Definition

Protected Health Information (PHI)

Protected health information (PHI) is individually identifiable health information, in any form, that a HIPAA covered entity or business associate creates, receives, maintains or transmits about a person's health, care or payment for care.

2 min readReviewed September 14, 2026

Also known as: Individually identifiable health information, ePHI, Electronic protected health information

Key facts

Defined in
45 CFR 160.103
Forms covered
Electronic, paper and oral information
Electronic subset
ePHI, which is also subject to the HIPAA Security Rule
Excluded
FERPA education records, employer employment records, people dead over 50 years

What is protected health information?

Information is PHI when it relates to a person's past, present or future physical or mental health, the provision of health care, or payment for health care, and it identifies the person or could reasonably be used to do so. It must also be held by a covered entity or business associate under HIPAA.

A diagnosis on a claim, a lab result tied to a medical record number and a bill with a patient's address are all PHI. The same diagnosis entered into an app a consumer downloaded on their own is usually not PHI, because the app developer is not acting for a covered entity.

Many uses and disclosures of PHI are subject to the minimum necessary standard, which limits the information shared to what the purpose requires.

How PHI can be used and shared

The HIPAA Privacy Rule sets several paths for PHI:

  • Treatment, payment and health care operations: permitted without patient authorization.
  • Specific public interest purposes: such as public health reporting, health oversight and legal requirements, under set conditions.
  • Authorization: most other uses, including many marketing uses, need the individual's written authorization.
  • Limited data set: PHI stripped of direct identifiers can be shared for research, public health or operations under a data use agreement.
  • De-identification: data that meets the HIPAA de-identification standard is no longer PHI.

Why PHI matters

Whether data counts as PHI decides which rules apply to it:

  • Analytics and AI teams: a data set containing PHI needs a HIPAA permission, a business associate agreement or de-identification before use.
  • Commercial teams: provider-level data about clinicians, such as NPI registry records, is not patient PHI.
  • Public Medicare data: CMS suppresses small counts in its public provider-level files, typically values from 1 to 10, to reduce the risk of identifying beneficiaries.
  • Security and breach planning: exposure of unsecured PHI can trigger HIPAA breach notification duties.

Sources

All glossary terms