Get HIPAA Audit →

What Is PHI (Protected Health Information)? Complete Guide

Quick Answer

Protected Health Information (PHI) is any health information that can be linked to or identifies an individual and is created, received, maintained, or transmitted by a covered entity or business associate. PHI includes 18 specific identifiers: names, addresses, birthdates, phone numbers, email addresses, medical record numbers, health plan IDs, and more. HIPAA regulations protect PHI in all forms—electronic (ePHI), paper, and oral. De-identification removes PHI status, allowing use without HIPAA restrictions, through either safe harbor or expert determination methods.

Defining Protected Health Information (PHI)

Protected Health Information is a cornerstone concept in HIPAA compliance. Understanding exactly what qualifies as PHI is essential because HIPAA's entire compliance framework revolves around protecting PHI.

HIPAA defines PHI as health information that can be linked to or identifies an individual, created, received, maintained, or transmitted by a covered entity or business associate. This definition encompasses far more than people typically realize—it's not just diagnoses and medications, but any information held in medical records that could identify a person.

The critical insight is that PHI requires two components: (1) health-related information and (2) a link to a specific individual. Information about health conditions is only PHI if it can be connected to identify who has that condition. This is why de-identification is possible—removing the identification elements removes the PHI status.

The 18 PHI Identifiers

HIPAA specifies 18 identifiers that, when linked with health information, make it PHI. If your organization removes or obscures all 18 identifiers, the remaining information is considered de-identified and no longer requires HIPAA protection:

1. Names
Patient's first, last, and middle names, nicknames, or initials that identify the individual.
2. Geographic Subdivisions
City, county, precinct, zip codes. (States are acceptable for de-identification.)
3. Birthdates
Full dates of birth, including month and year. Safe harbor allows year only for age 89 and older.
4. Dates
Admission, discharge, death dates, and other dates directly related to care (except year).
5. Phone Numbers
All telephone numbers including home, work, mobile, and fax numbers.
6. Email Addresses
All email addresses associated with the individual.
7. Social Security Numbers
Complete or partial SSNs identifying an individual.
8. Medical Record Numbers
Unique identifiers assigned by healthcare providers to individual patient records.
9. Health Plan ID Numbers
Insurance policy, member, or contract numbers.
10. Account Numbers
Patient bank or financial account numbers used in healthcare billing.
11. Vehicle Identification Numbers (VINs)
License plate or VIN numbers from vehicles.
12. Device Identifiers
Serial numbers or other identifiers of medical implants or devices (pacemakers, prosthetics).
13. URLs
Web addresses that identify an individual (such as personal website URLs).
14. IP Addresses
Internet protocol addresses of computers used by the individual.
15. Biometric Data
Fingerprints, voice prints, or other biometric identifiers.
16. Photographic Images
Photos or any image from which the individual can be recognized, except images of histopathology slides and imaging scans.
17. Unique Identifying Numbers
Any other unique identifiers assigned to individuals (license numbers, passport numbers, etc.).
18. Addresses
Street addresses (cities, counties, and zip codes covered separately).

Types of PHI: ePHI, Verbal, and Paper

PHI exists in multiple forms, and HIPAA protections apply to all of them:

Electronic Protected Health Information (ePHI)

ePHI is PHI that exists in electronic format—in electronic health records (EHRs), emails, text messages, cloud storage, databases, or any digital form. The HIPAA Security Rule specifically addresses ePHI, requiring encryption, access controls, audit logs, and other technical safeguards. ePHI is particularly vulnerable to breaches through hacking, accidental transmission, or unauthorized access.

Verbal PHI

Verbal PHI is information shared orally—when a patient discusses their health with a provider, when a nurse calls a patient with test results, or when staff discuss patient cases in hallways. Verbal PHI requires safeguards such as privacy policies, training staff to speak quietly about patient matters, and limiting discussions to authorized personnel. Many HIPAA violations occur through careless verbal disclosures.

Paper PHI

Paper PHI exists in medical records, test reports, billing statements, and other physical documents. Paper PHI requires physical safeguards such as locked file cabinets, restricted access to paper records, secure destruction of documents, and policies governing who can access physical records.

Examples of What Is and Isn't PHI

Understanding these distinctions helps clarify what your organization must protect:

Examples of PHI

Examples of NOT PHI (De-identified)

De-Identification Methods

De-identification removes the PHI status from health information, allowing its use without HIPAA restrictions. HIPAA recognizes two methods:

Safe Harbor Method

Remove all 18 identifiers from the health information. If you have a dataset with patient names, SSNs, birthdates, medical record numbers, and addresses, remove all these elements. The remaining data is considered de-identified and can be used freely without HIPAA restrictions. You must also ensure that you have no actual knowledge that the remaining information can be used to identify the individual. This is the most straightforward method but requires thorough removal of all identifying elements.

Expert Determination Method

Retain the data but hire a qualified statistician or de-identification expert to evaluate whether there's a very small risk that the remaining data could be re-identified. The expert applies statistical methods to determine if, when combined with other publicly available datasets, the information could reasonably identify someone. This method allows retention of some data but requires expert evaluation and documentation. It's more complex and expensive than safe harbor.

Common Mistakes in Identifying PHI

Organizations frequently misunderstand what qualifies as PHI:

Business Associate Responsibilities for PHI

Business associates who handle PHI on behalf of covered entities must implement the same protections as covered entities. Your Business Associate Agreements must specify how business associates will protect PHI, including:

Frequently Asked Questions

Is a patient's full address always PHI?
Addresses are PHI identifiers. State alone is not considered an identifier for safe harbor purposes, but city, county, precinct, and zip codes are. So a patient's state can be disclosed in de-identified data, but street address, city, or zip code cannot without removing the PHI status.
Is age always PHI?
Age alone is not an identifier. However, birthdates are identifiers. For safe harbor de-identification, you can use age in years, but cannot use birthdate with month and day. For ages 89 and older, safe harbor requires grouping as "89 or older" to prevent re-identification.
Can I use a patient's initials instead of their full name?
Initials are not safe harbor de-identification. The regulation requires removing names, and initials that identify an individual (like "B.S." for a well-known person) are still identifiers. Safe harbor requires complete removal of identifiers.
Is a medical record number (MRN) always PHI?
Yes, medical record numbers are direct identifiers. They must be removed for safe harbor de-identification. If you retain an MRN or use a code that could be linked to identify individuals, you need expert determination to justify de-identification.
What about genetic data—is it PHI?
Genetic data itself is health information. If it can be linked to or identify an individual, it's PHI. Genetic information that's de-identified according to safe harbor or expert determination methods is not PHI.
Does research using de-identified data need IRB approval?
Research using properly de-identified data is not considered human subjects research and may not require IRB approval under HIPAA. However, other regulations or your institution's policies may still require IRB review. Check with your IRB even for de-identified research.
Can I re-identify de-identified data?
Once data is properly de-identified, HIPAA allows you to re-identify it, but you cannot do so in ways that would constitute a violation of the original patient's privacy. Many organizations maintain code sheets linking de-identified data back to individuals for research purposes.
What's considered a breach of PHI?
A breach is unauthorized acquisition, access, use, or disclosure of PHI that compromises its security or privacy. If properly de-identified data is breached, it's not a HIPAA breach because it's no longer PHI.

Properly Classify and Protect PHI in Your Organization

Understanding exactly what qualifies as PHI in your organization and how to protect it is fundamental to HIPAA compliance. Medcurity helps healthcare organizations classify information, implement appropriate safeguards, and develop de-identification procedures that comply with HIPAA standards.

Get PHI Classification Audit →