Wednesday, July 15, 2026

What Is PHI? Health Information's Narrower, Stricter Cousin

 

What Is PHI? Health Information's Narrower, Stricter Cousin

The Garlick Group | July 2026

A prior post on this site walked through personally identifiable information and noted, near the end, that protected health information sits inside PII's sensitive tier as its own regulated subset. That deserves more room than a footnote gave it. PHI is not simply “health data.” It is a term of art built from three stacked definitions, and a piece of information can fail to qualify at any one of the three layers and fall outside HIPAA entirely, even when a layperson would call it medical information without hesitation.

The first layer is health information itself: anything, oral, written, or electronic, relating to a person's past, present, or future physical or mental condition, the provision of care, or payment for care. 1 This layer is broad and, standing alone, unprotected. A dataset of vital signs with no names or account numbers attached is health information, and it is not PHI, because nothing in it identifies whose vital signs they are. 2

The second layer adds identification. Health information becomes individually identifiable health information once it includes an identifier, or once there is a reasonable basis to believe the information could be used to identify a specific person even without one. HHS operationalized that standard through eighteen categories of identifier, and the presence of any single one, attached to health information, is generally sufficient to trigger the designation. Name and Social Security number are the obvious entries on the list; geographic subdivisions smaller than a state, dates other than year, device identifiers, vehicle identifiers, and full-face photographs are the less obvious ones.

The third layer is custodial rather than substantive: individually identifiable health information becomes protected health information only when a covered entity or its business associate creates, receives, maintains, or transmits it. 3 This is the layer most often missed, and it explains why the identical fact pattern can sit inside HIPAA in one setting and entirely outside it in another. A blood pressure reading recorded by a hospital nurse is PHI. The same number, logged by a consumer fitness app that has no relationship to a covered entity, is not, regardless of how sensitive the number is or how badly a person might want it kept private. The Federal Trade Commission, not HHS, has jurisdiction over that second case, through the Health Breach Notification Rule and general consumer protection authority. 4

The eighteen-identifier list does double duty. It defines individually identifiable health information, and it also anchors the Safe Harbor method of de-identification under the Privacy Rule: strip all eighteen categories from a designated record set, retain no actual knowledge that the remainder could still identify someone, and the resulting data is no longer PHI at all. A second, more flexible route exists alongside Safe Harbor. Expert Determination allows a qualified statistician to certify that re-identification risk is very small using accepted analytic methods, a route that preserves more analytic utility in the data than blunt removal does but requires documented statistical judgment rather than a checklist.

It is worth naming a limitation in the list itself. The eighteen categories were fixed when the Privacy Rule's de-identification standard was written, and critics have pointed out for years that the list has not kept pace with how re-identification actually happens now, particularly given how easily supposedly de-identified genomic or geolocation data can be re-linked to a person using outside datasets. 5 Treating Safe Harbor as a guarantee of anonymity, rather than a regulatory floor, overstates what the method was built to do.

PHI and ePHI are often used interchangeably, incorrectly. PHI is the substantive category; ePHI is PHI in electronic form specifically, and it is ePHI that triggers the Security Rule's administrative, physical, and technical safeguard requirements, discussed at length in this site's earlier post on the pending Security Rule overhaul. A handwritten progress note and a scanned copy of the same note sitting in a cloud-based EHR both count as PHI, but only the second is also ePHI, and only the second falls under the Security Rule's encryption, access control, and audit logging obligations rather than the Privacy Rule's use-and-disclosure framework alone.

Two categories that people commonly assume are PHI are not. Employment records held by a covered entity in its capacity as an employer, rather than as a treatment provider, fall outside the Privacy Rule; a hospital's HR file on a nurse's own workplace injury is not PHI, even though the same injury, treated by that hospital's emergency department as a patient encounter, would be. 6 Education records covered by FERPA are excluded as well, which is why a university student health center's records about currently enrolled students typically fall under FERPA rather than HIPAA, a distinction that trips up campus compliance programs more often than almost any other PHI question. 7

The practical test, when a new data element shows up in a workflow and someone asks whether it needs HIPAA-grade handling, runs through the same three questions each time. Does it relate to a health condition, treatment, or payment? Is it linked, or reasonably linkable, to a specific person? And did a covered entity or its business associate create, receive, maintain, or transmit it in that capacity? A yes to all three means PHI, with everything that designation carries. A no to any one of them means the data may still deserve careful handling under some other law, but it does not mean HIPAA.


www.garlickgroup.com 

No comments:

Post a Comment