Screenata

Beyond SOC 2

What does PHI stand for?

August 18, 20262 min read

What does PHI stand for?

PHI stands for Protected Health Information: any health information that identifies an individual, or could reasonably be used to identify them, when it is held or transmitted by a HIPAA covered entity or a business associate. In electronic form it is called ePHI and falls under the HIPAA Security Rule. The definition turns on two things together, health information and an identifier, not on either alone.

The 18 identifiers

Identifier
1Names
2Geographic subdivisions smaller than a state
3All dates related to an individual except year
4Telephone numbers
5Fax numbers
6Email addresses
7Social Security numbers
8Medical record numbers
9Health plan beneficiary numbers
10Account numbers
11Certificate or license numbers
12Vehicle identifiers and serial numbers
13Device identifiers and serial numbers
14Web URLs
15IP addresses
16Biometric identifiers, including finger and voice prints
17Full-face photographs and comparable images
18Any other unique identifying number, characteristic, or code

What makes something PHI

Three conditions, all required:

  1. It is health information: physical or mental health, healthcare provision, or payment for healthcare.
  2. It identifies an individual, through one of the 18 identifiers above.
  3. It is held or transmitted by a covered entity or business associate. The same data in a consumer fitness app that has no such relationship is generally not PHI.

That third condition is the one people miss. HIPAA regulates specific relationships, not health data in the abstract.

PHI, ePHI, and what changes

ePHI is PHI in electronic form. The distinction matters because the Security Rule applies only to ePHI, requiring administrative, physical, and technical safeguards. The Privacy Rule applies to PHI in every form, including paper charts and conversations.

De-identification removes it from scope

Two routes, both defined in the Privacy Rule:

  • Safe Harbor: remove all 18 identifiers and have no actual knowledge that the remainder could identify someone.
  • Expert determination: a qualified statistician certifies the re-identification risk is very small and documents the methodology.

Removing some identifiers is not de-identification. Data with 15 of 18 removed is still PHI.

Why this matters for a SaaS company

If your product touches PHI on behalf of a covered entity, you are a business associate with direct legal obligations, regardless of company size. That means a signed BAA, a documented risk analysis, and implemented safeguards. See what is a business associate agreement and what is HIPAA compliance and when does a SaaS company need it.

Connect and see

See your SOC 2 with your real systems.

Connect GitHub and cloud read-only. Vera shows your control matrix, policy gaps, and prioritized next actions before you commit to anything.