Definition
Protected health information is individually identifiable health information held or transmitted by a covered entity or business associate, in a form or medium covered by HIPAA.
In practice
- A team documents the data flow, owner, and evidence for this topic before deciding which control or process to improve.
Who this applies to
- Covered entities
- Business associates
- Teams designing data flows, applications, or analytics involving health information
What the rule asks for
- Classify data based on the information, the individual identifiability, and the organization holding it.
- Document permitted uses, disclosures, and access expectations.
- Separate de-identification decisions from assumptions about whether data feels sensitive.
How teams put it into practice
- Create a data dictionary that maps direct and indirect identifiers.
- Trace PHI through logs, support tools, backups, analytics, and exports.
- Minimize collection and remove data from systems that do not need it.
Common mistakes
- Looking only at database tables while overlooking logs, screenshots, exports, or support tickets.
- Assuming de-identification is a one-time label rather than a documented method and risk decision.
Questions that come up
Is all health information PHI?
No. HIPAA coverage depends on the information, identifiability, and the type of organization or service involved. Other laws and contracts may still apply.
References
- What is PHI? U.S. Department of Health & Human Services