Short answer: Protected Health Information (PHI) is individually identifiable health information created, received, or maintained by a covered entity — meaning it combines health information (diagnosis, treatment, test results, payment details) with something that could identify the specific patient (name, address, birth date, or similar identifiers). Health information alone isn't PHI if it can't be tied to an individual, and identifying information alone isn't PHI if it's not connected to health information. It's the combination that matters.
The two-part test
PHI requires both pieces at once:
- Health-related information. This includes diagnoses, treatment plans, test results, medical history, appointment information, and billing or payment details related to care.
- Something identifying. Names, addresses, dates directly related to an individual (including birth date), phone numbers, email addresses, medical record numbers, and 12 other specific identifier categories HIPAA defines.
If both pieces are present and connected, it's PHI. If either piece is missing, it generally isn't.
Common examples of PHI
- A patient's name paired with their diagnosis
- An appointment schedule showing which patients are seeing which provider on which date
- Billing records showing a patient's name alongside procedures performed
- Lab results tied to a specific patient's identity
- Insurance claims information
- Photographs of a patient that could reasonably identify them, paired with treatment information
What generally does NOT count as PHI
Properly de-identified data. If information has been stripped of all 18 specific identifier categories HIPAA defines (or verified as de-identified by a qualified statistical method), it's no longer considered PHI, even though it originated from patient records.
Health information with no identifying link. General statistics about a condition's prevalence, aggregate data with no individual tied to it, or educational health content aren't PHI on their own.
Employment records held by a covered entity in its role as an employer. If a practice, acting as an employer, maintains health-related records about its own employees for employment purposes (drug testing results for employment, for example) — separate from any treatment relationship — those records are generally treated differently under HIPAA than PHI created in the course of providing care.
Identifying information with no health information attached. A patient's name and address on a general mailing list with no health information involved isn't PHI on its own.
Common misconceptions worth clearing up
"If it's not in the EHR, it's not PHI." Format doesn't matter. A sticky note with a patient's name and diagnosis, a verbal conversation about a patient's condition, and a text message all involve PHI if they meet the two-part test, regardless of whether they're stored electronically.
"Only clinical information counts." Billing and payment information tied to a specific patient's care is PHI too, not just clinical notes and diagnoses.
"If a patient's name isn't attached, it's automatically safe to share." Even without a name, if enough other identifying details are present that a specific individual could reasonably be determined (a rare diagnosis in a small town, for example), that information may still function as PHI in practice.
Why getting this right matters day to day
Staff making real-time decisions about what they can discuss, text, or share need a working understanding of what actually counts as PHI — not just a vague sense that "medical stuff is protected." Getting this wrong in either direction causes real problems: being overly restrictive can interfere with normal patient care coordination, while being too loose creates genuine compliance exposure.