What Is Protected Health Information PHI? Protected Health Information (PHI) encompasses any health-related data that can be linked to a specific individual and is created, stored, or transmitted by a HIPAA-covered organization or its authorized business associates, making it a critical focus for compliance and cybersecurity efforts. That includes the obvious items like diagnoses, treatment records, and insurance details, but it also includes anything that links health data to an individual, down to an appointment date or a full-face photo. The part most explainers miss is that PHI status depends on context: the same data point can be protected inside your records system and not protected once it is properly stripped of identifiers. Teams most often leak PHI because they assume that removing a name makes data safe, when the rules are far broader than that.
I have helped healthcare organizations sort out what they actually have to protect for years, and the confusion almost always lives in the gray zone, not the obvious cases. Let us clear up both.
The 5 Things to Understand About PHI
Here is the shape of the concept before the detail:
- PHI links health to a person. It is health information combined with anything that identifies who the person is.
- There are 18 identifiers. HIPAA names specific data types, from names and dates to device IDs and photos, that can make data identifiable.
- Context decides protection. The same data can be PHI in one setting and not in another, depending on whether it is identifiable.
- Electronic PHI has extra rules. PHI stored or sent digitally, called ePHI, carries specific security requirements.
- De-identification is strict. Data only stops being PHI when it meets a formal HIPAA standard, not when you simply delete the name.
Why “No Name Attached” Is a Dangerous Assumption
The most common and costly misunderstanding about protected health information is the belief that data is safe once a name is removed. A staff member shares a spreadsheet of appointment dates and zip codes, confident that without names it cannot be PHI, and a privacy violation is born. HIPAA does not work that way. Information is protected when it can be tied to an individual through any of a broad set of identifiers, and a combination of seemingly harmless details, a birth date, a zip code, and an admission date, can re-identify a person even with no name in sight.
This is why the HHS HIPAA Privacy Rule defines What Is Protected Health Information PHI by identifiability rather than by a single field. The question is never “does this have a name on it,” it is “could this be linked back to a specific person.” Understanding that distinction is the difference between a team that protects data correctly and one that leaks it while believing it is careful. Our guide on how to secure PHI builds on this foundation with the practical controls.
There is a fair nuance worth holding. Not every piece of health-related data is PHI. Health information a person enters into a consumer fitness app that has no connection to a covered organization generally falls outside HIPAA. The rule attaches to who holds the data and how it is handled, not to the topic alone. So the honest answer to “is this PHI” is often “it depends on the context,” which is exactly why the contextual view matters.
The 18 HIPAA Identifiers, in Plain Terms
HIPAA names eighteen categories of identifiers that can make health information identifiable. They include names, geographic details smaller than a state, all dates tied to an individual such as birth or admission dates, phone and fax numbers, email addresses, Social Security numbers, medical record numbers, health plan numbers, account numbers, certificate or license numbers, vehicle identifiers, device identifiers, web URLs, IP addresses, biometric data like fingerprints, full-face photographs, and any other unique identifying code.
The practical takeaway is not to memorize the list but to recognize how broad it is. Most people expect names and Social Security numbers. Fewer realize that an IP address, a photo, or a device serial number can carry identifiability too. When you handle health data, the safe instinct is to treat any of these eighteen as a thread that could lead back to a person.
What is the difference between PHI and ePHI?
Electronic protected health information, or ePHI, is simply What Is Protected Health Information PHI that is created, stored, or transmitted in digital form, and it carries additional security obligations under the HIPAA Security Rule. A paper chart in a locked cabinet is PHI, while that same record in your records system, in an email, or on a laptop is ePHI. The distinction matters because digital data faces digital threats, so ePHI requires safeguards like access controls, encryption, and audit logging that a paper record does not. Most modern healthcare data is ePHI, which is why technical security has become inseparable from privacy compliance, the focus of our cybersecurity compliance work.
When does data stop being PHI?
