What is PHI?
short answer
PHI is individually identifiable health information created or held by a HIPAA covered entity or its business associate. It includes diagnoses, treatment, payment records, and the 18 identifiers HIPAA lists — names, dates, contact details, device identifiers and more. The crucial limit is who holds it: the same information in a consumer fitness app usually is not PHI, because that app is generally not a covered entity.
PHI is defined by the holder, not only by the content
This is the most misunderstood point in health privacy.
PHI is individually identifiable health information held by a covered entity — a health plan, a health care clearinghouse, or a health care provider transmitting health information electronically — or by a business associate acting on their behalf.
Your blood pressure in a doctor’s chart is PHI. The same reading in a consumer wellness app generally is not, because that app is usually neither a covered entity nor a business associate. It may still be regulated — state privacy laws, the FTC Act, and the FTC’s Health Breach Notification Rule can all apply — but not by HIPAA.
The practical consequence: “HIPAA compliant” describes a relationship, not a security certification. A vendor saying it is HIPAA compliant is telling you it can act as a business associate, not that your data is inherently safer.
The 18 identifiers
HIPAA’s Safe Harbor de-identification method lists 18 identifiers that must be removed before data stops being PHI:
- Names
- Geographic subdivisions smaller than a state
- All dates except year, where they relate to an individual
- Telephone numbers
- Fax numbers
- Email addresses
- Social Security numbers
- Medical record numbers
- Health plan beneficiary numbers
- Account numbers
- Certificate or license numbers
- Vehicle identifiers and serial numbers
- Device identifiers and serial numbers
- Web URLs
- IP addresses
- Biometric identifiers, including finger and voice prints
- Full-face photographs and comparable images
- Any other unique identifying number, characteristic, or code
Note how many are not health data at all. An email address in a treatment context is PHI, which is why “we only stored contact details” is not a defense.
PII and PHI overlap but are not nested
People often assume PHI is simply a subset of PII. It is close, but the framing hides the important difference:
| PII | PHI | |
|---|---|---|
| Defined by | The data itself | The data and who holds it |
| Governing law | State privacy laws, sectoral rules, GDPR | HIPAA, plus others |
| Applies to a marketing list | Often | Only if the holder is a covered entity |
| Penalties | Vary widely | Specific civil and criminal penalties |
If you are not a covered entity
If you buy or receive health-adjacent leads — insurance, Medicare, wellness, pharmacy — you may never touch PHI in the HIPAA sense and still carry real obligations. The information is sensitive under state law, the consent that produced it gets scrutinised, and reputational exposure does not care about the statutory boundary.
Treating health-adjacent data to a PHI-like standard, whether or not HIPAA applies, is the defensible position. It is also far easier than arguing about which side of the line you were on after something has already gone wrong.
people also ask this as
- What is protected health information?
- What is the difference between PII and PHI?
- Is my fitness tracker data PHI?
- What are the 18 HIPAA identifiers?
keep reading
Last updated August 2026. This is general information, not legal advice — privacy law changes often and turns on specifics. For your own situation, talk to counsel.