Beyond SOC 2
What does PHI stand for?
What does PHI stand for?
PHI stands for Protected Health Information: any health information that identifies an individual, or could reasonably be used to identify them, when it is held or transmitted by a HIPAA covered entity or a business associate. In electronic form it is called ePHI and falls under the HIPAA Security Rule. The definition turns on two things together, health information and an identifier, not on either alone.
The 18 identifiers
| Identifier | |
|---|---|
| 1 | Names |
| 2 | Geographic subdivisions smaller than a state |
| 3 | All dates related to an individual except year |
| 4 | Telephone numbers |
| 5 | Fax numbers |
| 6 | Email addresses |
| 7 | Social Security numbers |
| 8 | Medical record numbers |
| 9 | Health plan beneficiary numbers |
| 10 | Account numbers |
| 11 | Certificate or license numbers |
| 12 | Vehicle identifiers and serial numbers |
| 13 | Device identifiers and serial numbers |
| 14 | Web URLs |
| 15 | IP addresses |
| 16 | Biometric identifiers, including finger and voice prints |
| 17 | Full-face photographs and comparable images |
| 18 | Any other unique identifying number, characteristic, or code |
What makes something PHI
Three conditions, all required:
- It is health information: physical or mental health, healthcare provision, or payment for healthcare.
- It identifies an individual, through one of the 18 identifiers above.
- It is held or transmitted by a covered entity or business associate. The same data in a consumer fitness app that has no such relationship is generally not PHI.
That third condition is the one people miss. HIPAA regulates specific relationships, not health data in the abstract.
PHI, ePHI, and what changes
ePHI is PHI in electronic form. The distinction matters because the Security Rule applies only to ePHI, requiring administrative, physical, and technical safeguards. The Privacy Rule applies to PHI in every form, including paper charts and conversations.
De-identification removes it from scope
Two routes, both defined in the Privacy Rule:
- Safe Harbor: remove all 18 identifiers and have no actual knowledge that the remainder could identify someone.
- Expert determination: a qualified statistician certifies the re-identification risk is very small and documents the methodology.
Removing some identifiers is not de-identification. Data with 15 of 18 removed is still PHI.
Why this matters for a SaaS company
If your product touches PHI on behalf of a covered entity, you are a business associate with direct legal obligations, regardless of company size. That means a signed BAA, a documented risk analysis, and implemented safeguards. See what is a business associate agreement and what is HIPAA compliance and when does a SaaS company need it.