PHI means Protected Health Information: any health-related data that can identify a patient, such as a diagnosis linked to a name, a lab result tied to a medical record number, or a billing claim connected to an address. PII means Personally Identifiable Information, which is broader and covers data that can identify a person in many settings, not just healthcare.
TLDR: PHI is PII with a medical context and extra legal protection under HIPAA in the United States. For example, “Jane Smith has diabetes” is PHI because it links a person to a health condition, while “Jane Smith, 555-0199” is usually PII. In a 50-person clinic exporting 2,000 patient records, even one visible column with names, dates of birth, or medical record numbers can turn a simple spreadsheet into regulated PHI. That small detail can change how the file must be stored, shared, logged, and secured.
What Does PHI Mean in Medical Terms?
In medical settings, PHI refers to patient information that relates to health, care, payment, or insurance and can identify the person. The phrase comes from HIPAA, the Health Insurance Portability and Accountability Act. HIPAA sets rules for how covered entities and business associates handle this information.
PHI is not limited to dramatic details like surgery notes or genetic test results. It can be boring data, too. A prescription refill, appointment reminder, discharge date, or insurance claim can all be PHI if tied to an identifiable person.
The key test is simple: Can this information identify someone, and does it relate to their health or healthcare? If yes, you are probably looking at PHI.
PHI vs PII: The Core Difference
PII is any information that can identify a person. It appears in banking, education, retail, employment, travel, and government records. A name, passport number, Social Security number, email address, or driver’s license number may count as PII.
PHI is narrower, but often more sensitive. It is health information linked to an identifiable person. The medical context is what changes the risk level.
Here is the plain version:
- PII: “Maria Lopez, 214 Oak Street.”
- PHI: “Maria Lopez, cardiology follow-up scheduled for May 12.”
- PII: “Phone number: 312-555-0188.”
- PHI: “Phone number: 312-555-0188, patient called about chemotherapy side effects.”
Same person. Similar identifiers. Very different regulatory impact.
Common Examples of PHI
PHI can show up in electronic records, paper charts, emails, text messages, billing systems, call recordings, imaging platforms, wearable device reports, and support tickets. Honestly, it feels like the moment someone exports a “quick report,” there are three hidden columns that should not have been there.
Common PHI examples include:
- Patient names linked to appointments, diagnoses, or treatment notes
- Medical record numbers
- Health plan beneficiary numbers
- Lab results with identifiers
- Prescription histories
- Clinical photos that show a face or unique feature
- Billing records for medical services
- Email addresses inside a care coordination message
- IP addresses connected to a patient portal account
- Device IDs from remote patient monitoring tools
Even a date can matter. Admission dates, discharge dates, birth dates, and death dates can help identify someone, especially in small towns or rare disease programs.
The 18 HIPAA Identifiers
HIPAA lists 18 identifiers that can turn health data into PHI when paired with medical information. These include obvious items and a few that surprise people.
- Names
- Geographic details smaller than a state
- All date elements connected to a person, except year in some cases
- Phone numbers
- Fax numbers
- Email addresses
- Social Security numbers
- Medical record numbers
- Health plan numbers
- Account numbers
- Certificate or license numbers
- Vehicle identifiers
- Device identifiers
- Web URLs
- IP addresses
- Biometric identifiers
- Full face photos or comparable images
- Any other unique identifying number, code, or trait
This is why a “de-identified” file can still be risky. Remove names but leave full ZIP codes, exact appointment dates, and rare diagnosis codes, and a person may still be identifiable.
Why the Difference Matters
PHI and PII are treated differently because health data can cause serious harm if exposed. A leaked credit card can be replaced. A leaked HIV diagnosis, mental health record, fertility treatment, or substance use history cannot be pulled back.
For healthcare teams, the PHI vs PII distinction affects daily work:
- Storage: PHI may need encryption, access controls, and audit logs.
- Sharing: PHI should only go to approved parties for allowed purposes.
- Vendor contracts: Many vendors handling PHI need a Business Associate Agreement.
- Training: Staff need rules for email, printing, downloads, and messaging.
- Breach response: PHI incidents can trigger strict notice duties.
Expect to waste time on cleanup if a team sends patient lists through a generic file-sharing link. One misclick can create hours of access review, incident documentation, and awkward phone calls.
A Short Use Case Scenario
A primary care group wants to analyze missed appointments. The operations manager exports 10,000 appointment records from the scheduling system. The goal is simple: find out which appointment types have the highest no-show rate.
The first export includes patient names, phone numbers, birth dates, provider names, appointment reasons, insurance type, and visit dates. That file contains PHI. It must be handled under strict privacy controls.
The analyst then creates a safer version. Names are removed. Phone numbers are removed. Birth dates are changed to age ranges. Visit dates are converted to month only. Appointment reasons are grouped into broad categories, such as “routine care” and “specialist follow-up.”
The team finds that behavioral health follow-ups have a 23% no-show rate, compared with 11% for annual wellness visits. Staff can act on the trend without passing around identifiable patient data. That is the practical value of understanding PHI.
When PII Becomes PHI
PII becomes PHI when it connects to healthcare. A name alone is PII. A name on a hospital wristband is PHI. An email address alone is PII. An email address inside a message about biopsy results is PHI.
Context does the heavy lifting. “Robert Chen” in a marketing list is PII. “Robert Chen, oncology infusion appointment, 9:00 a.m.” is PHI.
This matters for software teams, too. A customer support ticket that says “login error” may contain PII. A ticket that includes “patient cannot access post-surgery discharge instructions” may contain PHI. The support tool, retention settings, role permissions, and vendor agreement then need closer review.
How to Protect PHI in Real Workflows
Good PHI protection is not just a policy binder. It is a set of habits built into daily work.
- Use the minimum necessary data. If age range works, do not share full birth dates.
- Limit access by role. Billing staff, nurses, analysts, and vendors do not need identical access.
- Encrypt files and devices. Laptops get lost. So do USB drives.
- Check recipients before sending. Autocomplete in email is a privacy trap.
- Use approved systems. Personal email and consumer chat apps create needless risk.
- Keep audit logs. You need to know who viewed, changed, or exported records.
- Train on real examples. Staff remember “don’t text a wound photo” better than abstract rules.
De-Identified Data, Limited Data Sets, and Anonymous Data
Healthcare data can be made safer, but terms matter. De-identified data has had identifiers removed under accepted methods. In HIPAA, this can be done through the Safe Harbor method or expert determination.
A limited data set removes many identifiers but may keep some dates, city, state, ZIP code, or other limited details. It usually requires a data use agreement.
Anonymous data should not identify a person and should not be reasonably linkable back to them. That is harder than it sounds. Small groups, rare diseases, and location clues can re-identify people faster than expected.
Quick Rule of Thumb
If the data identifies a person, think PII. If it identifies a person and says something about their health, care, insurance, payment, or medical service, think PHI. Treat PHI with extra care from the start. It is cheaper than fixing a privacy incident later.
The simplest safe habit is this: before sharing any healthcare data, ask, “Could someone figure out who this is, and does this reveal something medical?” If the answer is yes, slow down and protect it properly.