Protected Health Information (PHI)


Protected Health Information (PHI) refers to individually identifiable medical and insurance records plus associated hospital and laboratory test results governed under HIPAA.

  • includes information about past, present, or future health, as well as related payments and data used in the operation of a healthcare business
  • may be associated with a specific person or used as an anonymized or de-identified data set for analysis and research
    • de-identified data set contains codes that allow the subject information to be reconstructed by the data provider
  • highly sensitive
  • reputational damage caused by a healthcare data breach is huge
  • governed under HIPAA

Electronic PHI (ePHI) is any PHI stored or transmitted electronically.