Skip to main content
Call
Complianceaka PHI, ePHI, Protected Health Information

What is Protected Health Information (PHI)? Definition, Formula, and Benchmark

Reviewed by QuickIntell RCM Editorial Team · Last reviewed

Updated

Definition

Protected Health Information (PHI) is individually identifiable health information — any information that relates to a person's past, present, or future physical or mental health, healthcare provision, or healthcare payment — that is held or transmitted by a HIPAA-covered entity. PHI in electronic form is ePHI. PHI is the central protected data type under HIPAA.

Overview

Protected Health Information, or PHI, is the central protected data type under HIPAA — individually identifiable health information held or transmitted by a covered entity or business associate, in any form or medium. PHI encompasses any information relating to the past, present, or future physical or mental health of an individual, the provision of healthcare to an individual, or the past, present, or future payment for the provision of healthcare to an individual, when that information identifies or could reasonably be used to identify the individual.

The HIPAA Privacy Rule identifies 18 specific data elements that, when combined with health information, make it PHI: name, address (below state level), dates related to an individual (birth date, admission date), phone numbers, fax numbers, email addresses, Social Security numbers, medical record numbers, health plan beneficiary numbers, account numbers, certificate or license numbers, vehicle identifiers, device identifiers, web URLs, IP addresses, biometric identifiers, full-face photos, and any other unique identifying number, characteristic, or code. De-identification requires removing these or achieving statistical de-identification under §164.514.

ePHI — electronic Protected Health Information — is PHI in electronic form. ePHI is subject to the Security Rule in addition to the Privacy Rule, requiring administrative, physical, and technical safeguards including access controls, audit logs, encryption in transit and at rest (implementation specification — addressable), workforce training, and incident response. Most RCM-relevant PHI is electronic, making ePHI compliance the practical focus of most organizations.

PHI use and disclosure are governed by the Privacy Rule. Permitted uses and disclosures include treatment, payment, and healthcare operations (TPO) — the categories that cover most day-to-day RCM activity. Other permitted uses include public-health reporting, legal compliance, research under IRB oversight, and similar specific categories. Uses outside permitted categories require patient authorization — marketing, research beyond TPO, certain payment activities with third parties.

Minimum-necessary is a Privacy Rule principle requiring that PHI used or disclosed be limited to what is reasonably necessary for the specific purpose. This affects access controls (role-based access limited to job function), record requests (sharing only what's needed), and data sharing agreements (limiting data scope). Minimum-necessary analysis is a recurring audit topic and a source of OCR findings when organizations over-share or over-access PHI.

Compliance programs treat Protected Health Information (PHI) as a recurring audit trigger rather than a one-time policy exercise. The practical approach is a quarterly Protected Health Information (PHI) self-audit tied into the broader compliance calendar, with findings tracked against hipaa compliance and patient responsibility so a Protected Health Information (PHI) gap cannot silently persist from one audit cycle to the next. Reviewers on this site pair every Protected Health Information (PHI) reference with the corresponding regulatory citation so the policy owner can trace the requirement back to its authoritative source.

Industry benchmark

45 CFR 164.501 definition of PHI. HIPAA Privacy Rule 18 identifier list at §164.514(b). Safe Harbor de-identification standard and Expert Determination standard.

Worked example

A biller needs to call a patient about a balance. The biller's role-based EHR access shows the patient's name, date of birth, account, balance, and recent services — the minimum necessary for the call. The EHR's audit log records the biller's access event. The biller does not need access to clinical notes or medication history and is not granted them by the role. This is minimum-necessary compliance.

Frequently asked questions — Protected Health Information (PHI)

What are the 18 HIPAA identifiers?

Name, address below state, dates related to individual, phone, fax, email, SSN, MRN, health plan ID, account numbers, cert/license, vehicle ID, device ID, URLs, IP addresses, biometric identifiers, full-face photos, and any other unique identifier. These combined with health info make data PHI.

What is de-identified data?

PHI with identifiers removed (Safe Harbor method) or statistically de-identified by an expert (Expert Determination method) to the point that there is low risk of re-identification. De-identified data is not subject to HIPAA restrictions. Used for research, analytics, and benchmarking where PHI access is not necessary.

Is billing information PHI?

Yes — account numbers, payment records, and claim data tied to an individual's care are PHI. RCM activities (charging, billing, collections) are considered healthcare payment activities and are permitted uses under HIPAA, but the underlying data is still PHI subject to the Privacy and Security Rules.

Can we share PHI with outside billing services?

Yes, if the billing service is a business associate with a signed BAA. The BAA extends HIPAA obligations to the billing service and makes the relationship permitted under the Privacy Rule. Sharing PHI without a BAA in place is a HIPAA violation regardless of the purpose.

Disclaimer

This glossary entry is operational reference for revenue-cycle and medical-billing professionals. It is not legal, clinical, or contractual advice. Industry benchmarks cite named public sources where available; always verify against the current guidance from the authority body before relying on a number in a contract, policy, or compliance filing.