What is Protected Health Information?
Protected Health Information (PHI) is any health information that can be linked to a specific individual and is created, received, maintained, or transmitted by a covered entity or business associate. PHI is protected under HIPAA regulations.
What Constitutes PHI
Health information + any of 18 identifiers:
- Names
- Geographic data smaller than state
- Dates (except year)
- Phone numbers
- Fax numbers
- Email addresses
- Social Security numbers
- Medical record numbers
- Health plan beneficiary numbers
- Account numbers
- Certificate/license numbers
- Vehicle identifiers and serial numbers
- Device identifiers and serial numbers
- Web URLs
- IP addresses
- Biometric identifiers
- Full-face photographs
- Any other unique identifying number
PHI vs. ePHI
PHI: Any form (paper, verbal, electronic) ePHI: Electronic PHI specifically
De-identification Methods
Safe Harbor: Remove all 18 identifiers Expert Determination: Statistical/scientific verification
PHI Handling Requirements
- Minimum necessary standard
- Access controls
- Encryption (especially ePHI)
- Audit trails
- Business Associate Agreements
- Breach notification procedures