What Is PHI (Protected Health Information)? Complete Guide
Quick Answer
Protected Health Information (PHI) is any health information that can be linked to or identifies an individual and is created, received, maintained, or transmitted by a covered entity or business associate. PHI includes 18 specific identifiers: names, addresses, birthdates, phone numbers, email addresses, medical record numbers, health plan IDs, and more. HIPAA regulations protect PHI in all forms—electronic (ePHI), paper, and oral. De-identification removes PHI status, allowing use without HIPAA restrictions, through either safe harbor or expert determination methods.
Defining Protected Health Information (PHI)
Protected Health Information is a cornerstone concept in HIPAA compliance. Understanding exactly what qualifies as PHI is essential because HIPAA's entire compliance framework revolves around protecting PHI.
HIPAA defines PHI as health information that can be linked to or identifies an individual, created, received, maintained, or transmitted by a covered entity or business associate. This definition encompasses far more than people typically realize—it's not just diagnoses and medications, but any information held in medical records that could identify a person.
The critical insight is that PHI requires two components: (1) health-related information and (2) a link to a specific individual. Information about health conditions is only PHI if it can be connected to identify who has that condition. This is why de-identification is possible—removing the identification elements removes the PHI status.
The 18 PHI Identifiers
HIPAA specifies 18 identifiers that, when linked with health information, make it PHI. If your organization removes or obscures all 18 identifiers, the remaining information is considered de-identified and no longer requires HIPAA protection:
Types of PHI: ePHI, Verbal, and Paper
PHI exists in multiple forms, and HIPAA protections apply to all of them:
Electronic Protected Health Information (ePHI)
ePHI is PHI that exists in electronic format—in electronic health records (EHRs), emails, text messages, cloud storage, databases, or any digital form. The HIPAA Security Rule specifically addresses ePHI, requiring encryption, access controls, audit logs, and other technical safeguards. ePHI is particularly vulnerable to breaches through hacking, accidental transmission, or unauthorized access.
Verbal PHI
Verbal PHI is information shared orally—when a patient discusses their health with a provider, when a nurse calls a patient with test results, or when staff discuss patient cases in hallways. Verbal PHI requires safeguards such as privacy policies, training staff to speak quietly about patient matters, and limiting discussions to authorized personnel. Many HIPAA violations occur through careless verbal disclosures.
Paper PHI
Paper PHI exists in medical records, test reports, billing statements, and other physical documents. Paper PHI requires physical safeguards such as locked file cabinets, restricted access to paper records, secure destruction of documents, and policies governing who can access physical records.
Examples of What Is and Isn't PHI
Understanding these distinctions helps clarify what your organization must protect:
Examples of PHI
- "John Smith diagnosed with diabetes in 2024" - name + medical condition = PHI
- "Patient at 123 Main Street has hypertension" - address + condition = PHI
- "MRN 987654: pneumonia treatment" - medical record number + condition = PHI
- A photo of a patient that shows their face - identifying image = PHI
- "Patient born 3/15/1985 undergoing chemotherapy" - birthdate + condition = PHI
- An email discussing a patient's psychiatric history - linked to identified person = PHI
Examples of NOT PHI (De-identified)
- "A 38-year-old with diabetes" - no identifiable link to a specific person
- "Patient received surgery on 3/20" - date only, no name or MRN attached
- Statistical summary: "10% of patients in our practice have hypertension" - aggregate data
- A photo of a histopathology slide - images of pathology specimens are excluded
- "Northeast region: pneumonia rates increased 5%" - geographic information without identifiers
- Research data with names/addresses/SSNs/MRNs removed, using only age and state
De-Identification Methods
De-identification removes the PHI status from health information, allowing its use without HIPAA restrictions. HIPAA recognizes two methods:
Safe Harbor Method
Remove all 18 identifiers from the health information. If you have a dataset with patient names, SSNs, birthdates, medical record numbers, and addresses, remove all these elements. The remaining data is considered de-identified and can be used freely without HIPAA restrictions. You must also ensure that you have no actual knowledge that the remaining information can be used to identify the individual. This is the most straightforward method but requires thorough removal of all identifying elements.
Expert Determination Method
Retain the data but hire a qualified statistician or de-identification expert to evaluate whether there's a very small risk that the remaining data could be re-identified. The expert applies statistical methods to determine if, when combined with other publicly available datasets, the information could reasonably identify someone. This method allows retention of some data but requires expert evaluation and documentation. It's more complex and expensive than safe harbor.
Common Mistakes in Identifying PHI
Organizations frequently misunderstand what qualifies as PHI:
- Underestimating indirect identifiers: Not realizing that combinations of information (age + rare condition + city) can identify someone even without names or SSNs.
- Forgetting about dates: Leaving discharge dates, birthdates, or other specific dates in "de-identified" datasets, which can identify individuals.
- Overlooking geographic information: Including zip codes or city information that, combined with other data, can identify patients.
- Not protecting verbal PHI: Failing to implement confidentiality procedures for conversations, assuming only written records need protection.
- Inadequate paper record security: Leaving medical records on desks, in unsecured areas, or not implementing proper destruction procedures.
- Sharing de-identified data inappropriately: Assuming de-identified data needs no protections at all once it leaves your organization.
Business Associate Responsibilities for PHI
Business associates who handle PHI on behalf of covered entities must implement the same protections as covered entities. Your Business Associate Agreements must specify how business associates will protect PHI, including:
- Physical safeguards for paper and electronic PHI
- Access restrictions limiting staff to necessary PHI
- Encryption of ePHI in transit and at rest
- Breach notification procedures
- Secure data destruction when contracts end
- Workforce training on PHI protection
Frequently Asked Questions
Properly Classify and Protect PHI in Your Organization
Understanding exactly what qualifies as PHI in your organization and how to protect it is fundamental to HIPAA compliance. Medcurity helps healthcare organizations classify information, implement appropriate safeguards, and develop de-identification procedures that comply with HIPAA standards.
Get PHI Classification Audit →