What Does PHI Stand For Under HIPAA? Definition, Examples, and Compliance Requirements
HIPAA Compliance
/
November 20, 2025

What PHI means under HIPAA: the regulatory definition, all 18 identifiers, real examples, exclusions, patient rights, and the penalties for mishandling it.
Last updated: September 3, 2026
What does PHI stand for? Under HIPAA, the abbreviation means protected health information: health data that identifies a person and is created, received, maintained, or transmitted by the organizations the law covers. The Department of Health and Human Services (HHS) answers the question in one line: "PHI stands for Protected Health Information." The definition sounds simple, but its boundaries decide real obligations: which records need safeguards, who is allowed to see them, and what an organization owes the government and its patients when they leak.
This guide walks through the regulatory definition, the 18 identifiers, everyday examples, what falls outside the definition, the compliance requirements attached to PHI, and the penalties for getting it wrong. Every rule cited here links to the regulation itself, 45 CFR Parts 160 and 164, so you can verify the wording at the source.
What PHI Stands For: Definition and Scope
PHI stands for protected health information, and the phrase is a defined legal term, not a loose description. The PHI term itself comes from the HIPAA Privacy Rule, the regulation implementing the Health Insurance Portability and Accountability Act of 1996. The regulation, 45 CFR 160.103, states: "Protected health information means individually identifiable health information" that is "transmitted by electronic media, maintained in electronic media, or transmitted or maintained in any other form or medium." That last clause matters: the PHI definition is not limited to digital files. A paper chart, a faxed referral, and a conversation at the front desk all qualify.
The weight of the definition sits in the phrase "individually identifiable health information." The same section defines it as information, including demographic data, that meets three conditions:
- It is created or received by a health care provider, health plan, employer, or health care clearinghouse.
- It relates to a person's past, present, or future physical or mental health, the provision of health care to that person, or the past, present, or future payment for that care.
- It identifies the person, or there is a reasonable basis to believe it could be used to identify them.
So the PHI meaning in HIPAA comes down to a combination: health information plus an identifier, in the hands of an organization the law covers. Data about a condition that cannot be traced to a person is not protected health information, and identifying information with no medical context is not either.

What Does PHI Under HIPAA Stand For? The 18 Identifiers
So what does PHI under HIPAA stand for in day-to-day work? It stands for any health or payment record that carries at least one of 18 identifiers listed in 45 CFR 164.514(b)(2). The regulation frames the list as what must be removed for data to stop being identifiable, which makes it the working checklist for what PHI includes:
- Names. The patient's full or partial name, and equally a relative's or employer's name sitting inside the record.
- Geographic data smaller than a state. Street address, city, county, precinct, and zip code. The rule makes one narrow allowance: the first three digits of a zip code may stay when the area they cover holds more than 20,000 people.
- Dates. All elements of dates except the year, when they relate directly to the person: birth date, admission date, discharge date, date of death, plus every age over 89, because so few people reach it that the age itself narrows the search.
- Telephone numbers. Including the numbers stored in scheduling and appointment-reminder systems.
- Fax numbers. Referrals still travel by fax, and a fax log tied to patient traffic counts.
- Email addresses. Personal or work, wherever one sits next to health or billing data.
- Social Security numbers. The highest-stakes entry in practice: OCR's April 2026 ransomware cases list SSNs among the exposed data.
- Medical record numbers. The chart number identifies on its own, even with the name stripped out.
- Health plan beneficiary numbers. Member and policy IDs on insurance cards, claims, and explanations of benefits.
- Account numbers. Billing and financial account references in payment records.
- Certificate or license numbers. A driver's license or any other license number tied to the person.
- Vehicle identifiers and serial numbers. Including license plate numbers, for example in a clinic's parking or patient-transport records.
- Device identifiers and serial numbers. An implant's serial number or a monitoring device issued to a patient.
- Web URLs. A personal or portal URL that points to the individual.
- IP addresses. The address a patient's device used, for example in patient-portal access logs.
- Biometric identifiers. Finger and voice prints, and other biometric markers used to recognize the person.
- Full-face photographs and any comparable images. Clinical photos where the face, or anything equally recognizable, is visible.
- Any other unique identifying number, characteristic, or code. The catch-all that keeps the list from going stale: if it singles the person out, it belongs here.
Two things about the PHI identifiers surprise people:
- The list covers more people than the patient. Identifiers of the person's relatives, employers, and household members count too.
