PHI and ePHI
What counts as protected health information under HIPAA, how ePHI differs, what is excluded, and practical examples for small practices and health tech companies.
PHI and ePHI at a glance
Protected health information (PHI) is individually identifiable health information held or transmitted by a HIPAA covered entity or business associate, in any form — electronic, paper or spoken. It relates to a person's past, present or future health, their care, or payment for care, and identifies them or could reasonably be used to. Electronic PHI (ePHI) is PHI that is created, stored or sent electronically; the Security Rule applies to ePHI.
| Defined in | 45 CFR 160.103 |
|---|---|
| Covers | Health, care or payment information that identifies a person — in any form |
| ePHI | PHI transmitted or maintained in electronic media; protected by the Security Rule |
| Excludes | Employment records held as an employer, FERPA education records, people deceased more than 50 years |
| Not PHI | Properly de-identified data |
The definition
Under 45 CFR 160.103, protected health information is individually identifiable health information that is transmitted or maintained in any form or medium. Individually identifiable health information is information — including demographics — that:
- is created or received by a health care provider, health plan, employer or clearinghouse; and
- relates to a person’s past, present or future physical or mental health, the provision of health care, or payment for health care; and
- identifies the person, or could reasonably be used to identify them.
In practice HIPAA protects it when a covered entity or business associate holds it.
ePHI
Electronic protected health information is PHI transmitted by or maintained in electronic media — EHRs, email, cloud storage, messaging, backups. The Security Rule applies to ePHI; the Privacy Rule applies to PHI in every form, including paper and conversation.
What is not PHI
The definition excludes individually identifiable health information:
- in education records covered by FERPA;
- in employment records a covered entity holds in its role as employer;
- about a person deceased for more than 50 years.
Information that has been properly de-identified under 45 CFR 164.514 is not PHI.
Examples
| Information | PHI when held by a covered entity or BA? |
|---|---|
| Patient name with appointment date | Yes |
| Diagnosis, test result, prescription linked to a person | Yes |
| Insurance member ID or billing record | Yes |
| Email address on a clinic’s patient list | Yes — it reveals the person is a patient |
| Staff sick-leave records held as employer | No — employment record |
| Aggregate statistics with no identifiers | No, if properly de-identified |
What this means for tools
Any vendor that is a business associate — typically email, cloud storage, AI assistants and forms that handle ePHI for you — needs a business associate agreement, and you need appropriate safeguards. Our tool comparisons show which vendors sign one.
Guides
- HIPAA law →How the HIPAA law is structured: the 1996 statute, the HHS regulations in 45 CFR, the HITECH Act and the Omnibus Rule — and who enforces them.
- HIPAA meaning →What HIPAA stands for, what people actually mean when they say "HIPAA", and what it does and does not cover.
- HIPAA violation →What counts as a HIPAA violation, common examples in small practices and health tech companies, how violations differ from breaches, and what happens next.
- What is HIPAA? →A plain-English overview of HIPAA: what it protects, who it applies to, the three main rules, patients' rights and how it is enforced.
- Who must comply with HIPAA? →Who HIPAA applies to — covered entities and business associates — with examples, common edge cases like health apps and private-pay practices, and who is outside HIPAA.
Related requirements
Frequently asked questions
What is PHI in simple terms?
Health information that can identify someone and is held by a doctor, health plan, clearinghouse or a company working for them — for example a diagnosis with a name, appointment dates, or billing records.
What is the difference between PHI and ePHI?
ePHI is PHI in electronic form. All PHI is covered by the Privacy Rule; ePHI is also covered by the Security Rule's safeguards.
Is a name and email address PHI?
On its own, not necessarily. It becomes PHI when a covered entity or business associate holds it together with health, care or payment information — for example, a clinic's patient list.
Is health data in a fitness app PHI?
Usually not, unless the app creates, receives, maintains or transmits it on behalf of a covered entity. Other laws may still apply.