PHI (protected health information)
PHI (protected health information) is individually identifiable health information held or transmitted by a HIPAA-covered entity or its business associates — the data class HIPAA exists to protect.
- Individually identifiable health information under HIPAA
- 18 identifiers make health data identifiable, including IP and email
- ePHI is the electronic form the Security Rule protects
- Properly de-identified data falls outside HIPAA
What counts as PHI
Health information becomes PHI when it can identify a person and is held in connection with care or payment. The Privacy Rule lists 18 identifiers — name, address, dates, phone, email, IP address, photos, and more — whose presence makes data identifiable. A diagnosis attached to an email address is PHI; so is an appointment date attached to a name.
Electronic PHI (ePHI) is the same data in digital form, and it is what the Security Rule’s encryption, access-control, and audit requirements target.
PHI in product and analytics decisions
The everyday failure mode is leakage into tools that never signed a BAA: ad pixels on logged-in pages, session-replay scripts capturing intake answers, support tickets pasted into non-compliant SaaS. The rule of thumb: any system that can see a patient identifier next to a health fact is in scope — architect the analytics stack so marketing tools live strictly on the anonymous side of the wall.
De-identification is the release valve: strip the 18 identifiers (safe harbor) or apply expert statistical determination, and the data exits HIPAA. Hold vendors to that actual standard, not to the phrase “anonymized.”
Compliance handled, so you can build
Lithos runs the clinicians, pharmacies, and 50-state rules behind your care program — one API.
Frequently asked questions
Is an email address PHI?
By itself, no — but an email address held by a care program alongside any health information is an identifier that makes the record PHI.
Are marketing leads PHI?
Data collected before any care relationship generally is not PHI — but the moment the same person becomes a patient, the line must be drawn carefully in your stack.
What is safe-harbor de-identification?
Removing all 18 HIPAA identifiers so the data can no longer identify an individual — one of two recognized methods for taking data out of HIPAA scope.