Protected Health Information
Protected Health Information (PHI) is health information that can be used to identify a specific person and that is held or transmitted by a healthcare organization or one of its partners subject to HIPAA. It covers details about someone's health condition, care, or payment for care, in any form, whether spoken, written, or electronic. Because it identifies real individuals, HIPAA sets federal rules for how it must be protected.
Under the HIPAA Privacy Rule (45 CFR 160.103), PHI is individually identifiable health information held or transmitted by a covered entity or its business associate, in any form or medium, including electronic, paper, and oral. It encompasses information relating to an individual's past, present, or future physical or mental health condition, the provision of health care, or payment for care, where that information either identifies the individual or provides a reasonable basis to identify them. Note that PHI is not limited to information maintained within a designated record set; membership in a designated record set is relevant primarily to patients' right-of-access provisions rather than to whether information qualifies as PHI. Health information that has been properly de-identified in accordance with HIPAA standards is not considered PHI.
Why it matters
PHI sits at the center of healthcare compliance because HIPAA imposes federal obligations on how it is stored, accessed, transmitted, and disclosed. Any organization that qualifies as a covered entity or a business associate must safeguard individually identifiable health information in every form it takes, whether electronic, paper, or spoken. A frequent and consequential misunderstanding is the belief that information only becomes PHI when it lives inside a formal medical record or a 'designated record set.' That is incorrect: under 45 CFR 160.103, PHI is any individually identifiable health information held or transmitted by a covered entity or business associate in any form or medium. The designated record set concept is relevant primarily to patients' right-of-access provisions, not to whether information qualifies as PHI in the first place. Treating PHI too narrowly leaves gaps in protection precisely where regulators expect coverage.
Who it's relevant to
Inside PHI
Common questions
Answers to the questions practitioners most commonly ask about PHI.