US Medical BillingRevenue cycle solutions

Protected health information (PHI)

Individually identifiable health information — including the data on a claim — that a HIPAA covered entity or business associate creates, receives, maintains, or transmits in any form. It is the information the HIPAA Privacy Rule protects.

Updated

Protected health information (PHI) is individually identifiable health information — information relating to a person's health, their care, or the payment for that care that identifies them or could reasonably be used to identify them — when a HIPAA covered entity or business associate creates, receives, maintains, or transmits it. It is protected in any form: electronic, on paper, or spoken.

In a billing operation, PHI is the everyday content of a claim and its remittance: the patient's identifiers, the diagnosis and procedure codes, the dates and place of service, and the payer's response. Because that information is PHI, how it may be used and disclosed is governed by the HIPAA Privacy Rule.

In practice

PHI is defined at 45 CFR 160.103. The definition carves out a few categories — for example, employment records a covered entity holds in its role as an employer, and certain education records — but the information a revenue cycle handles is squarely PHI. Information that has been de-identified under the Privacy Rule's standard is no longer PHI.

Commonly confused with

Sources

Keep reading

Referenced in the Knowledge Base

Published articles that link to this page.

Ready to improve your revenue cycle?

Explore our services and knowledge base to see how we can help.