Protected Health Information
Protected Health Information (PHI) is personal health information that can identify an individual and that is held or transmitted by organizations subject to the U.S. HIPAA rules, such as healthcare providers and their service partners. It generally covers details about a person's health condition, the care they receive, and payment for that care when combined with information that identifies them. PHI is a concept defined under U.S. federal law and does not describe health data protection requirements in other jurisdictions.
Under the HIPAA Privacy Rule, PHI is 'individually identifiable health information' that is held or transmitted by a covered entity or its business associate, in any form or medium. It encompasses information relating to an individual's past, present, or future physical or mental health or condition, the provision of health care, or payment for health care, where that information identifies the individual or provides a reasonable basis to identify them. In practice, this includes health, treatment, and payment information maintained within a designated record set, along with associated identifiers. PHI is distinct from de-identified health information, which falls outside HIPAA's protections once identifiers are removed under the applicable standard. This definition reflects U.S. federal regulatory scope and applies to entities regulated as covered entities or business associates; readers should verify the precise regulatory text and any amendments against the current official HHS source, as HIPAA does not govern health data held by entities outside its defined scope.
Why it matters
PHI sits at the center of U.S. healthcare privacy compliance because it defines the scope of what the HIPAA Privacy Rule protects. When information qualifies as PHI, the covered entity or business associate holding it is generally subject to obligations governing how that information may be used, disclosed, and safeguarded. Misclassifying data—treating PHI as ordinary business data, or failing to recognize that a service partner is handling it—can lead to unauthorized uses or disclosures that fall within HIPAA's enforcement scope. For compliance officers, correctly identifying what constitutes PHI is therefore a prerequisite to nearly every downstream control decision.
The concept also determines who bears responsibility. Because the Privacy Rule protects individually identifiable health information held or transmitted by a covered entity or its business associate, the same underlying health data may or may not be PHI depending on which entity holds it and in what capacity. This makes contractual and organizational context, not just the content of the data, decisive. Health information held by an organization outside HIPAA's defined scope is not PHI and is not governed by these federal protections, even if it is sensitive.
Equally important is the boundary between PHI and de-identified information. Health data that has had identifiers removed under the applicable standard falls outside HIPAA's protections, which is why de-identification is a significant compliance lever for research, analytics, and secondary use. Because interpretations and regulatory text are periodically amended, and because application to specific data flows requires professional judgment, readers should verify particular classifications against the current official HHS source rather than relying on general characterizations.
Who it's relevant to
Inside PHI
Common questions
Answers to the questions practitioners most commonly ask about PHI.

