Protected Health Information

The HIPAA Privacy Rule protects all “individually identifiable health information” held or transmitted by a covered entity or its business associates, in any form or media, whether electronic, paper, or oral. The HIPAA Privacy and Security Rules call this information “protected health information” (PHI) or “electronic Protected Health Information” (ePHI), if in electronic format. “Individually identifiable health information” is information, including demographic data, that relates to (a) the individual’s past, present, or future physical or mental health or condition; (b) the provision of healthcare to the individual; or (c) the past, present, or future payment for the provision of healthcare to the individual; and that identifies the individual or for which there is a reasonable basis to believe it can be used to identify the individual. Individually identifiable health information includes many common identifiers (e.g., name, address, birth date, Social Security number).

As defined by the 45 CFR § 160.103 Definitions (2013 HIPAA Omnibus Rule).