What Is PHI?
Health Information's Narrower, Stricter Cousin
The Garlick Group | July 2026
A prior post on
this site walked through personally identifiable information and noted, near
the end, that protected health information sits inside PII's sensitive tier as
its own regulated subset. That deserves more room than a footnote gave it. PHI
is not simply “health data.” It is a term of art built from three stacked
definitions, and a piece of information can fail to qualify at any one of the
three layers and fall outside HIPAA entirely, even when a layperson would call
it medical information without hesitation.
The first layer
is health information itself: anything, oral, written, or electronic, relating
to a person's past, present, or future physical or mental condition, the
provision of care, or payment for care. 1 This layer is broad and,
standing alone, unprotected. A dataset of vital signs with no names or account
numbers attached is health information, and it is not PHI, because nothing in
it identifies whose vital signs they are. 2
The second
layer adds identification. Health information becomes individually identifiable
health information once it includes an identifier, or once there is a
reasonable basis to believe the information could be used to identify a
specific person even without one. HHS operationalized that standard through
eighteen categories of identifier, and the presence of any single one, attached
to health information, is generally sufficient to trigger the designation. Name
and Social Security number are the obvious entries on the list; geographic
subdivisions smaller than a state, dates other than year, device identifiers,
vehicle identifiers, and full-face photographs are the less obvious ones.
The third layer
is custodial rather than substantive: individually identifiable health
information becomes protected health information only when a covered entity or
its business associate creates, receives, maintains, or transmits it. 3
This is the layer most often missed, and it explains why the identical fact
pattern can sit inside HIPAA in one setting and entirely outside it in another.
A blood pressure reading recorded by a hospital nurse is PHI. The same number,
logged by a consumer fitness app that has no relationship to a covered entity,
is not, regardless of how sensitive the number is or how badly a person might
want it kept private. The Federal Trade Commission, not HHS, has jurisdiction
over that second case, through the Health Breach Notification Rule and general
consumer protection authority. 4
The
eighteen-identifier list does double duty. It defines individually identifiable
health information, and it also anchors the Safe Harbor method of
de-identification under the Privacy Rule: strip all eighteen categories from a
designated record set, retain no actual knowledge that the remainder could
still identify someone, and the resulting data is no longer PHI at all. A
second, more flexible route exists alongside Safe Harbor. Expert Determination
allows a qualified statistician to certify that re-identification risk is very
small using accepted analytic methods, a route that preserves more analytic
utility in the data than blunt removal does but requires documented statistical
judgment rather than a checklist.
It is worth
naming a limitation in the list itself. The eighteen categories were fixed when
the Privacy Rule's de-identification standard was written, and critics have
pointed out for years that the list has not kept pace with how
re-identification actually happens now, particularly given how easily
supposedly de-identified genomic or geolocation data can be re-linked to a
person using outside datasets. 5 Treating Safe Harbor as a guarantee
of anonymity, rather than a regulatory floor, overstates what the method was
built to do.
PHI and ePHI
are often used interchangeably, incorrectly. PHI is the substantive category;
ePHI is PHI in electronic form specifically, and it is ePHI that triggers the
Security Rule's administrative, physical, and technical safeguard requirements,
discussed at length in this site's earlier post on the pending Security Rule
overhaul. A handwritten progress note and a scanned copy of the same note sitting
in a cloud-based EHR both count as PHI, but only the second is also ePHI, and
only the second falls under the Security Rule's encryption, access control, and
audit logging obligations rather than the Privacy Rule's use-and-disclosure
framework alone.
Two categories
that people commonly assume are PHI are not. Employment records held by a
covered entity in its capacity as an employer, rather than as a treatment
provider, fall outside the Privacy Rule; a hospital's HR file on a nurse's own
workplace injury is not PHI, even though the same injury, treated by that
hospital's emergency department as a patient encounter, would be. 6
Education records covered by FERPA are excluded as well, which is why a
university student health center's records about currently enrolled students
typically fall under FERPA rather than HIPAA, a distinction that trips up
campus compliance programs more often than almost any other PHI question. 7
The practical
test, when a new data element shows up in a workflow and someone asks whether
it needs HIPAA-grade handling, runs through the same three questions each time.
Does it relate to a health condition, treatment, or payment? Is it linked, or
reasonably linkable, to a specific person? And did a covered entity or its
business associate create, receive, maintain, or transmit it in that capacity?
A yes to all three means PHI, with everything that designation carries. A no to
any one of them means the data may still deserve careful handling under some
other law, but it does not mean HIPAA.
www.garlickgroup.com
No comments:
Post a Comment