Key points
- PHI connects health information to an individual or a reasonable basis for identification.
- The same fact may fall outside HIPAA when held by an entity that is not acting as a covered entity or business associate.
- Names, dates, contact details, record numbers, and other identifiers can make health information identifiable.
- De-identification has specific HIPAA methods; merely removing a name may be insufficient.
PHI is defined by information and relationship
HIPAA applies to health plans, health care clearinghouses, and certain health care providers, plus business associates performing covered functions or services involving PHI. Information held in a personal consumer app may be sensitive health data without being PHI under HIPAA if the app is not acting for a covered entity or business associate. [1][2]
PHI can appear in obvious clinical records and in operational workflows: appointment details, billing context, care-team tasks, messages, attachments, or notes that connect a person to care or payment.
Identifiability is broader than a patient name
Information can identify someone directly or provide a reasonable basis to do so. Dates, contact details, geographic detail, account and record numbers, images, device identifiers, and combinations of facts may matter. Removing a single obvious field does not necessarily de-identify a record.
Encryption is important, but classification comes first
Teams should identify where PHI enters a workflow, minimize it, define authorized users, keep it out of unintended metadata fields, set retention and export rules, and verify contracts. Encryption reduces exposure risk but does not change whether information is PHI or eliminate HIPAA obligations.
Common questions.
Is all health data PHI?
No. PHI is a HIPAA term tied to individually identifiable health information handled by covered entities and business associates. Other health data can still be sensitive and regulated by other laws.
Is encrypted PHI still PHI?
Yes. Encryption is a safeguard; it does not by itself remove PHI status or the obligations that apply to covered entities and business associates. [3]
Does removing a name de-identify PHI?
Not necessarily. HIPAA recognizes specific de-identification paths, and other identifiers or combinations of facts may still identify a person.
Primary sources
Definitions prefer standards bodies, government guidance, and the first-party SealTask architecture. Links open the complete source.
- 01 HHS: Summary of the HIPAA Privacy Rule Official overview of protected health information and the Privacy Rule.
- 02 HHS: Business Associates Official explanation of business associates and required written assurances.
- 03 HHS: HIPAA and cloud service providers Official guidance on cloud services, ePHI, BAAs, and risk analysis.
- 04 SealTask security architecture Product-specific encryption boundary, server visibility, protocols, and current limitations.