What Is PHI? A Practical Test for Every Record You Hold
Your front desk exports a list of 312 patients who missed appointments last quarter and emails it to a marketing consultant so she can build a reactivation campaign. No diagnoses. No chart notes. Just names, phone numbers, and appointment dates. Whether that email was a reportable disclosure comes down to what is PHI — and the answer is yes, that spreadsheet is protected health information. This article gives you the operational test, the six edge cases your staff get wrong, the inventory work that follows, and the documentation an OCR investigator will ask to see.
What Is PHI? The Two-Part Test That Settles Every Argument
PHI is individually identifiable health information — information relating to a person's past, present, or future physical or mental health, the provision of health care to that person, or payment for that care — that identifies the person or could reasonably be used to identify them, and that is created, received, maintained, or transmitted by a covered entity or business associate. It counts in every form: paper, electronic, spoken, imaged, or faxed.
Run both halves of the test every time. Most staff arguments happen because someone stopped after the first half.
Part one: is it health information?
"Provision of health care" is the phrase that trips people up. It is far broader than diagnosis and treatment. The bare fact that a person is your patient is health information. So is the date they came in, the provider they saw, the fact that a claim was submitted, and the amount they still owe.
That is why the no-show spreadsheet qualifies. Nobody wrote down a condition, but the file establishes that 312 named people received or sought care at your practice. If you are a specialty practice — fertility, behavioral health, oncology, addiction medicine — the mere patient relationship carries the diagnosis with it.
Part two: is it identifiable, and who is holding it?
The information has to point back to a human being, and it has to be in the hands of a covered entity or one of its business associates. Both conditions matter. The same blood pressure reading is PHI in your EHR and is not PHI in a consumer wellness app the patient downloaded on their own. That app is regulated elsewhere — the FTC enforces the Health Breach Notification Rule against non-HIPAA health apps and connected devices.
Custody is the reason a vendor relationship changes your obligations. When your billing company receives claim files, the data does not stop being PHI — the vendor becomes a business associate and inherits duties directly under HIPAA.
The 18 Identifiers Are Not the Definition of PHI
Practice staff commonly recite "the 18 identifiers" as if that list defines what is PHI. It does not. The list comes from the Privacy Rule's safe harbor method for de-identification at 45 CFR 164.514(b)(2). Strip all 18 from a data set, have no actual knowledge that what remains could re-identify anyone, and the data is no longer PHI. That is the list's only job.
The identifiers you must remove for safe harbor de-identification:
- Names
- Geographic subdivisions smaller than a state, including street address, city, county, and ZIP code (except the first three ZIP digits when that area holds more than 20,000 people)
- All dates directly related to an individual except the year — birth, admission, discharge, death
- Ages over 89, and any date indicating such an age
- Telephone numbers
- Fax numbers
- Email addresses
- Social Security numbers
- Medical record numbers
- Health plan beneficiary numbers
- Account numbers
- Certificate and license numbers
- Vehicle identifiers and license plate numbers
- Device identifiers and serial numbers
- Web URLs
- IP addresses
- Biometric identifiers, including fingerprints and voiceprints
- Full-face photographs and comparable images
The eighteenth catch-all — any other unique identifying number, characteristic, or code — is the one that undoes sloppy work. A four-person practice in a rural county cannot de-identify "58-year-old male, left below-knee amputation" by deleting a name. HHS's de-identification guidance walks through both safe harbor and the expert determination method, which is what you actually need for small populations.
Six Edge Cases Your Staff Decide Wrong
Employee health records
Records you hold as an employer — pre-employment physicals, workers' comp files, FMLA certifications, sick notes in a personnel folder — are excluded from the definition of PHI. They are still confidential under the ADA and state law, and they still belong in a locked cabinet separate from the personnel file. If that same employee is also your patient, their chart is PHI. Two files, two rule sets.
Limited data sets
A limited data set strips direct identifiers but keeps dates and geography down to the ZIP code. It is still PHI. It requires a data use agreement, not a research exemption. Practices that hand a limited data set to an analytics vendor without a DUA and a business associate agreement have made an unauthorized disclosure.
Deceased patients
Health information stays PHI for 50 years following the date of death. Your records-request workflow needs a personal-representative verification step for decedent requests, and your retention schedule should account for the 50-year window rather than treating a death as the end of the obligation.
The waiting room
Calling a patient's first name across the lobby, a sign-in sheet, a whiteboard with room assignments — these produce incidental disclosures, which the Privacy Rule tolerates when you apply reasonable safeguards and minimum necessary. Full name plus reason for visit on a shared sign-in sheet is not a reasonable safeguard. Neither is a monitor at the check-in desk turned toward the queue.
Website analytics and ad pixels
An IP address combined with a visit to your "pediatric endocrinology" page can be individually identifiable health information. OCR's guidance on online tracking technologies pushed practices to inventory every script on their sites; subsequent litigation narrowed parts of that guidance, so treat the legal edges as unsettled. The operational answer has not changed: know what tags are on your patient portal and appointment pages, get a BAA from any tracking vendor that receives identifiable data, or remove the tag.
