What is PHI?

short answer

PHI is individually identifiable health information created or held by a HIPAA covered entity or its business associate. It includes diagnoses, treatment, payment records, and the 18 identifiers HIPAA lists — names, dates, contact details, device identifiers and more. The crucial limit is who holds it: the same information in a consumer fitness app usually is not PHI, because that app is generally not a covered entity.

PHI is defined by the holder, not only by the content

This is the most misunderstood point in health privacy.

PHI is individually identifiable health information held by a covered entity — a health plan, a health care clearinghouse, or a health care provider transmitting health information electronically — or by a business associate acting on their behalf.

Your blood pressure in a doctor’s chart is PHI. The same reading in a consumer wellness app generally is not, because that app is usually neither a covered entity nor a business associate. It may still be regulated — state privacy laws, the FTC Act, and the FTC’s Health Breach Notification Rule can all apply — but not by HIPAA.

The practical consequence: “HIPAA compliant” describes a relationship, not a security certification. A vendor saying it is HIPAA compliant is telling you it can act as a business associate, not that your data is inherently safer.

The 18 identifiers

HIPAA’s Safe Harbor de-identification method lists 18 identifiers that must be removed before data stops being PHI:

  1. Names
  2. Geographic subdivisions smaller than a state
  3. All dates except year, where they relate to an individual
  4. Telephone numbers
  5. Fax numbers
  6. Email addresses
  7. Social Security numbers
  8. Medical record numbers
  9. Health plan beneficiary numbers
  10. Account numbers
  11. Certificate or license numbers
  12. Vehicle identifiers and serial numbers
  13. Device identifiers and serial numbers
  14. Web URLs
  15. IP addresses
  16. Biometric identifiers, including finger and voice prints
  17. Full-face photographs and comparable images
  18. Any other unique identifying number, characteristic, or code

Note how many are not health data at all. An email address in a treatment context is PHI, which is why “we only stored contact details” is not a defense.

PII and PHI overlap but are not nested

People often assume PHI is simply a subset of PII. It is close, but the framing hides the important difference:

PII PHI
Defined by The data itself The data and who holds it
Governing law State privacy laws, sectoral rules, GDPR HIPAA, plus others
Applies to a marketing list Often Only if the holder is a covered entity
Penalties Vary widely Specific civil and criminal penalties

If you are not a covered entity

If you buy or receive health-adjacent leads — insurance, Medicare, wellness, pharmacy — you may never touch PHI in the HIPAA sense and still carry real obligations. The information is sensitive under state law, the consent that produced it gets scrutinised, and reputational exposure does not care about the statutory boundary.

Treating health-adjacent data to a PHI-like standard, whether or not HIPAA applies, is the defensible position. It is also far easier than arguing about which side of the line you were on after something has already gone wrong.

people also ask this as

keep reading

Last updated August 2026. This is general information, not legal advice — privacy law changes often and turns on specifics. For your own situation, talk to counsel.