TL; DR
PHI stands for Protected Health Information – in HIPAA, it refers to any health, treatment, or payment data that can be used to identify an individual, whether in written, oral, or electronic form. PHI includes 18 identifiers such as names, addresses, phone numbers, Social Security numbers, email addresses, and full-face photos.
Protected Health Information (PHI) is any personal or medical information that can be used to identify a patient or their medical history. HIPAA’s Privacy Rules sets the standards on how PHI can be used and transmitted by while protecting patients’ privacy.
Health Insurance Portability and Accountability Act (HIPAA) also classifies those attributes as PHI that contain mental conditions, pharmaceutical transactions, and any information from a patient’s past, present, and possible future data. Any attributes of personal health records either in paper or electronic form, are considered PHI.
While these are a few attributes tagged as PHI, there are many others too. In this article, we talk in detail about what is considered HIPAA-protected health information, the PHI data that doesn’t make it to the list, and the tips for managing it.
What does PHI Stand For
Protected Health Information (PHI) refers to any data, such as treatment details, insurance information, billing data, or health records associated with an individual. It also includes identifiers such as IP addresses, email addresses, phone numbers, Social Security numbers, license numbers, and biometric data that can directly identify the individual.
HIPAA-protected health information is also referred to as “Individually identifiable health information” and includes information relating to:
- The individual’s physical or mental health condition at any time (past, present, or future)
- The medical care provided to the individual
- The payments made for the individual’s health care (past, present, or future)
El Privacy Rule of HIPAA provides guidelines on how PHI is to be used, stored, or transmitted by the covered entities while protecting the privacy rights of individuals.
What is considered PHI as per HIPAA rules?
El Ley HIPAA has identified 18 attributes as PHI. While most of these attributes hold the potential to identify a patient individually, few of them have to be used in unison for identifying individuals.

Here are the 18 attributes:
- Nombre
- Número de Teléfono
- Dates (admission date, discharge date, appointment date etc.)
- Fax details
- Identificación de correo
- SSN (Número de Seguro Social)
- MRN (Medical Record Number)
- HPBN (Health Plan Beneficiary Number)
- Certificados médicos
- Licence details
- VIN (número de identificación del vehículo)
- Identifiers in Medical devices (Pacemaker)
- URL del sitio web
- Dirección IP
- Biometrics (Fingerprint)
- Full-face photographs or images with differentiators (facial scars, moles etc.)
- Any other unique identifiers
- Address (if it has information on the city, street, and house number)
What types of information qualify as protected health information (PHI)?
Under HIPAA, FI includes any information that relates to an individual’s health or healthcare y can identify the individual, and is handled by HIPAA-covered entities or business associates.
Broadly, PHI falls into the following types:
1. Información de salud
Information about a person’s physical or mental health condition, including diagnoses, test results, treatment records, prescriptions, and medical histories. Holding this kind of structured clinical data calls for a Base de datos compatible con HIPAA setup specifically, since record-level access controls, audit logging, and field-level encryption matter more once diagnoses and prescription details sit inside queryable rows rather than scattered across documents.
2. Healthcare provision information
Details of medical services provided to an individual, including doctor visits, hospital stays, procedures, lab reports, and clinical notes.
3. Payment and billing information
Data related to payment for healthcare services, including insurance details, claims, billing records, account numbers, and payment histories.
4. Personal identifiers linked to health data
Identifiers such as name, address, dates of birth, phone numbers, email addresses, Social Security numbers, medical record numbers, IP addresses, biometric data, or photographs—when associated with health information.
En breve: any health, treatment, or payment information that can identify an individual, directly or indirectly, qualifies as PHI.
What is not considered PHI?
Any information shared with Covered Entities or Business Associates that does not contain personal Health Information is not considered PHI. The specific definitions of covered entities and business associates determine which organizations carry HIPAA obligations in the first place, which is what makes this distinction so consequential when classifying which data flows fall inside or outside the law’s scope.
For example, a urine sample sent to a hospital without patient details is not considered as HIPAA-protected health information.
Only when Personal Identifiable Information (PII) is shared with covered entities or business associates, qualifies as PHI.
Ejemplos de información de salud protegida (PHI)
Any information that can be used to identify a patient is an example of PHI. Any of the 18 attributes mentioned above are perfect examples. How do those attributes look in real life? Each of these identifying attributes also needs to be addressed in a documented Plan de recuperación ante desastres de HIPAA, which covers how PHI containing any of the 18 identifiers will be restored after a system failure or breach without introducing new exposure during the recovery process.
Aquí algunos ejemplos:
- Address: Any address that has more than anything that the state of a patient is PHI
- Registros médicos: : Any medical record with diagnosis codes on terminal and non-terminal diseases.
- Cliff notes and extra information the staff of medical services providers put in patient records
- Cuentas del hospital
- Información de seguro médico
How is PHI handled or managed?
The process of storing PHI in hospital records starts early for individuals. For instance, any baby born in a hospital is registered, and their personal information is added to the central medical repositories. Attributes like name, gender, age, height, weight, blood group, etc., are added.
As the patient grows and visits hospitals for any medical assistance, the details of the visits are cataloged to help the next healthcare personnel get the context of the patient’s medical records. Details of allergies (if any) and more sensitive information like this could help the medical staff make informed decisions in critical scenarios.
Medical researchers and clinical scientists use PHI (without accessing identifiers) to analyze patient data and make health trends. These trends are also used to create programs designed to incentivize healthcare providers to provide better healthcare.
Covered entities are regulated by all HIPAA rules; Business Associates are regulated in the context of their services to covered entities
Rajiv Ranjan, ISO Lead Auditor, Sprinto
Los buenos consejos suman. Obtén más de las mentes más brillantes en GRC. Suscríbete a nuestra boletín
What is the difference between PHI and ePHI?
The significant difference between PHI and ePHI (electronic PHI) is the format in which the PHI is stored, processed, or transmitted. Any identifiable information shared or used by Entidades cubiertas por la HIPAA in physical form is called PHI.
Pro-tip:
HIPAA-covered entities should implement controls and policies to restrict access to physical patient data records.
ePHI has the same attributes as PHI. However, unlike PHI, ePHI is stored in electronic form, and covered entities and socios comerciales should implement encryption protocols and train their staff on the mejores prácticas de ciberseguridad.
How can Sprinto help organizations secure their PHI and ePHI?
pique is purpose-built to help organizations become HIPAA compliant regardless of the type of PHI they process. Sprinto enables organizations to set up the processes and policies required to enable security.
Organizations also leverage Sprinto’s built-in training modules to boost their internal teams with the latest cybersecurity best practices for securing data from bad actor instances.
Únete a los más de 450 profesionales satisfechos que han logrado el cumplimiento normativo con Sprinto.
Preguntas frecuentes
Autor
Vimal Mohan
Vimal es un líder de contenido en Sprinto que simplifica magistralmente el mundo del cumplimiento normativo para el público en general. Cuando no está descifrando complejos requisitos y jerga de cumplimiento, se le puede encontrar en el dojo local de MMA, explorando senderos en bicicleta o haciendo senderismo. Combina sabiduría regulatoria con un espíritu aventurero, desenvolviéndose con soltura en ambos mundos.Explora más
Investigaciones y análisis seleccionados para ayudarte a ganarte un lugar en la mesa.


























