Protected health information (PHI)
Individually identifiable health information — including the data on a claim — that a HIPAA covered entity or business associate creates, receives, maintains, or transmits in any form. It is the information the HIPAA Privacy Rule protects.
Updated
Protected health information (PHI) is individually identifiable health information — information relating to a person's health, their care, or the payment for that care that identifies them or could reasonably be used to identify them — when a HIPAA covered entity or business associate creates, receives, maintains, or transmits it. It is protected in any form: electronic, on paper, or spoken.
In a billing operation, PHI is the everyday content of a claim and its remittance: the patient's identifiers, the diagnosis and procedure codes, the dates and place of service, and the payer's response. Because that information is PHI, how it may be used and disclosed is governed by the HIPAA Privacy Rule.
In practice
PHI is defined at 45 CFR 160.103. The definition carves out a few categories — for example, employment records a covered entity holds in its role as an employer, and certain education records — but the information a revenue cycle handles is squarely PHI. Information that has been de-identified under the Privacy Rule's standard is no longer PHI.
Commonly confused with
- Individually identifiable health information: The same data becomes PHI specifically once a covered entity or business associate holds or transmits it; the broader term names the information regardless of who holds it.
- De-identified data: Information stripped of identifiers under the Privacy Rule's de-identification standard is not PHI and falls outside these use-and-disclosure rules.