- Several entries are not medical at all. A license plate number or an IP address becomes protected health information under HIPAA the moment it sits in a record that also says something about someone's health or care, which is why a hospital's web server logs and a clinic's appointment-reminder texts need the same discipline as the medical records themselves.
What Does PHI Stand For in Healthcare? Forms and Examples
What does PHI stand for in healthcare operations? Something broader than most teams expect, because the definition covers every form the information takes:
- Electronic: entries in an electronic health record, lab results in a portal, e-prescriptions, claims submitted to a payer, appointment data in a scheduling system, and backups of any of them.
- Paper: printed charts, intake forms, superbills, referral letters, and the day's schedule lying next to the front-desk printer.
- Verbal: a diagnosis discussed by name within earshot of a waiting room, or a voicemail that pairs a patient's name with a test result.
Concrete PHI HIPAA examples from daily operations:
- a nurse's progress note about a named patient;
- an X-ray labeled with a medical record number;
- a prescription tied to a date of birth;
- an explanation of benefits mailed to a member;
- treatment plans and medical history summaries shared between healthcare providers during a referral.
Billing is part of the same picture. What is PHI in medical billing? Claims, invoices, billing records, insurance details, and payment information: the definition in 45 CFR 160.103 covers "the past, present, or future payment for the provision of health care," so billing data is PHI wherever it lives.
PHI vs ePHI
PHI in HIPAA stands for the protected information in any form; ePHI, short for electronic protected health information, is the subset that is created, received, maintained, or transmitted electronically, whether it sits in a database or moves between systems. The distinction matters because the HIPAA Security Rule applies specifically to ePHI, adding administrative, physical, and technical safeguards on top of the privacy protections that cover every form. A paper chart and a database record hold the same information; only the second one needs technical safeguards such as access controls, audit logs, and encryption to satisfy the Security Rule.
Who Handles PHI: Covered Entities and Business Associates
HIPAA does not protect health data everywhere; it binds specific organizations. 45 CFR 160.103 defines two roles:
- Covered entities are health plans, health care clearinghouses, and health care providers that transmit health information electronically for standard transactions such as claims. In plain terms: hospitals, clinics, physician practices, pharmacies, insurers, and the clearinghouses that route claims between them.
- Business associates are organizations that create, receive, maintain, or transmit protected health information (PHI) on a covered entity's behalf: billing companies, IT and cloud vendors, analytics providers, lawyers, accountants, and collection agencies, among others.
Before any PHI changes hands, the parties must sign a business associate agreement (BAA), the contract required by 45 CFR 164.502(e) that obligates the vendor to safeguard the information and report breaches. Two consequences follow:
- letting a vendor touch PHI without a BAA is itself a compliance violation by the covered entity;
- subcontractors of business associates inherit the same obligations down the chain.
Learn more about covered entities
Our guide to covered entities under HIPAA walks through both roles, with examples and the edge cases that trip organizations up.
What Is Not Considered PHI Under HIPAA
Knowing what is not considered PHI under HIPAA prevents two expensive mistakes: over-protecting data that carries no obligations, and assuming data is safe to share when it is not. The regulation itself, 45 CFR 160.103, names four categories that are expressly excluded from the definition:
- Education records covered by the Family Educational Rights and Privacy Act (FERPA), such as immunization records a school holds about a student.
- Certain student treatment records described at 20 U.S.C. 1232g(a)(4)(B)(iv), kept by a university clinic solely for the medical treatment of a student.
- Employment records held by a covered entity in its role as an employer. A hospital's own HR file on a nurse, including sick notes, is not PHI, even though the hospital is a covered entity.
- Records of a person who has been deceased for more than 50 years.
Two further boundaries follow from the definition rather than from an exclusion list:
- De-identified information. 45 CFR 164.514(a) states that health information is no longer individually identifiable once it neither identifies a person nor provides a reasonable basis to identify one. The rule allows two paths:
- Expert Determination: a qualified expert applying generally accepted statistical and scientific principles determines and documents that the re-identification risk is very small;
- Safe Harbor: all 18 identifiers are removed and the organization has no actual knowledge the remainder could identify someone.
- Health data held outside covered entities and business associates. The step counter in a consumer fitness app, a nutrition log, or readings from a wellness wearable are not PHI while they stay with a vendor that is neither a covered entity nor working on a covered entity's behalf. The same reading becomes PHI the moment a clinic imports it into a patient's chart.
The label "not PHI" means HIPAA does not attach, not that the data is unregulated: whether it is considered PHI or not, state privacy laws and consumer-protection rules can still apply.
PHI vs PII: What Is the Difference?
