What Is PHI: A Complete Guide to Protected Health Information
Safeguarding patient data is one of the most fundamental obligations in healthcare. But before you can protect it, you have to understand what PHI is.
Here’s the fastest way to check: does it relate to a patient’s health, treatment, or payment for care, and could it be used to identify that patient, even indirectly?
If both are true, it’s PHI or Protected Health Information.
That single test resolves most of the confusion healthcare organizations run into.
This blog will cover:
- The legal definition of PHI, including its three required elements
- PHI vs. Health Information vs. PII
- The 18 HIPAA identifiers and de-identification methods
- Where PHI hides in everyday communications, and common compliance mistakes
- How to protect PHI across email, text, and other channels
What Is PHI
Protected Health Information (PHI) is individually identifiable health information that is created, received, maintained, or transmitted by a covered entity or its business associate, in any form like electronic, paper, or oral.
The definition comes from the Health Insurance Portability and Accountability Act (HIPAA) and its implementing regulations.
For data to be considered PHI, it must meet three required elements:
- Content: The information must relate to an individual’s physical or mental health condition, health care received, or payment for that care.
- Identifiability: It must identify the individual or provide a reasonable basis to do so.
- Custodianship: It must be held or transmitted by a covered entity (a health plan, health care clearinghouse, or health care provider) or a business associate acting on that entity’s behalf.
Examples:
- A physician’s email to a specialist. Any message that names a patient and their symptoms, treatment plan, or test results counts.
- A text confirming a prescription refill. A staff text naming a patient and their medication is PHI the instant it’s sent.
- A voicemail reciting a date of birth. A callback message that verifies identity with a birth date and mentions an appointment type.
- A lab result on a patient portal. Test results related to a patient’s account are PHI if the patient views them once or the message sits unread for weeks.
PHI vs. Health Information vs. PII
These three terms are often used interchangeably, but understanding the distinctions between them is essential in a healthcare setting.
Health Information
Health information is any data related to a person’s physical or mental condition, the care they receive, or the payment for that care. This includes diagnoses, lab results, vital signs, or treatment notes. But health information alone isn’t PHI. A de-identified data set of vital signs, for instance, doesn’t qualify as PHI unless it’s paired with an identifier that ties it back to a specific person. Once that link exists, the same data takes on a different level of regulatory sensitivity.
Personally Identifiable Information (PII)
PII refers to any information that can be used to distinguish or trace an individual’s identity, either on its own or when combined with other data. It’s typically broken into two categories: direct identifiers (full name or Social Security number) which can identify someone without any additional information, and indirect identifiers (date of birth or zip code), which only become identifying when combined with other data points.
PII spans far beyond healthcare and only becomes PHI when it’s connected to health, treatment, or payment information within a covered entity’s records.
Protected Health Information (PHI)
Context is what makes the difference. A person’s name on a hotel reservation is PII. That same name attached to a diagnosis in a patient chart becomes PHI. The distinction matters because PHI carries additional regulatory weight under HIPAA that triggers specific requirements around how it’s stored, transmitted, and protected, obligations that simply don’t apply to PII in other contexts.
Examples that are not PHI
- Data with the identifiers stripped out. Once all 18 identifiers are removed under Safe Harbor, or an expert certifies negligible re-identification risk, the information falls outside HIPAA.
- Life insurers and law firms. Health records reviewed by a life insurer for underwriting or a law firm for litigation don’t count as PHI, since neither is acting as a covered entity.
- Devices without a signed BAA. A fitness tracker’s health data stays outside HIPAA unless its maker has a Business Associate Agreement with a covered entity.
- School health records. A school nurse’s vaccination log is protected under FERPA, not HIPAA, even though the content is medical.
The 18 HIPAA Identifiers That Turn Health Data Into PHI
HIPAA’s Safe Harbor de-identification standard lists 18 specific identifiers. If health information is linked to any one of these, it’s PHI and subject to full HIPAA protection:
1. Names (patient, relatives, employers, household members)
2. Geographic subdivisions smaller than a state (street address, city, county, ZIP code)
3. All elements of dates (except year) directly tied to an individual — birth date, admission date, discharge date, date of death — and ages over 89
4. Phone numbers
5. Fax numbers
6. Email addresses
7. Social Security numbers
8. Medical record numbers
9. Health plan beneficiary numbers
10. Account numbers
11. Certificate or license numbers
12. Vehicle identifiers and serial numbers, including license plates
13. Device identifiers and serial numbers
14. Web URLs
15. IP addresses
16. Biometric identifiers, including fingerprints and voiceprints
17. Full-face photographs and comparable images
18. Any other unique identifying number, characteristic, or code
These 18 identifiers are the criteria that must be stripped out before health data can be shared without HIPAA restrictions. They aren’t a definition of PHI itself. Health information becomes PHI once it relates to a patient’s care and is linked to any of these identifiers.
