effect immediately for all active sessions. Users currently viewing unmasked data will see the updated masking rules upon page refresh. All configuration changes are logged in the Audit Trail for compliance purposes.