HIPAAmart

HIPAA foundations · 6 min read

Protected Health Information

A plain-English starting point for recognizing PHI, understanding identifiers, and separating HIPAA analysis from broader privacy questions.

Reviewed August 2026

Definition

Protected health information is individually identifiable health information held or transmitted by a covered entity or business associate, in a form or medium covered by HIPAA.

In practice

  • A team documents the data flow, owner, and evidence for this topic before deciding which control or process to improve.

Who this applies to

  • Covered entities
  • Business associates
  • Teams designing data flows, applications, or analytics involving health information

What the rule asks for

  • Classify data based on the information, the individual identifiability, and the organization holding it.
  • Document permitted uses, disclosures, and access expectations.
  • Separate de-identification decisions from assumptions about whether data feels sensitive.

How teams put it into practice

  • Create a data dictionary that maps direct and indirect identifiers.
  • Trace PHI through logs, support tools, backups, analytics, and exports.
  • Minimize collection and remove data from systems that do not need it.

Common mistakes

  • Looking only at database tables while overlooking logs, screenshots, exports, or support tickets.
  • Assuming de-identification is a one-time label rather than a documented method and risk decision.

Questions that come up

Is all health information PHI?

No. HIPAA coverage depends on the information, identifiability, and the type of organization or service involved. Other laws and contracts may still apply.

References