Removing all 18 is the most common way organizations de-identify data for research or analytics purposes.
Where PHI Lives in a Healthcare Organization
PHI doesn’t live only inside the EHR (electronic health record), it moves through every channel staff use to communicate about patients. EHRs are considered the most tightly controlled environment a healthcare organization has.
The real exposure sits in the everyday communication channels surrounding that system:
- A physician emailing a specialist about a shared patient
- A nurse texting a colleague about a medication change
- A front-desk voicemail confirming an appointment and reciting a date of birth to verify identity
Every one of these is PHI the moment it includes an identifier alongside health information, and every one of them is subject to the same retention, security, and breach-notification obligations as a formal medical record.
A clinic might have airtight EHR access controls and still have zero visibility into what’s being said about patients over personal cell phones, unsecured email, or messaging apps that were never designed with retention in mind.
This is where healthcare organizations tend to underestimate their exposure.
💡 Read more on Intradyns guide on HIPAA-COMPLIANT EMAIL ARCHIVING AND RETENTION
Learn HIPAA compliance, including the six-year minimum retention period HIPAA requires for electronic records and the access and audit controls that must remain in place throughout.
PHI De-Identification: Safe Harbor vs. Expert Determination
HIPAA recognizes two accepted methods for de-identifying PHI so it can be used for research, analytics, or data sharing without triggering the Privacy Rule’s restrictions:
Safe Harbor Method — requires removing all 18 identifiers listed above, along with a good-faith determination that the remaining information couldn’t reasonably be used, alone or in combination, to re-identify the patient.
Expert Determination Method — relies on a qualified statistician or scientist to certify that the risk of re-identification is very small, using accepted statistical principles. These principles allow organizations to retain more granular data when Safe Harbor’s blunt removal rules would eliminate too much analytical value.
Most healthcare organizations default to Safe Harbor because it’s straightforward and doesn’t require hiring an outside expert, but Expert Determination is often the better choice for research programs that need finer-grained data.
Why PHI Compliance Matters: The Real Cost of Getting It Wrong
The stakes behind PHI compliance have increased in recent years.
In 2025, the HHS Office for Civil Rights issued 21 settlements and civil monetary penalties, which is the second-highest annual enforcement total on record. The agency’s investigation backlog keeps growing, too.
As of January 2026, nearly 1,000 large healthcare data breaches remained under active or pending OCR investigation.
And the financial exposure goes well beyond the federal settlement itself.
The IBM Cost of a Data Breach Report found the average healthcare data breach cost $7.42 million in 2025, the highest of any industry for fourteen consecutive years. This includes legal fees, breach notification, credit monitoring, and reputational damage, on top of any regulatory fine.
Penalty Costs
The OCR sets its civil penalties in four tiers, based on how much the organization knew and how it responded.
| Penalty Tier | Level of Culpability | Minimum and Maximum Penalty |
|---|---|---|
| Tier 1 | Unaware Violation | Minimum = $145
Maximum = $73,011 |
| Tier 2 | Lack of Oversight | Minimum = $1,461
Maximum = $73,011 |
| Tier 3 | Neglect (corrected within 30 days) | Minimum = $14,602
Maximum = $73,011 |
| Tier 4 | Neglect (Not Corrected within 30 days) | Minimum = $73,011
Maximum = $2,190,294 |
Enforcement Patterns worth watching
- Size doesn’t provide cover – In one recent enforcement year, more than half of OCR’s settlements were brought against small practices, not large hospital systems. Smaller organizations tend to under-invest in documented risk analysis and staff training.
- Business associates carry real exposure – Vendors that handle PHI on a covered entity’s behalf, including IT contractors, billing services, and archiving providers, accounted for a majority of breached records in 2025.
- Access delays are their own violation – OCR’s “Right of Access” enforcement initiative has produced more than 50 separate settlements since 2019. This initiative targets delays in giving patients their own records. PHI compliance isn’t only about preventing unauthorized disclosure. Failing to produce PHI promptly when a patient requests it is its own enforceable violation.