Personally identifiable information (PII) is the broader category: any data that can distinguish or trace a specific person, in any industry. PHI is the healthcare-specific subset that HIPAA regulates. The difference is context and custody, and it decides which law applies:
| PII | PHI | |
|---|---|---|
| What it covers | Any data that identifies a person (name, SSN, address, biometrics) | Identifiable data about health, care, or payment for care |
| Who holds it | Any organization in any industry | HIPAA covered entities and their business associates |
| Governing rules | A patchwork: state privacy laws, FTC Act, sector rules | HIPAA Privacy, Security, and Breach Notification Rules |
| Example | An email address in a retailer's customer list | The same email address in a patient portal account |
The example row is the practical test: the identifier does not change, but the moment it is linked to health data inside a covered organization, it becomes PHI.
PHI Compliance Requirements
PHI compliance requirements come from three HIPAA rules, and each attaches a different set of obligations to the same information:
- The HIPAA Privacy Rule (45 CFR Part 164, Subpart E) governs every form of PHI:
- limits uses and disclosures to what the rule permits;
- requires a signed authorization for everything else;
- imposes the minimum necessary standard: reasonable efforts to limit PHI to the minimum needed for the purpose (164.502(b)).
- The Security Rule (45 CFR Part 164, Subpart C) applies to ePHI and requires three families of safeguards:
- The Breach Notification Rule (45 CFR Part 164, Subpart D) sets who must hear about a breach of unsecured PHI, and when:
Two more layers sit on top of the three rules:
- contractual: business associate agreements for every vendor that touches PHI;
- documentation: the policies, procedures, and records of compliance actions that HIPAA regulations require organizations to retain.
PHI and HIPAA compliance are inseparable: the definition decides what the program covers, the rules decide what it must do.
Learn more about the cost of compliance
Our breakdown of HIPAA compliance costs shows what meeting these HIPAA rules takes in practice, item by item.
Permitted Uses and Disclosures of PHI
HIPAA is not a blanket prohibition on sharing; it is a permission system. 45 CFR 164.502(a)(1) permits a covered entity to use or disclose PHI:
- to the individual the information is about;
- for treatment, payment, or health care operations (TPO), under 164.506: a physician sharing records with a specialist to coordinate patient care, a practice billing an insurer for healthcare services, a hospital running quality reviews;
- incident to an otherwise permitted use, when reasonable safeguards and the minimum necessary standard are in place;
- under a valid written authorization from the individual (164.508), which is the path for marketing, most research, and anything TPO does not cover;
- with the individual's informal agreement for facility directories and family involvement (164.510);
- without authorization in twelve public-interest situations listed in 164.512, including public health activities, abuse reporting, health oversight, law enforcement requests that meet the rule's conditions, and research under specific safeguards.
The practical discipline: identify which permission a disclosure rests on before it happens. If none fits, the answer is an authorization or a refusal; informal patient consent does not substitute for the written one the rule requires.
What Is a Designated Record Set?
A designated record set is the group of records a covered entity uses to make decisions about individuals, and it defines the scope of several patient rights. 45 CFR 164.501 names three components:
- the medical records and billing records a provider maintains;
- a health plan's enrollment, payment, claims adjudication, and case management records;
- any other records used, in whole or in part, to make decisions about individuals.
The concept matters for one practical reason: the rights of access and amendment apply to the designated record set, not to every scrap of data that mentions the patient. In practice the line runs like this:
- Inside the set: the chart, the problem list, lab results, imaging, and billing records.
- Outside it: records not used to make decisions about individuals, such as internal quality-assessment analyses.
- Excepted from the access right itself: psychotherapy notes and information compiled for legal proceedings (45 CFR 164.524(a)(1)).
When a patient requests their records, the designated record set is the boundary of what the organization is obliged to produce.
Patient Rights Over PHI
The Privacy Rule pairs the restrictions with enforceable rights that patients hold over their own information:
- Access. Under 45 CFR 164.524, a person has the right to inspect and obtain a copy of their PHI in the designated record set, and the organization must act on the request no later than 30 days after receiving it, with one 30-day extension allowed on written notice of the reasons and the expected date. PHI access covers electronic copies when records are stored electronically.
- Amendment. Under 164.526, a person may ask to correct their records, and a covered entity that denies the request must document why and record the disagreement.
- Accounting of disclosures. Under 164.528, a person may request a list of certain disclosures made in the previous six years.
- Restrictions and confidential communications. Under 164.522, a person may request limits on uses and disclosures and ask to be contacted at an alternative address or number.