Data stops being protected only when it is properly de-identified to a formal standard, not when someone deletes the obvious fields. HHS describes two accepted methods in its de-identification guidance: the Safe Harbor method, which removes all eighteen identifier categories, and Expert Determination, where a qualified expert formally certifies that re-identification risk is very small. Holding both sides honestly, de-identified data is genuinely useful for research and analytics and falls outside What Is Protected Health Information PHI when done correctly, but informal “I just took the names out” is not de-identification and leaves the data protected. The gap between those two is where many violations happen.

Who Has to Protect PHI?
PHI obligations fall on covered entities, which include healthcare providers, health plans, and healthcare clearinghouses, and on their business associates, meaning any vendor that handles PHI on their behalf. That second group surprises people. An IT provider, a billing company, a cloud host, or a shredding service that touches PHI becomes a business associate with real obligations. This is why everyday handling matters so much, and why training staff on protecting patient information in the workplace is as important as the technical controls. A single employee emailing a patient list to a personal account can create a breach regardless of how strong the systems are.
The practical lesson for any organization that touches health data is to map where PHI actually lives before trying to protect it. In our experience, leaders are often surprised by how many copies exist: the records system everyone expects, but also spreadsheets exported for a report, attachments sitting in email, scanned documents on a shared drive, and backups in a cloud account nobody reviews. Each of those copies is protected health information, and each one is a place a leak can happen. A data map that lists every system, device, and vendor holding PHI turns an abstract obligation into a concrete checklist. Without that map, an organization protects the systems it remembers and quietly exposes the ones it forgot, which is exactly where many real incidents begin.
Frequently Asked Questions
Is a patient’s name alone considered PHI?
A name on its own, with no connection to health information or a healthcare context, is generally just personal information rather than PHI. It becomes protected health information when it is combined with health data or held by a covered organization in a way that links it to care, treatment, or payment. The protection comes from the connection between identity and health, not the name in isolation.
Are appointment dates PHI?
Yes, when they relate to an identifiable individual receiving care. What Is Protected Health Information PHI treats dates tied to a person, including appointment, admission, and discharge dates, as identifiers, because they can help link records back to a specific patient. This is why sharing a schedule of appointment times, even without names, can still expose protected health information.
Does HIPAA apply to health data in a fitness app?
Usually not, if the app has no relationship with a covered healthcare organization. HIPAA attaches to covered entities and their business associates, so data a consumer enters into a standalone fitness or wellness app generally falls outside it. The same data inside a provider’s system or a HIPAA-covered service would be protected, which shows again that context decides.
What makes PHI “electronic” PHI?
PHI becomes ePHI when it is created, stored, or transmitted in digital form, such as in a records system, an email, a database, or on a device. ePHI carries the HIPAA Security Rule’s technical safeguards, including access controls, encryption, and audit logging. Because nearly all modern health data is electronic, ePHI protection is central to compliance today.
How is data properly de-identified?
HIPAA recognizes two methods: Safe Harbor, which removes all eighteen categories of identifiers, and Expert Determination, where a qualified expert formally certifies that the risk of re-identification is very small. Simply deleting names or obvious fields does not meet either standard, so data handled that way remains protected health information despite the effort.
Get Your PHI Handling Reviewed
Understanding what counts as protected health information is the first step. The harder part is making sure your systems, your vendors, and your staff actually handle it correctly every day. We help healthcare organizations map where PHI lives, tighten the controls around ePHI, and confirm that “de-identified” data really meets the standard. Book a free strategy call and we will walk through your current handling, the gaps most teams miss, and what stronger PHI protection looks like for an organization your size.
PHI Protection and HIPAA Compliance Expertise from Matt Rosenthal
Matt Rosenthal, CEO of Mindcore Technologies, has over 30 years of experience helping healthcare organizations and business associates map where protected health information actually lives across their systems, vendors, and workflows, then build the technical and administrative controls that keep it there. He has seen firsthand how teams remove a patient’s name from a spreadsheet and believe the data is no longer protected, then create a reportable breach through a combination of appointment dates, zip codes, and admission dates that re-identifies every record. Matt leads a team that starts HIPAA engagements with a data inventory that surfaces the copies of PHI everyone expected plus the exported spreadsheets, email attachments, shared drives, and vendor systems that most organizations protect last, after an incident forces the conversation.

