Skip to main content
Category: Data Protection & Privacy

Protected Health Information

Also known as: PHI, Individually Identifiable Health Information
Simply put

Protected Health Information (PHI) is health information that can be used to identify a specific person and that is held or transmitted by a healthcare organization or one of its partners subject to HIPAA. It covers details about someone's health condition, care, or payment for care, in any form, whether spoken, written, or electronic. Because it identifies real individuals, HIPAA sets federal rules for how it must be protected.

Formal definition

Under the HIPAA Privacy Rule (45 CFR 160.103), PHI is individually identifiable health information held or transmitted by a covered entity or its business associate, in any form or medium, including electronic, paper, and oral. It encompasses information relating to an individual's past, present, or future physical or mental health condition, the provision of health care, or payment for care, where that information either identifies the individual or provides a reasonable basis to identify them. Note that PHI is not limited to information maintained within a designated record set; membership in a designated record set is relevant primarily to patients' right-of-access provisions rather than to whether information qualifies as PHI. Health information that has been properly de-identified in accordance with HIPAA standards is not considered PHI.

Why it matters

PHI sits at the center of healthcare compliance because HIPAA imposes federal obligations on how it is stored, accessed, transmitted, and disclosed. Any organization that qualifies as a covered entity or a business associate must safeguard individually identifiable health information in every form it takes, whether electronic, paper, or spoken. A frequent and consequential misunderstanding is the belief that information only becomes PHI when it lives inside a formal medical record or a 'designated record set.' That is incorrect: under 45 CFR 160.103, PHI is any individually identifiable health information held or transmitted by a covered entity or business associate in any form or medium. The designated record set concept is relevant primarily to patients' right-of-access provisions, not to whether information qualifies as PHI in the first place. Treating PHI too narrowly leaves gaps in protection precisely where regulators expect coverage.

Who it's relevant to

Healthcare organizations (covered entities)
Providers, health plans, and healthcare clearinghouses hold and transmit PHI as part of routine operations and are directly subject to the HIPAA Privacy and Security Rules. Their leadership carries accountability for ensuring that PHI is protected across all forms and media, not just within formal record systems.
Business associates and their subcontractors
Vendors that create, receive, maintain, or transmit PHI on behalf of a covered entity are also bound by HIPAA obligations. A virtual CISO advising such firms should confirm that contractual arrangements and safeguards address PHI in every form the organization actually handles.
Security and compliance leaders, including virtual CISOs
Those responsible for governance and risk need an accurate scope of what counts as PHI to build proportionate controls and avoid the common error of scoping protection only to designated record sets. A vCISO typically advises on strategy, policy, and readiness, while legal and organizational accountability for HIPAA compliance remains with the client organization and its officers.
Teams handling data for research or analytics
Groups that reuse health data should understand that properly de-identified information is not PHI under HIPAA, which affects what protections and permissions apply. Whether de-identification has been performed correctly is a technical and legal determination that should be validated rather than assumed.

Inside PHI

Individually Identifiable Health Information
PHI is health information that relates to an individual's past, present, or future physical or mental health condition, the provision of health care, or payment for that care, and that identifies the individual or provides a reasonable basis to identify them. This is the core definitional element under 45 CFR 160.103.
Held or Transmitted in Any Form or Medium
PHI includes such information in any form or medium, whether electronic, paper, or oral. It is not limited to records stored in a particular system or a designated record set; membership in a designated record set is relevant primarily to patients' right-of-access provisions, not to whether information qualifies as PHI.
Held by a Covered Entity or Business Associate
The information qualifies as PHI when it is held or transmitted by a covered entity (such as a health plan, health care clearinghouse, or covered health care provider) or a business associate acting on their behalf.
Common Identifiers
Identifiers that can link health information to an individual include names, addresses, dates related to an individual, contact numbers, and other data elements that alone or in combination could reasonably identify a person.
Electronic PHI (ePHI)
The subset of PHI that is created, received, maintained, or transmitted in electronic form. ePHI is the specific focus of the HIPAA Security Rule's safeguard requirements, while the Privacy Rule applies to PHI more broadly.

Common questions

Answers to the questions practitioners most commonly ask about PHI.

