Skip to content

Compliance

PHI

PHI, or protected health information, is individually identifiable health information held or transmitted by a HIPAA covered entity or business associate.

PHI, or protected health information, is individually identifiable health information held or transmitted by a HIPAA covered entity or business associate.

What PHI means

PHI, or protected health information, is individually identifiable health information held or transmitted by a HIPAAHIPAAHIPAA is a US federal law whose Privacy, Security, and Breach Notification Rules govern protected health information for covered entities and business associates. covered entity or business associate.

HHS explains that PHI can relate to a person’s past, present, or future health condition, care, or payment and can exist in electronic, paper, or oral form. Context and the organization handling the information matter. Health-related data outside a covered relationship may be sensitive without being PHI under HIPAA.

How it works

Organizations identify where health information is collected, linked to an individual, stored, transmitted, displayed, or disclosed. Workflows limit collection to what is needed, restrict access, secure transmission and storage, and route authorized uses according to policy and agreements.

Practical use cases

Protecting appointment and billing details in a call record

Restricting access to healthcare transcripts

Avoiding unnecessary health details in a general CRMCRMA CRM is the system used to manage leads, contacts, accounts, opportunities, activity, ownership, and follow-up.

Do not use PHI as a casual synonym for every health-related datum. Correct classification determines which HIPAA controls and relationships apply, while other privacy laws may still govern non-PHI health data.

Frequently asked questions

Why does PHI matter?

Do not use PHI as a casual synonym for every health-related datum. Correct classification determines which HIPAA controls and relationships apply, while other privacy laws may still govern non-PHI health data.

Is de-identified health information PHI?

HHS states that information meeting the Privacy Rule’s de-identification requirements is not PHI. Removing obvious names alone may not be sufficient.

Primary source: HHS’s HIPAA Privacy Rule summary.

Related concepts: hipaa, piiPersonally Identifiable Information (PII)Personally identifiable information, or PII, is information that can distinguish or trace an individual’s identity alone or when combined with linked data., data retentionData retentionData retention defines how long recordings, transcripts, messages, personal data, and conversation metadata are kept before deletion or archival., knowledge baseKnowledge baseA knowledge base is a maintained collection of approved business information that an agent can use to answer questions..

See it in action.

Book a demo. We'll run a live agent against one of your real lead sources.