hipaa.systems
General provisions · 45 CFR 160.103

PHI and ePHI

What counts as protected health information under HIPAA, how ePHI differs, what is excluded, and practical examples for small practices and health tech companies.

Checked 2026-10-06Sources 2

PHI and ePHI at a glance

Protected health information (PHI) is individually identifiable health information held or transmitted by a HIPAA covered entity or business associate, in any form — electronic, paper or spoken. It relates to a person's past, present or future health, their care, or payment for care, and identifies them or could reasonably be used to. Electronic PHI (ePHI) is PHI that is created, stored or sent electronically; the Security Rule applies to ePHI.

Defined in45 CFR 160.103
CoversHealth, care or payment information that identifies a person — in any form
ePHIPHI transmitted or maintained in electronic media; protected by the Security Rule
ExcludesEmployment records held as an employer, FERPA education records, people deceased more than 50 years
Not PHIProperly de-identified data

The definition

Under 45 CFR 160.103, protected health information is individually identifiable health information that is transmitted or maintained in any form or medium. Individually identifiable health information is information — including demographics — that:

  1. is created or received by a health care provider, health plan, employer or clearinghouse; and
  2. relates to a person’s past, present or future physical or mental health, the provision of health care, or payment for health care; and
  3. identifies the person, or could reasonably be used to identify them.

In practice HIPAA protects it when a covered entity or business associate holds it.

ePHI

Electronic protected health information is PHI transmitted by or maintained in electronic media — EHRs, email, cloud storage, messaging, backups. The Security Rule applies to ePHI; the Privacy Rule applies to PHI in every form, including paper and conversation.

What is not PHI

The definition excludes individually identifiable health information:

  • in education records covered by FERPA;
  • in employment records a covered entity holds in its role as employer;
  • about a person deceased for more than 50 years.

Information that has been properly de-identified under 45 CFR 164.514 is not PHI.

Examples

Information PHI when held by a covered entity or BA?
Patient name with appointment date Yes
Diagnosis, test result, prescription linked to a person Yes
Insurance member ID or billing record Yes
Email address on a clinic’s patient list Yes — it reveals the person is a patient
Staff sick-leave records held as employer No — employment record
Aggregate statistics with no identifiers No, if properly de-identified

What this means for tools

Any vendor that is a business associate — typically email, cloud storage, AI assistants and forms that handle ePHI for you — needs a business associate agreement, and you need appropriate safeguards. Our tool comparisons show which vendors sign one.

Guides

Frequently asked questions

What is PHI in simple terms?

Health information that can identify someone and is held by a doctor, health plan, clearinghouse or a company working for them — for example a diagnosis with a name, appointment dates, or billing records.

What is the difference between PHI and ePHI?

ePHI is PHI in electronic form. All PHI is covered by the Privacy Rule; ePHI is also covered by the Security Rule's safeguards.

Is a name and email address PHI?

On its own, not necessarily. It becomes PHI when a covered entity or business associate holds it together with health, care or payment information — for example, a clinic's patient list.

Is health data in a fitness app PHI?

Usually not, unless the app creates, receives, maintains or transmits it on behalf of a covered entity. Other laws may still apply.