Protected health information (PHI) is health information that can identify a person and that is created, received, stored or transmitted by a HIPAA covered entity, such as a health plan or healthcare provider, or by a business associate working on its behalf. It covers information about a person’s physical or mental health, the care they received or payment for that care, when linked to identifiers like a name, address, date of birth, medical record number or email address. PHI can be on paper, spoken or electronic. This entry is an overview for buyers, not legal advice.
At a glance
- PHI is a US HIPAA concept: it depends on both the data (identifiable health information) and who holds it (a covered entity or business associate).
- It covers PHI in any form; electronic PHI (ePHI) is the subset the HIPAA Security Rule focuses on.
- Properly de-identified data is not PHI.
- Providers that handle PHI for a covered entity are generally business associates and sign a business associate agreement.
- Some records are excluded, such as employment records a covered entity holds as an employer.
What problem it solves
Health information is among the most sensitive data a person has, and it flows through many hands: clinics, insurers, billing companies, labs, IT providers and contact centers. The PHI concept draws a clear line around what HIPAA protects, so organizations know which data needs safeguards, limits on use and disclosure, patient rights handling and breach notification.
For buyers, the practical value is scoping. If you know where PHI lives, which systems touch it and which providers can reach it, you know where HIPAA obligations apply and which contracts need a business associate agreement (BAA).
How it works
Two tests. Information is PHI when it is individually identifiable health information, meaning it relates to health, care or payment and identifies a person or reasonably could, and when a covered entity or business associate holds or transmits it. The same blood pressure reading is PHI in a clinic’s records but may not be in a consumer app that isn’t working for a covered entity.
Covered entities and business associates. Health plans, healthcare clearinghouses and providers that conduct certain electronic transactions are covered entities. Vendors that create, receive, maintain or transmit PHI for them, including cloud hosting, backup, email, UCaaS, contact center and MSP providers, are generally business associates.
Safeguards. The Privacy Rule limits how PHI is used and disclosed. The Security Rule requires administrative, physical and technical safeguards for ePHI, such as access controls, audit controls and transmission security, with encryption a common way to meet them.
De-identification. HIPAA provides two methods: removing a defined list of 18 identifier types, with no actual knowledge that the remaining data could identify someone, or a documented expert determination that the risk is very small. A limited data set, which removes direct identifiers but keeps some dates and location details, remains PHI and can be shared for research, public health or operations under a data use agreement.
Breach notification. An unauthorized acquisition, access, use or disclosure of unsecured PHI can trigger notification duties to individuals, regulators and sometimes the media. See data breach.
Classification. Many organizations tag PHI in their data classification scheme and use data loss prevention (DLP) tools to keep it from leaving approved systems.
When it matters for buyers
- When a provider will store, process or transmit patient data. Cloud, backup, email, phone, contact center and MSP contracts may all need a BAA.
- When call recordings, chat transcripts or tickets capture health details. PHI can appear in unexpected systems.
- When sharing data for analytics or AI. Decide whether it must be de-identified first.
- When retiring systems. PHI must be retained and disposed of according to your obligations; see your data retention policy.
Our governance, risk and compliance overview covers help with HIPAA programs and provider oversight.
Questions to ask vendors
- Will you sign a business associate agreement for this specific service?
- Which features, regions or products are excluded from your HIPAA-eligible offering?
- Is PHI encrypted in transit and at rest, and who controls the keys?
- Which of your staff and subcontractors could access our PHI, and how is that access logged?
- How quickly will you notify us of a suspected breach involving PHI?
- How do you return or destroy PHI when the contract ends?
How it differs from PII
Personally identifiable information (PII) is a broad term for any data that can identify a person, used across many laws and policies, and its exact definition varies by law. PHI is narrower and defined by HIPAA: identifiable health, care or payment information held by covered entities and business associates. Most PHI includes PII, but plenty of PII, such as a customer list or employee directory, isn’t PHI. Data can also be health-related without being PHI if no covered entity or business associate is involved, though state privacy laws may still protect it.
