Skip to main content
The state of ai impact assessment
Category: Data Types & Classification

Protected Health Information

Also known as: PHI, Individually Identifiable Health Information
Simply put

Protected Health Information (PHI) is personal health information that can identify an individual and that is held or transmitted by organizations subject to the U.S. HIPAA rules, such as healthcare providers and their service partners. It generally covers details about a person's health condition, the care they receive, and payment for that care when combined with information that identifies them. PHI is a concept defined under U.S. federal law and does not describe health data protection requirements in other jurisdictions.

Formal definition

Under the HIPAA Privacy Rule, PHI is 'individually identifiable health information' that is held or transmitted by a covered entity or its business associate, in any form or medium. It encompasses information relating to an individual's past, present, or future physical or mental health or condition, the provision of health care, or payment for health care, where that information identifies the individual or provides a reasonable basis to identify them. In practice, this includes health, treatment, and payment information maintained within a designated record set, along with associated identifiers. PHI is distinct from de-identified health information, which falls outside HIPAA's protections once identifiers are removed under the applicable standard. This definition reflects U.S. federal regulatory scope and applies to entities regulated as covered entities or business associates; readers should verify the precise regulatory text and any amendments against the current official HHS source, as HIPAA does not govern health data held by entities outside its defined scope.

Why it matters

PHI sits at the center of U.S. healthcare privacy compliance because it defines the scope of what the HIPAA Privacy Rule protects. When information qualifies as PHI, the covered entity or business associate holding it is generally subject to obligations governing how that information may be used, disclosed, and safeguarded. Misclassifying data—treating PHI as ordinary business data, or failing to recognize that a service partner is handling it—can lead to unauthorized uses or disclosures that fall within HIPAA's enforcement scope. For compliance officers, correctly identifying what constitutes PHI is therefore a prerequisite to nearly every downstream control decision.

The concept also determines who bears responsibility. Because the Privacy Rule protects individually identifiable health information held or transmitted by a covered entity or its business associate, the same underlying health data may or may not be PHI depending on which entity holds it and in what capacity. This makes contractual and organizational context, not just the content of the data, decisive. Health information held by an organization outside HIPAA's defined scope is not PHI and is not governed by these federal protections, even if it is sensitive.

Equally important is the boundary between PHI and de-identified information. Health data that has had identifiers removed under the applicable standard falls outside HIPAA's protections, which is why de-identification is a significant compliance lever for research, analytics, and secondary use. Because interpretations and regulatory text are periodically amended, and because application to specific data flows requires professional judgment, readers should verify particular classifications against the current official HHS source rather than relying on general characterizations.

Who it's relevant to

Healthcare providers and covered entities
Organizations regulated as covered entities are directly responsible for protecting PHI they hold or transmit. They need to identify which of their records qualify as individually identifiable health information within a designated record set so that appropriate use, disclosure, and safeguarding practices apply. Whether a specific record qualifies depends on the facts and the current regulatory text.
Business associates and service partners
Service partners that handle health, treatment, or payment information on behalf of covered entities may themselves be business associates subject to HIPAA obligations. Because the Privacy Rule extends to information held or transmitted by a business associate, these organizations should determine whether the data they process constitutes PHI and confirm their status against the applicable regulatory scope.
Compliance officers and privacy specialists
Those responsible for HIPAA compliance rely on the PHI definition to scope policies, controls, and data-handling procedures. Distinguishing PHI from de-identified information and from health data held outside HIPAA's scope is central to that work. Given that HIPAA is periodically amended, classifications should be validated against the current official HHS source.
Researchers and analytics teams
Teams using health data for secondary purposes must understand where PHI ends and de-identified information begins, since information de-identified under the applicable standard generally falls outside HIPAA's protections. This boundary affects how data may be used, though its application to a particular dataset requires professional judgment.

Inside PHI

Individually Identifiable Health Information
PHI consists of individually identifiable health information relating to a person's past, present, or future physical or mental health condition, the provision of health care, or payment for that care. The information must be capable of identifying the individual, either directly or in combination with other data.
Identifiers Linked to Health Information
PHI generally includes health information tied to identifiers such as names, geographic subdivisions, dates related to an individual, contact details, and other data elements that can single out a person. Under HIPAA's de-identification approaches, removing specified identifiers (or obtaining an expert determination that re-identification risk is very small) can render information no longer PHI.
Covered Media and Formats
PHI may exist in any form or medium, including electronic, paper, and oral communications. Electronic PHI (ePHI) is the subset held or transmitted in electronic form and is the specific focus of the HIPAA Security Rule.
Jurisdictional and Regulatory Scope
PHI is a concept defined under U.S. federal law, principally through HIPAA and its associated rules, and generally applies to covered entities (such as health plans, health care clearinghouses, and certain health care providers) and their business associates. It is a sector-specific U.S. framework and does not automatically govern health data in other jurisdictions, which may apply their own regimes.

Common questions

Answers to the questions practitioners most commonly ask about PHI.