Substance use disorder records
If any part of your practice qualifies as a Part 2 program, those records carry consent restrictions stricter than HIPAA. HHS finalized rules aligning 42 CFR Part 2 more closely with HIPAA, with a compliance date in February 2026 — close enough that behavioral health practices should have consent forms and notices in redraft now, not next summer.
Where PHI Actually Lives in Your Practice
You cannot protect what you have not located. Sit down with your practice manager and IT contact and build a written inventory. Real inventories from small practices routinely surface 25 to 40 locations:
- EHR and practice management database, plus any local cache on workstations
- Imaging archive, dental sensors, ultrasound and EKG carts that store studies locally
- Clearinghouse portal, payer portals, remittance downloads in the billing folder
- Email — including the inbox where patients send their own records
- Fax, whether a physical machine, a fax server, or an e-fax service
- Scheduling reminder and secure-messaging platforms
- Answering service and voicemail, including after-hours transcripts
- Staff mobile phones used for on-call texting or clinical photos
- Copier and multifunction printer hard drives
- Cloud backups, file-sharing folders, and that one shared drive nobody has audited
- Vendors: RCM, transcription, collections, shredding, IT support with remote access, cloud hosting
- Paper: charts in storage, superbills, encounter forms, the recycling bin
That inventory is the foundation of the Security Rule risk analysis every covered entity must conduct and update — and it is the first document OCR requests after a breach. The HHS Security Rule guidance library is the source of record for the requirement. If assembling and maintaining that documentation is what keeps sliding off your list, tooling that generates your risk analysis report and the full policy set gets you to a defensible baseline in an afternoon instead of a quarter.
Every vendor on that list needs a signed agreement
Walk the vendor rows and confirm you hold a current business associate agreement for each. Missing BAAs are among the most common findings in enforcement, partly because they are trivially easy for an investigator to check — either the paper exists or it does not. If you have gaps, you can produce a signature-ready business associate agreement and close them this week.
PHI, ePHI, and the Designated Record Set: Three Labels, Three Duties
These terms overlap and operators conflate them, which produces wrong answers on records requests.
PHI triggers the Privacy Rule: minimum necessary, permitted uses and disclosures, your Notice of Privacy Practices, accounting of disclosures.
ePHI is the electronic subset and triggers the Security Rule: risk analysis, access controls, audit logs, encryption decisions, workforce sanctions. Paper PHI is outside the Security Rule but squarely inside the Privacy Rule's safeguards requirement.
The designated record set is narrower than PHI. It is the medical and billing records you use to make decisions about individuals. The right of access attaches to the DRS, not to every byte of PHI you hold — which is why a patient is entitled to their chart and claims history but not to your internal peer review file or your audit logs. Psychotherapy notes kept separate from the chart are excluded from access. You have 30 days to respond, with one 30-day extension available if you notify the patient in writing of the reason and the new date.
A 60-Day Plan to Get This Documented
- Days 1–10 — Privacy Officer: Draft the PHI inventory. One row per system or location: what data, what identifiers, who has access, which vendor, BAA status, retention period.
- Days 11–20 — Practice Manager: Reconcile the vendor column against signed BAAs. Escalate every gap to the owner with a deadline.
- Days 21–35 — Privacy Officer plus IT: Complete or refresh the risk analysis against the inventory. Document each identified risk, its likelihood and impact, and the remediation you chose — including risks you accepted and why.
- Days 36–45 — Front Desk Lead: Walk the physical space. Monitor angles, sign-in sheets, fax placement, unattended charts, shred bin security. Photograph fixes.
- Days 46–55 — Privacy Officer: Train the workforce on the two-part test using your own edge cases, not generic slides. Collect signed attestations with dates.
- Days 56–60 — Owner: Sign and date the risk analysis and the remediation plan. An unsigned assessment reads as a draft to an investigator.
What Documented Evidence Looks Like
If OCR opens an investigation — most commonly after a patient complaint or a breach report posted to the HHS breach portal — the request letter tends to ask for the same artifacts:
- The current risk analysis, dated and signed, with the risk management plan
- Policies and procedures covering uses and disclosures, minimum necessary, access, amendment, and breach response, with adoption dates
- Workforce training records with names and dates
- Executed BAAs for every vendor touching PHI
- Access logs and the record of your last user-access review
- Your Notice of Privacy Practices and evidence of distribution
- The breach risk assessment for the specific incident, showing how you evaluated probability of compromise
Retention for HIPAA documentation is six years from creation or last effective date, whichever is later. Keep superseded policy versions. "We updated it" without the prior version is a gap.
Start With the Inventory
Answering what is PHI in the abstract takes one paragraph. Answering it for your practice takes a written inventory, a current risk analysis, and a vendor file that matches reality. Do the inventory first — everything else derives from it. If you want the assessment, policies, and full document set generated against your actual environment rather than rebuilt from scratch, hipaa.app produces the compliance documentation package and keeps it versioned so your six-year retention takes care of itself.