Taken together, these patterns point to the same conclusion: enforcement isn’t reserved for the biggest breaches or the biggest organizations. It follows wherever PHI moves without documented safeguards, whether that’s a small clinic’s email inbox or a vendor’s billing system.
How to Protect PHI in Everyday Communications
The most effective compliance programs treat PHI protection as a communications infrastructure problem, not just a policy document.
That means every channel where PHI might travel including email, text, patient portal messages, needs the same three things:
Encryption in transit and at rest — Encryption alone isn’t sufficient if the underlying transport protocol has known vulnerabilities. Organizations should verify that their email and messaging systems run on current TLS standards, rather than legacy configurations carried over from earlier system builds that no longer meet security requirements.
Role-based access — ensures only authorized staff can retrieve records, but needs to account for staff turnover and role changes as well. Permissions left active for a former employee or a nurse who has transferred departments are among the most common gaps auditors find during HIPAA risk assessments.
A Retention and Audit trail — be able to reconstruct exactly who accessed what and when, but that data is only useful if it’s reviewed on a set schedule. A log nobody checks does nothing to prevent exposure, it only surfaces after a breach forces someone to go looking.
How Intradyn Helps Healthcare Organizations Safeguard PHI
Intradyn’s archiving solutions for healthcare capture and secure email, text messages, and other digital communications that may contain PHI, storing everything in AES-256 encrypted, tamper-evident archives that satisfy HIPAA’s retention and audit requirements.
Built-in role-based permissions ensure only authorized personnel can retrieve archived PHI, while fast, granular search means your compliance or HIPAA privacy officer can respond to an audit or a patient records request in minutes rather than days.
For organizations whose staff communicate about patients over SMS or text, which is a growing reality in modern care coordination, Intradyn’s text message archiving extends the same evidentiary-grade protection to mobile conversations, so PHI shared outside the EHR doesn’t become a compliance gap.
Key Takeaways
- PHI is individually identifiable health information created, received, maintained, or transmitted by a covered entity or business associate, in any form.
- Health information only becomes PHI when it’s linked to an identifier, PII only becomes PHI when it’s tied to health, treatment, or payment data.
- HIPAA’s Safe Harbor method lists 18 identifiers that, when linked to health data, classify it as PHI.
- Most PHI exposure happens outside the EHR (electronic health record), in everyday channels like email, text messages, voicemail, and fax.
- Organizations can de-identify PHI through Safe Harbor’s removal method or Expert Determination’s statistical certification.
- HIPAA enforcement is rising, with business associates and small practices facing significant, growing exposure.
- Common compliance failures include treating email and text as inherently secure and overlooking legacy risk points like fax and voicemail.
- Protecting PHI requires encryption, role-based access, and a reviewed retention and audit trail across every communication channel.
FAQ
What is PHI in simple terms?
PHI is any information about a patient’s health, treatment, or payment for care that could be used to identify that patient, whether it’s stored electronically, on paper, or communicated verbally.
Is an email containing a patient’s name and appointment time considered PHI?
Yes, if it also references health information like an appointment for a specific type of care, a treatment reminder, the combination of an identifier and health-related content makes it PHI.
Does de-identified health data still count as PHI?
No. Once all 18 identifiers are properly removed under the Safe Harbor method, or an expert certifies negligible re-identification risk under Expert Determination, the data is no longer considered PHI and falls outside HIPAA’s Privacy Rule restrictions.
Are text messages about patients subject to the same HIPAA rules as email?
Yes. HIPAA’s requirements apply regardless of the communication channel. A text message containing PHI carries the same retention, security, and access-control obligations as an email or a paper chart entry.
Who is responsible for PHI once it’s shared with an outside vendor?
Both parties share responsibility. Under HIPAA, any vendor that creates, receives, maintains, or transmits PHI on a covered entity’s behalf is a business associate and is independently liable for safeguarding that data. But the covered entity remains responsible for confirming a signed Business Associate Agreement is in place before any PHI is shared.
Not Sure Where PHI Is Hiding in Your Organization?
Don’t wait for an OCR audit or a breach investigation to find out PHI has been moving through unsecured email, text, or voicemail all along. Our Intradyn team can help you map your communication channels and close the gaps before they become a compliance finding.