Does HIPAA protect all health information, no matter who holds it?
No. HIPAA's protections for PHI apply only to information held or transmitted by covered entities (such as health plans, health care clearinghouses, and most health care providers) and their business associates. Health information you record about yourself, or data held by organizations that are not covered entities or business associates, generally falls outside HIPAA's scope, even though it may describe your health. Other laws or contractual obligations could apply in those situations, so the absence of HIPAA coverage does not mean the information is entirely unregulated. Application to specific circumstances requires professional judgment, and readers should verify against the current official text of HIPAA and its implementing regulations.
Are PHI under HIPAA and personal data under the GDPR the same thing?
No. They are distinct concepts arising under different legal regimes and jurisdictions. PHI is a category defined under U.S. HIPAA rules and is tied to covered entities and business associates in the health care context. Personal data under the EU GDPR is a broader category covering information relating to an identified or identifiable natural person, with a special category for health-related data subject to heightened conditions. The two frameworks differ in scope, definitions, obligated parties, and territorial reach, so a single data set may be treated differently under each. An organization subject to both would need to assess its obligations under each regime separately, and application to particular circumstances requires professional judgment.
How does de-identification affect whether information counts as PHI?
Health information that has been de-identified in accordance with the standards set out in the HIPAA rules is generally no longer treated as PHI and, in most cases, is not subject to the same restrictions on use and disclosure. HIPAA describes recognized methods for achieving de-identification. The practical difficulty lies in applying those methods correctly and in managing any residual re-identification risk. Because interpretations and techniques evolve, organizations should verify the applicable de-identification standard against the current official text and involve qualified personnel when determining whether a given data set qualifies.
What is the practical distinction between a covered entity and a business associate for PHI handling?
Both may handle PHI, but they occupy different positions. A covered entity generally originates or holds PHI in the course of health care activities, while a business associate performs functions or services on behalf of a covered entity that involve access to PHI. The distinction matters operationally because obligations, and the contractual arrangements that govern them, differ between the two roles. Determining which role an organization occupies for a given activity is fact-specific, and readers should confirm the applicable definitions against the current official text rather than assuming a single classification applies across all engagements.
How should organizations approach identifying what qualifies as PHI within their systems?
As a practical matter, organizations often begin by mapping where health-related information enters, is stored, and flows through their systems, and by determining whether they act as a covered entity or business associate for those data. Because PHI is defined by its context and the parties involved rather than by data format alone, the analysis is generally fact-specific. This entry describes the concept qualitatively and does not substitute for a documented data inventory or for professional judgment about particular data sets. Verify classifications against the current authoritative text.
Does the safeguarding of PHI concern privacy, security, or both?
In practice it involves both, but they are distinct concerns. Privacy generally addresses the permitted uses and disclosures of PHI and the rights of individuals regarding their information, while security generally addresses the administrative, physical, and technical safeguards that protect PHI from unauthorized access or compromise. HIPAA addresses these dimensions through separate but related requirements. Treating them as interchangeable can lead to gaps, so organizations typically address each explicitly. Specific obligations depend on the facts and should be verified against the current official text, with professional judgment applied to particular circumstances.

Common misconceptions

Any health-related information a person holds is automatically PHI subject to HIPAA.
PHI status under HIPAA generally depends on who holds the information. Health information handled by a covered entity or its business associate is typically PHI, whereas similar data collected by organizations outside HIPAA's scope, such as many consumer health apps or wearables, may fall under other laws or none at all rather than HIPAA. Readers should verify the applicable regime against the current official text.
PHI and ePHI are interchangeable terms.
ePHI is the electronic subset of PHI. PHI can exist in paper, oral, or electronic form, but the HIPAA Security Rule's safeguard requirements are directed specifically at ePHI. Treating the two as identical can lead to misapplying which safeguards are required for which medium.
Stripping a name from a record automatically makes it no longer PHI.
De-identification under HIPAA generally requires more than removing a name. It typically involves either removing a defined set of identifiers or obtaining an expert determination that re-identification risk is very small. Partially masked data that can still be linked to an individual may remain PHI. Consult the current official standard to confirm the applicable method.

Best practices

Determine at the outset whether your organization is acting as a covered entity, a business associate, or falls outside HIPAA's scope, since PHI obligations flow from that status.
Inventory where PHI resides across electronic, paper, and oral forms, and separately identify ePHI so that Security Rule safeguards can be applied to the correct data.
Apply a recognized de-identification method fully rather than assuming that removing a single identifier such as a name is sufficient to remove data from PHI status.
Confirm which jurisdiction's rules apply to a given data set, and do not assume HIPAA governs health data collected outside its scope or in other jurisdictions.
Verify current identifier lists, de-identification standards, and rule requirements against the latest authoritative HIPAA text, as regulations and guidance are periodically amended.
Treat this entry as informational and involve qualified compliance or legal professionals when applying PHI requirements to specific circumstances.
a promotional banner asking how ready are you for PCI DSS 4.0? With a call-to-action to get the checklist now.