PHI

PHI (protected health information) is any individually identifiable health information, about a person’s condition, care or payment for care, that is held or transmitted by a HIPAA covered entity or its business associate, in any form.

Also called: protected health information, ePHI, individually identifiable health information

Information is PHI when it relates to someone’s past, present or future health, the care they receive, or payment for that care, and it identifies them or could reasonably be used to. HIPAA’s “safe harbor” de-identification method lists 18 identifiers, name, phone number, email, dates other than year, medical record number, voice recordings among them, whose removal takes information out of scope. Electronic PHI (ePHI) is the same information in digital form and is what the Security Rule governs.

On a phone call PHI is created quickly: a caller giving their name and saying why they need an appointment has already produced it. The recording, the transcript, the summary and the calendar entry are all PHI if the business is a covered entity or acting for one.

Information held by organizations outside HIPAA, a fitness app, a general-purpose retailer, is not PHI even when it is about health, although other privacy laws may apply to it.