Does health information only count as PHI if it lives in a formal medical record or designated record set?
No. This is a common misconception. Under 45 CFR 160.103, PHI is any individually identifiable health information that a covered entity or business associate holds or transmits, in any form or medium, whether electronic, paper, or oral. Membership in a designated record set is not a requirement for information to be PHI; the designated record set concept is relevant mainly to a patient's right-of-access provisions, not to whether data qualifies as PHI in the first place. A virtual CISO advising on scope should treat email, chat logs, backups, and informal notes containing identifiable health data as potentially in scope, not just the official chart.
Is protecting PHI purely a technical IT problem that a security tool can solve?
No. Safeguarding PHI is a governance and organizational risk function as much as a technical one. HIPAA's requirements span administrative, physical, and technical safeguards, so policies, workforce training, access governance, business associate agreements, and documented risk analysis matter alongside any technology. A virtual CISO typically advises on this program-level strategy and governance rather than administering the tools directly. Treating PHI protection as something a single product guarantees is a mistake an experienced practitioner would correct, since accountability for compliant handling remains with the organization and its officers.
How does a virtual CISO typically help an organization identify where its PHI actually resides?
A virtual CISO often guides a data mapping or data flow exercise to locate where identifiable health information is created, received, stored, and transmitted across systems, vendors, and communication channels. Because PHI can exist in any form or medium, this discovery commonly extends beyond the primary electronic health record to email, ticketing systems, cloud storage, backups, and third-party services. The vCISO generally directs and structures this effort and interprets the results for risk decisions, while the client's staff and system owners supply the operational detail. The completeness of the mapping depends heavily on stakeholder cooperation and access.
What is typically in scope versus out of scope when a virtual CISO supports PHI protection?
In many engagements, a virtual CISO's scope includes strategy, risk analysis oversight, policy and governance development, business associate agreement review, safeguard planning, and executive-level guidance on handling PHI. Hands-on operational work, such as configuring encryption, administering security tools, monitoring a SOC, or executing incident response, is generally out of scope unless explicitly contracted. Scope may vary by provider and engagement type, so organizations should confirm boundaries in writing to avoid assuming the vCISO will perform tasks better suited to internal staff or a managed service.
Can engaging a virtual CISO guarantee HIPAA compliance for how our PHI is handled?
No engagement can guarantee compliance. A virtual CISO can support readiness by helping structure a risk analysis, close identified gaps, and align safeguards with HIPAA requirements, but compliance is an ongoing organizational obligation, not a one-time outcome. Legal and regulatory accountability for how PHI is handled typically remains with the covered entity or business associate and its officers, not the vCISO, unless a contract specifies otherwise. Sustained compliance also depends on organizational maturity, workforce behavior, and consistent execution over time.
How should an organization handle PHI shared with vendors or business associates under a virtual CISO's guidance?
When PHI is disclosed to a vendor that creates, receives, maintains, or transmits it on the organization's behalf, that relationship generally requires a business associate agreement. A virtual CISO often reviews the vendor inventory, advises on which relationships require such agreements, and helps assess the safeguards those parties apply. Because PHI remains subject to protection regardless of the medium or the party holding it, the vCISO commonly recommends contractual controls and periodic review. The value of this work depends on the organization providing an accurate list of its vendors and data-sharing arrangements.

Common misconceptions

Health information only becomes PHI when it is stored in a designated record set.
Under 45 CFR 160.103, PHI is any individually identifiable health information held or transmitted by a covered entity or business associate in any form or medium. Membership in a designated record set is not required for information to qualify as PHI; that concept is relevant mainly to patients' right-of-access provisions.
Engaging a virtual CISO makes the organization HIPAA compliant or transfers accountability for protecting PHI.
A virtual CISO typically supports readiness and advises on governance, risk, and safeguards for PHI, but legal and regulatory accountability generally remains with the covered entity or business associate and its officers. A vCISO engagement supports, rather than guarantees, compliance, and accountability shifts only where a contract explicitly specifies it.
PHI only exists in electronic systems, so protecting it is purely a technical task.
PHI can exist in electronic, paper, or oral form. Protecting it is a governance and business risk function as much as a technical one, and a vCISO typically directs strategy and program development rather than performing hands-on operational safeguards unless those are explicitly contracted.

Best practices

Identify and inventory where PHI, including electronic, paper, and oral forms, is created, received, maintained, or transmitted across the organization and its business associates, rather than assuming it resides only in a single system.
Do not rely on designated record set membership to determine whether information is PHI; treat all individually identifiable health information held or transmitted by the covered entity or business associate as PHI under 45 CFR 160.103.
Clearly define in the engagement scope which PHI-related activities a virtual CISO will advise on versus which hands-on operational safeguards remain the client's responsibility.
Keep legal and regulatory accountability for PHI documented as residing with the covered entity or business associate and its officers unless a contract explicitly assigns otherwise.
Distinguish HIPAA Security Rule obligations, which focus on electronic PHI, from broader Privacy Rule obligations that apply to PHI in any form, when scoping safeguards and readiness support.
Ensure the vCISO has access to relevant stakeholders and documentation, since the value of guidance on PHI protection depends on organizational maturity, client cooperation, and defined scope.