What Is PHI (Protected Health Information)?

Related problems: Not sure whether the data our new provider will handle counts as PHI; A healthcare customer wants us to sign a business associate agreement; Call recordings, emails and tickets may contain patient details; Need to share health data for analytics without exposing patients

Protected health information (PHI) is health information that can identify a person and that is created, received, stored or transmitted by a HIPAA covered entity, such as a health plan or healthcare provider, or by a business associate working on its behalf. It covers information about a person’s physical or mental health, the care they received or payment for that care, when linked to identifiers like a name, address, date of birth, medical record number or email address. PHI can be on paper, spoken or electronic. This entry is an overview for buyers, not legal advice.

At a glance

  • PHI is a US HIPAA concept: it depends on both the data (identifiable health information) and who holds it (a covered entity or business associate).
  • It covers PHI in any form; electronic PHI (ePHI) is the subset the HIPAA Security Rule focuses on.
  • Properly de-identified data is not PHI.
  • Providers that handle PHI for a covered entity are generally business associates and sign a business associate agreement.
  • Some records are excluded, such as employment records a covered entity holds as an employer.

What problem it solves

Health information is among the most sensitive data a person has, and it flows through many hands: clinics, insurers, billing companies, labs, IT providers and contact centers. The PHI concept draws a clear line around what HIPAA protects, so organizations know which data needs safeguards, limits on use and disclosure, patient rights handling and breach notification.

For buyers, the practical value is scoping. If you know where PHI lives, which systems touch it and which providers can reach it, you know where HIPAA obligations apply and which contracts need a business associate agreement (BAA).

How it works

Two tests. Information is PHI when it is individually identifiable health information, meaning it relates to health, care or payment and identifies a person or reasonably could, and when a covered entity or business associate holds or transmits it. The same blood pressure reading is PHI in a clinic’s records but may not be in a consumer app that isn’t working for a covered entity.

Covered entities and business associates. Health plans, healthcare clearinghouses and providers that conduct certain electronic transactions are covered entities. Vendors that create, receive, maintain or transmit PHI for them, including cloud hosting, backup, email, UCaaS, contact center and MSP providers, are generally business associates.

Safeguards. The Privacy Rule limits how PHI is used and disclosed. The Security Rule requires administrative, physical and technical safeguards for ePHI, such as access controls, audit controls and transmission security, with encryption a common way to meet them.

De-identification. HIPAA provides two methods: removing a defined list of 18 identifier types, with no actual knowledge that the remaining data could identify someone, or a documented expert determination that the risk is very small. A limited data set, which removes direct identifiers but keeps some dates and location details, remains PHI and can be shared for research, public health or operations under a data use agreement.

Breach notification. An unauthorized acquisition, access, use or disclosure of unsecured PHI can trigger notification duties to individuals, regulators and sometimes the media. See data breach.

Classification. Many organizations tag PHI in their data classification scheme and use data loss prevention (DLP) tools to keep it from leaving approved systems.

When it matters for buyers

  • When a provider will store, process or transmit patient data. Cloud, backup, email, phone, contact center and MSP contracts may all need a BAA.
  • When call recordings, chat transcripts or tickets capture health details. PHI can appear in unexpected systems.
  • When sharing data for analytics or AI. Decide whether it must be de-identified first.
  • When retiring systems. PHI must be retained and disposed of according to your obligations; see your data retention policy.

Our governance, risk and compliance overview covers help with HIPAA programs and provider oversight.

Questions to ask vendors

  • Will you sign a business associate agreement for this specific service?
  • Which features, regions or products are excluded from your HIPAA-eligible offering?
  • Is PHI encrypted in transit and at rest, and who controls the keys?
  • Which of your staff and subcontractors could access our PHI, and how is that access logged?
  • How quickly will you notify us of a suspected breach involving PHI?
  • How do you return or destroy PHI when the contract ends?

How it differs from PII

Personally identifiable information (PII) is a broad term for any data that can identify a person, used across many laws and policies, and its exact definition varies by law. PHI is narrower and defined by HIPAA: identifiable health, care or payment information held by covered entities and business associates. Most PHI includes PII, but plenty of PII, such as a customer list or employee directory, isn’t PHI. Data can also be health-related without being PHI if no covered entity or business associate is involved, though state privacy laws may still protect it.

Frequently Asked Questions

What is the difference between PHI and ePHI?
ePHI, or electronic protected health information, is the subset of PHI that is stored or transmitted electronically. The HIPAA Privacy Rule covers PHI in any form, including paper and spoken words, while the Security Rule's technical safeguards focus on ePHI.
Is all health information PHI?
No. Health information is PHI under HIPAA only when it is individually identifiable and held or transmitted by a covered entity or a business associate. The same fitness-app data or employee sick note may fall outside HIPAA, though other privacy laws can still apply.
Does de-identified data count as PHI?
Not if it has been properly de-identified under HIPAA's methods: either removing a defined list of identifiers with no actual knowledge that the rest could identify someone, or an expert's documented determination that the risk of identification is very small.
Do our IT and cloud providers handle PHI?
If they create, receive, maintain or transmit PHI for you, they are generally business associates and need a business associate agreement, even if they never look at the data. Confirm specific cases with counsel; this is not legal advice.

You Don’t Need Another Sales Call. You Need an Answer.

30 minutes. No pitch. Just an honest conversation about where you are, what you need, and whether working together makes sense.

We use your details to set up and prepare for the call, and send the newsletter only if you ask for it. Privacy policy.