Quick Answer: What Counts as PHI Under HIPAA?
PHI, or protected health information, includes any individually identifiable health information that a covered entity or business associate creates, receives, or stores. Under HIPAA, health data becomes PHI only when identifiers such as a name, date of birth, medical record number, or IP address link it to a specific person. Remove all 18 identifiers in accordance with HIPAA’s Safe Harbor method, and HIPAA no longer treats the resulting data as PHI.
HIPAA compliance starts with knowing what data the rules apply to. Get that wrong and you either overprotect data that does not need it, or leave real PHI exposed.
Understanding what counts as protected health information is the foundation for every other HIPAA decision your team makes. It shapes how you store data, who you share it with, and whether a vendor needs to sign a Business Associate Agreement.
Here is what qualifies as PHI, what does not, and how to keep it safe.
What Is PHI?
The HIPAA Privacy Rule defines protected health information as any individually identifiable health information that a covered entity or business associate holds or transmits.
Two things must be true for information to qualify as PHI:
- It relates to a person’s health, treatment, or payment for care
- It ties to a specific individual through one or more identifiers
Health data alone is not PHI. A study showing 30 percent of adults have hypertension is not PHI. The same statistic tied to a named patient is.
The 18 HIPAA Identifiers
Under HIPAA’s Safe Harbor method, information becomes PHI when it is combined with any of these 18 identifiers, as defined by HHS:
- Names
- Geographic subdivisions smaller than a state
- Dates directly related to an individual (birth, admission, discharge, death, and all ages over 89)
- Telephone numbers
- Fax numbers
- Email addresses
- Social Security numbers
- Medical record numbers
- Health plan beneficiary numbers
- Account numbers
- Certificate or license numbers
- Vehicle identifiers and serial numbers, including license plate numbers
- Device identifiers and serial numbers
- Web URLs
- IP addresses
- Biometric identifiers, including fingerprints and voiceprints
- Full-face photographs and comparable images
- Any other unique identifying number, characteristic, or code
Combine health information with any of these, and the data is PHI.
Read More: The Ultimate HIPAA Compliance Checklist
What Does Not Count as PHI?
Not every piece of health-related information is PHI. Three common exceptions:
De-identified data: If all 18 identifiers are removed, or an expert determines the re-identification risk is very low, the data is no longer PHI and can be shared without HIPAA restrictions.
Employment records held by a covered entity as an employer: A hospital’s HR file on its own nurse is not PHI, even if it contains health information.
Education records under FERPA: When a school maintains health records, FERPA usually covers them instead of HIPAA.
Read More: 7 Best HIPAA Compliant Email Providers
How to Protect PHI When Sharing It
PHI has to move between providers, insurers, patients, and vendors every day. A referral. A lab result. A batch of medical imaging. A billing file to a third-party processor. Each transfer is a moment when PHI could be exposed if the wrong tool is used.
The HIPAA Security Rule sets the baseline for protecting PHI in motion:
- Encrypt PHI in transit and at rest
- Use multi-factor authentication on any system that touches PHI
- Restrict access to authorized users only
- Log every access, download, and share
The proposed HIPAA Security Rule update, currently in rulemaking, would make encryption and MFA mandatory rather than “addressable.” For most healthcare organizations, aligning with these requirements now is easier than scrambling to catch up later.
Common Ways PHI Gets Exposed
Most PHI exposures do not come from sophisticated attacks. They come from staff reaching for the tools they already know for jobs those tools were never built for. In Office for Civil Rights (OCR) investigations and internal breach reviews, four patterns show up over and over:
- Regular email with an attachment (standard email does not encrypt by default)
- Personal Dropbox or Google Drive accounts (no audit trail, no signed BAA)
- USB drives shared between offices (easy to lose or misplace)
- Fax machines in shared workspaces (paper sits in the tray)
A Practical Alternative to Transfer PHI Securely
TitanFile is a secure file sharing platform built for healthcare and other regulated industries. AES-256 encryption in transit and at rest, MFA, granular access, tamper-evident audit logs, and a signed Business Associate Agreement come standard. Recipients open a simple portal with no software to install. Every transfer produces a complete audit record for compliance reviews.
If your team sends PHI regularly, start a 15-day free trial or book a demo to explore more.
FAQs About PHI
Is a patient’s name alone considered PHI?
No. A name by itself is not PHI. It becomes PHI once you combine it with any health information about that person.
Is an email address PHI?
Linking an email address to a person’s health information makes it PHI. On its own, in a marketing list, it is not.
Are patient photographs PHI?
Yes. Full-face photographs and comparable images are one of the 18 HIPAA identifiers. Any photo that could identify a patient and shows or implies health information is PHI.
Conclusion
PHI is the intersection of health information and personal identifiers. Understanding what qualifies, and what does not, helps healthcare providers, business associates, and their vendors avoid unnecessary risk. When in doubt, treat information as PHI until you can confirm otherwise.
This article is general information, not legal advice. Consult a HIPAA privacy expert for guidance on your specific circumstances.