Why protected health information matters
PHI matters because it connects a person’s identity to sensitive details about their health, care, or payment for care. When that information is exposed, misused, or accessed by the wrong person, the impact can extend beyond a single record or system.
For healthcare organizations and their partners, PHI is both a privacy concern and a security concern. Protecting it requires knowing where the data exists, who can access it, how it moves, and what happens when something goes wrong.
Some common risks include:
- Unauthorized access: A user, vendor, or attacker views PHI they shouldn’t be able to access.
- Data leakage: PHI is accidentally shared, stored in the wrong place, or exposed through a misconfigured system. Data leakage can happen without a malicious actor.
- Data breaches: PHI is stolen, disclosed, or accessed during a security incident. A data breach may trigger investigation, notification, and compliance obligations.
- Operational blind spots: Teams cannot protect PHI effectively if they don’t know where it lives across applications, cloud storage, endpoints, and third-party systems.
How PHI works under HIPAA
PHI isn’t just any health-related information. Under HIPAA, health information becomes PHI when it can identify a person and is created, received, maintained, or transmitted by a covered entity or business associate.
Covered entities and associates
Covered entities generally include healthcare providers, health plans, and healthcare clearinghouses. Business associates are organizations or people that handle PHI while performing services for a covered entity. This can include billing vendors, cloud service providers, consultants, analytics providers, and other third parties, depending on the work they perform.
PHI can exist in multiple formats
PHI isn’t limited to digital records. It can appear in:
- Electronic records: Patient portals, databases, emails, cloud files, and billing platforms
- Paper records: Printed forms, lab reports, faxes, and discharge instructions
- Oral communications: Conversations about a patient’s care, payment, or treatment
Electronic protected health information, or ePHI, is the electronic subset of PHI. It includes PHI that is created, stored, received, or transmitted electronically.
PHI vs. PII vs. ePHI
These terms often overlap, but they aren’t identical.
- PHI is identifiable health, treatment, or payment information protected under HIPAA.
- PII is personally identifiable information, such as a name, address, Social Security number, or phone number, and it may or may not be health-related.
- ePHI is PHI in electronic form.
A name by itself is usually not PHI. A name paired with a diagnosis, appointment record, claim, prescription, or treatment note can become PHI when handled in a HIPAA-covered context.
Key components of PHI
PHI usually includes two things: information about health, care, or payment, and information that can identify the person connected to it.
Health, treatment, and payment information
PHI can include information about:
- Health status: Diagnoses, symptoms, lab results, conditions, medications, allergies, or mental health information
- Healthcare services: Appointments, procedures, care plans, referrals, discharge details, or clinical notes
- Payment for care: Insurance claims, billing records, member IDs, payment history, or coverage details
The same type of information can appear in many systems. A diagnosis may live in an electronic health record, a billing platform, a customer support ticket, a report export, or a spreadsheet. That makes data security especially important for organizations that handle healthcare data.
Identifiers that can make data PHI
Health information becomes more sensitive when it’s tied to a person. HIPAA defines 18 identifiers that can make information individually identifiable.
The important point is context, as in an email address in a general marketing list may be PII. That same email address connected to a treatment question, appointment, or insurance claim may be PHI.
Examples of protected health information
Patient portal record
A portal record with a patient’s name, date of birth, lab result, diagnosis, and upcoming appointment is PHI. It identifies the person and connects them to healthcare services and health status.
Security teams need to protect this data through strong authentication, access control, monitoring, and encryption. Data encryption helps reduce exposure if records are intercepted or accessed outside normal workflows.
Insurance claim
A claim that includes a member ID, treatment date, provider name, procedure code, and payment amount is PHI. Even if the record doesn’t include a diagnosis written in plain language, the billing and procedure details can reveal information about care.
Support ticket
A support ticket can become PHI when a patient or employee includes medical details. For example, an email address paired with a medication issue, lab result question, or appointment concern may qualify as PHI.
This is why PHI protection isn’t limited to clinical systems. It can also involve ticketing platforms, email, chat tools, shared drives, and SaaS applications.
Cloud storage file
A spreadsheet stored in the cloud that includes patient names, dates of birth, procedure information, and insurance details is PHI. If that file is shared too broadly or stored in an unmanaged location, it can create exposure risk.
Data security posture management (DSPM) can help teams understand where sensitive data exists, how it’s exposed, and which access paths may need review.
What may not be PHI
Not all health-related data is PHI. Examples can include:
- De-identified health data that no longer identifies a person
- Employment records held by an employer in its role as an employer
- Education records covered by separate privacy rules
- Health or fitness data that isn‘t held by a covered entity or business associate
Teams should involve legal, privacy, or compliance stakeholders when a classification decision affects policy, reporting, or regulatory obligations.
How PHI fits into security operations
Protecting PHI isn’t a single control, but an ongoing security practice that spans data discovery, access, monitoring, response, and governance. Security teams help protect PHI by answering practical questions:
- Where is PHI stored? Data discovery and classification help teams locate PHI across systems, cloud services, endpoints, and applications.
- Who can access it? Identity and access management (IAM) helps enforce least privilege and reduce unnecessary access.
- How does it move? Teams need visibility into email, file transfers, APIs, SaaS apps, backups, and third-party workflows.
- Is activity being monitored? Logs and alerts can show unusual access patterns, large downloads, failed login attempts, or policy violations.
- What happens during an incident? Incident response (IR) helps teams investigate what happened, what data was involved, who was affected, and what actions are needed next.
PHI protection also overlaps with vendor risk, as business associates may store, process, or transmit PHI on behalf of a covered entity. Security teams should understand which third parties handle PHI, what access they have, and how those relationships are governed.