Protected Health Information (PHI)

What is protected health information (PHI)?

PHI stands for protected health information. The HIPAA Privacy Rule provides federal protections for personal health information held by covered entities and gives patients various rights concerning that information.

PHI and electronically protected health information (ePHI) mean any identifiable data about the patient, including:

  • Name
  • Address
  • Date of birth
  • Social security number
  • Device identifiers
  • Email addresses
  • Biometrics
  • Lab or imaging results
  • Medical history
  • Payment information

PHI is a subset of personally identifiable information (PII) that refers explicitly to information processed by HIPAA-covered entities. When health information is combined with a personal identifier, the data becomes PHI.

The requirements for processing PHI help protect patient privacy and allow making care coordination easier. The HIPAA Privacy Rule ensures that PHI is shared and used only with patient permission or for care coordination between covered entities. Identifiable health information is not considered PHI unless that organization is a HIPAA-covered entity.

Learn more about HIPAA-compliant analytics and marketing:


  • University website personalization: First-party data strategies for student recruitment and retention

    University websites receive millions of visits annually from diverse audiences – prospective students, admitted students weighing their options, current undergraduates, graduate students, parents, alumni, and faculty. Yet most institutions serve identical content to all these visitors, missing critical opportunities to engage each audience with relevant information.

  • Digital marketing in the energy sector: Key challenges and fixes

    Summary The European energy and utilities sector is changing quickly. Customers expect smooth digital experiences, personalized communication, and easy access to their data. At the same time, regulators continue to tighten privacy and security standards across the EU. For marketing teams, this creates a familiar dilemma – how to deliver relevant, data-driven experiences while staying…