Everything else in the designated record set is the patient's to see.
How Is PHI Stolen?
The threat picture for healthcare data is documented in enforcement records rather than in speculation. "Hacking and ransomware are the most frequent type of large breach reported to OCR," said Paula M. Stannard, Director of the HHS Office for Civil Rights, announcing four ransomware settlements in April 2026 that together affected more than 427,000 individuals. How the theft happens, in the same enforcement record:
- Ransomware. Malicious software that blocks access to data, typically by encrypting it with a key known only to the attacker, until a ransom is paid. The compromised ePHI in the four cases included demographic data, Social Security numbers, financial information, lab results, medications, and diagnoses.
- Phishing. The entry point in one of the four cases: a phishing attack succeeded, the threat actor gained access to a server holding ePHI, and the encryption followed.
- Unexamined weak points. The failure OCR cited across the resolutions is the missing or inadequate risk analysis: the organizations had not adequately mapped their own vulnerabilities. As of that release, OCR had completed 19 ransomware investigations, and the count has kept climbing since.
Patient records make a persistent target for a simple reason: a single file pairs identifiers with financial and medical detail.
How to Protect PHI: Best Practices
The Security Rule names the safeguard families; practice decides whether they hold. "Proactively implementing the HIPAA Security Rule before a breach or an OCR investigation not only is the law but also is a regulated entity's best opportunity to prevent or mitigate the harmful effects of a successful cyberattack," Stannard said in the same April 2026 release.

The measures below map to the requirements in 45 CFR 164.308-164.312 and to the failures OCR keeps citing:
- Run a real risk analysis, and repeat it. Inventory every system that creates, receives, maintains, or transmits ePHI, then assess threats and vulnerabilities against it. The missing risk analysis is the finding OCR cited across its April 2026 ransomware settlements.
- Limit access to the minimum necessary. Role-based access controls, unique user IDs, and periodic access reviews keep each workforce member inside the data their job requires.
- Encrypt ePHI at rest and in transit. Breach notification obligations attach to unsecured PHI; properly encrypted data that is stolen without its key does not trigger them (45 CFR 164.402). Encryption is formally an addressable specification under 164.312; the safe harbor is a large part of why it is the default choice anyway.
- Harden authentication. Multi-factor authentication on email, remote access, and any system holding ePHI cuts off the phished-credential path documented in one of OCR's April 2026 cases.
- Train the workforce and test the training. Security awareness training is an administrative safeguard requirement, and phishing simulations show whether it works.
- Keep audit controls on. Logging and log review are technical safeguards that turn a silent intrusion into a detected one.
- Cover the physical layer. Locked records rooms, workstation placement, screen locks, and media disposal procedures protect the paper and hardware half of the problem.
- Prepare for the bad day. Data backup, a disaster recovery plan, and an incident response procedure are required contingency planning, and they decide how much a ransomware event actually costs.
Learn more about common Security Rule gaps
Our review of five common HIPAA Security Rule deficiencies covers the failures assessors find most often and how to close them.
Penalties for PHI Violations
Mishandling PHI carries civil and criminal exposure, and both scales are set in law rather than negotiated from scratch. On the civil side, 45 CFR 160.404 sets four culpability tiers, with dollar amounts adjusted for inflation annually and published at 45 CFR 102.3. As of the current table:
| Tier | Culpability | Per violation | Annual cap |
|---|---|---|---|
| 1 | Did not know, and could not have known with reasonable diligence | $145 to $73,011 | $2,190,294 |
| 2 | Reasonable cause, not willful neglect | $1,461 to $73,011 | $2,190,294 |
| 3 | Willful neglect, corrected within 30 days | $14,602 to $73,011 | $2,190,294 |
| 4 | Willful neglect, not corrected within 30 days | $73,011 minimum | $2,190,294 |
Criminal penalties under Section 1177 of the Social Security Act apply to knowingly obtaining or disclosing individually identifiable health information in violation of the rules:
- up to $50,000 and one year of imprisonment at the base tier;
- up to $100,000 and five years when the offense involves false pretenses;
- up to $250,000 and ten years when the intent is to sell, transfer, or use the information for commercial advantage, personal gain, or malicious harm.
Enforcement is not theoretical: OCR's 2026 ransomware settlements each carried a monetary payment plus a corrective action plan under OCR monitoring.
Learn more about HIPAA fines
Our guide to HIPAA fines and penalties shows how the amounts play out in real enforcement cases.
Conclusion
PHI stands for protected health information: identifiable health, treatment, or payment information, in any form, held by covered entities and their business associates. Inside that boundary sit the 18 identifiers, the permission system for disclosures, patient rights with deadlines, and safeguard obligations that OCR enforces; outside it, de-identified data and a short list of named exclusions. An organization that knows exactly which of its data is PHI, where it lives, and who touches it has done the hardest part; every rule that follows is published and checkable at the sources linked in this guide.
Get Expert Support for Your HIPAA Compliance
CyberCrest helps healthcare organizations and their business associates protect PHI and meet HIPAA requirements end to end. Our HIPAA compliance services run from a readiness assessment that identifies gaps across administrative, physical, and technical safeguards, through remediation of identified gaps, to assessment support that confirms your policies, access controls, and minimum necessary standards align with the Privacy and Security Rules.
Engagements start with a conversation about your systems, your data flows, and where PHI actually lives in your organization. Book a call and we will scope the work from there.
Sources
- U.S. Government Publishing Office / eCFR. 45 CFR 160.103, Definitions. https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-160/subpart-A/section-160.103
- U.S. Government Publishing Office / eCFR. 45 CFR 164.514, Other requirements relating to uses and disclosures of protected health information. https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-E/section-164.514
- U.S. Government Publishing Office / eCFR. 45 CFR 164.502, Uses and disclosures of protected health information: General rules. https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-E/section-164.502
- U.S. Government Publishing Office / eCFR. 45 CFR 164.524, Access of individuals to protected health information. https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-E/section-164.524
- U.S. Government Publishing Office / eCFR. 45 CFR 160.404, Amount of a civil money penalty. https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-160/subpart-D/section-160.404
- U.S. Government Publishing Office / eCFR. 45 CFR 102.3, Penalty adjustment and table. https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-A/part-102/section-102.3
- U.S. Department of Health and Human Services. What is PHI? https://www.hhs.gov/answers/hipaa/what-is-phi/index.html
- U.S. Department of Health and Human Services. Summary of the HIPAA Security Rule. https://www.hhs.gov/hipaa/for-professionals/security/laws-regulations/index.html
- U.S. Department of Health and Human Services. HHS' Office for Civil Rights Settles Four HIPAA Security Rule Ransomware Investigations. https://www.hhs.gov/press-room/ocr-settles-four-ransomware-investigations.html
- Social Security Administration. Social Security Act Section 1177, Wrongful Disclosure of Individually Identifiable Health Information. https://www.ssa.gov/OP_Home/ssact/title11/1177.htm


FAQ
What type of PHI is protected by HIPAA?
Every type, in every form. HIPAA protects individually identifiable health information whether it is transmitted or maintained electronically, on paper, or spoken aloud, and the protection covers clinical, payment, and demographic data alike. If the record combines something about a person's health, care, or payment for care with any of the 18 identifiers, or anything else that could reasonably identify them, it is protected regardless of the medium it lives in.
Which of the following would be considered PHI?
Training quizzes love this question, and the test behind it is always the same three-part check from the regulation: the information is held by a covered entity or business associate, it relates to health, care, or payment, and it identifies the person or could reasonably do so. A lab result with a name, a billing statement with an account number, and an appointment reminder with a phone number all pass the test. A step count in a consumer fitness app and a de-identified research dataset both fail it.
Is a patient's name alone considered PHI?
In a covered entity's records, usually yes. A name on a patient list reveals that the person is a patient, which is itself information about the provision of health care, and the definition covers information that identifies the person and relates to their care. The same name in a context with no health connection, such as a retailer's mailing list, is not PHI.
Who is allowed to access PHI inside an organization?
Workforce members whose roles require it, and no further: the minimum necessary standard in 45 CFR 164.502(b), implemented through the role-based policies required by 164.514(d), obliges organizations to limit each person's access to what their job needs, which is why role-based permissions and access reviews are compliance requirements rather than IT preferences. Outside the workforce, access follows the permission system for disclosures, and patients themselves hold an enforceable right of access to their own records.
How many years after a person's death is PHI protected?
50 years. The definition in 45 CFR 160.103 excludes individually identifiable health information "regarding a person who has been deceased for more than 50 years," so HIPAA's protections apply for five decades after death and end there.
Who enforces HIPAA, and where are violations reported?
The HHS Office for Civil Rights (OCR) investigates complaints, conducts compliance reviews, and negotiates the settlements and penalties described above. Individuals can file complaints directly with OCR, and workforce members who see a problem internally should know the escalation path; our guide on how to report a HIPAA violation walks through both routes.











