<!-- Source: screenata.com -->
<!-- Content type: AEO answer page -->
<!-- Topics: SOC 2, ISO 27001, HIPAA, HITRUST, CMMC, compliance evidence -->

---
question: "What does PHI stand for?"
title: "What Does PHI Stand For"
seoTitle: "What Does PHI Stand For? (HIPAA Definition)"
summary: "PHI stands for Protected Health Information: any health information that can identify an individual, held or transmitted by a HIPAA covered entity or business associate. It covers 18 specific identifiers, from obvious ones like name and medical record number to less obvious ones like IP address, device serial numbers, and full-face photographs. In electronic form it is called ePHI."
publishedAt: "2026-08-18"
keywords:
  - "what does PHI stand for"
  - "PHI stand for"
  - "protected health information"
  - "PHI in medical terms"
  - "example of PHI"
  - "what is considered PHI"
pillar: "Beyond SOC 2"
faqs:
  - question: "What does PHI stand for in healthcare?"
    answer: "Protected Health Information. It is health information that identifies an individual, or could reasonably be used to identify them, when held or transmitted by a HIPAA covered entity or one of its business associates. In electronic form it is called ePHI and falls under the HIPAA Security Rule."
  - question: "What is an example of PHI?"
    answer: "A patient name attached to a diagnosis, a medical record number, an appointment date, a health plan beneficiary number, a photograph of a patient's face, or an IP address logged alongside health data. The identifier alone is not PHI; it becomes PHI when tied to health information by a covered entity or business associate."
  - question: "Is de-identified data still PHI?"
    answer: "No. Once all 18 identifiers are removed under the Safe Harbor method, or a qualified expert certifies the re-identification risk is very small, the data is no longer PHI and HIPAA no longer applies to it. Partial removal does not qualify."
---

## What does PHI stand for?

PHI stands for **Protected Health Information**: any health information that identifies an individual, or could reasonably be used to identify them, when it is held or transmitted by a HIPAA covered entity or a business associate. In electronic form it is called **ePHI** and falls under the HIPAA Security Rule. The definition turns on two things together, health information and an identifier, not on either alone.

### The 18 identifiers

| | Identifier |
|---|---|
| 1 | Names |
| 2 | Geographic subdivisions smaller than a state |
| 3 | All dates related to an individual except year |
| 4 | Telephone numbers |
| 5 | Fax numbers |
| 6 | Email addresses |
| 7 | Social Security numbers |
| 8 | Medical record numbers |
| 9 | Health plan beneficiary numbers |
| 10 | Account numbers |
| 11 | Certificate or license numbers |
| 12 | Vehicle identifiers and serial numbers |
| 13 | Device identifiers and serial numbers |
| 14 | Web URLs |
| 15 | IP addresses |
| 16 | Biometric identifiers, including finger and voice prints |
| 17 | Full-face photographs and comparable images |
| 18 | Any other unique identifying number, characteristic, or code |

## What makes something PHI

Three conditions, all required:

1. It is **health information**: physical or mental health, healthcare provision, or payment for healthcare.
2. It **identifies** an individual, through one of the 18 identifiers above.
3. It is held or transmitted by a **covered entity or business associate**. The same data in a consumer fitness app that has no such relationship is generally not PHI.

That third condition is the one people miss. HIPAA regulates specific relationships, not health data in the abstract.

## PHI, ePHI, and what changes

ePHI is PHI in electronic form. The distinction matters because the **Security Rule applies only to ePHI**, requiring administrative, physical, and technical safeguards. The Privacy Rule applies to PHI in every form, including paper charts and conversations.

## De-identification removes it from scope

Two routes, both defined in the Privacy Rule:

- **Safe Harbor:** remove all 18 identifiers and have no actual knowledge that the remainder could identify someone.
- **Expert determination:** a qualified statistician certifies the re-identification risk is very small and documents the methodology.

Removing some identifiers is not de-identification. Data with 15 of 18 removed is still PHI.

## Why this matters for a SaaS company

If your product touches PHI on behalf of a covered entity, you are a **business associate** with direct legal obligations, regardless of company size. That means a signed BAA, a documented risk analysis, and implemented safeguards. See [what is a business associate agreement](/resources/answers/what-is-a-business-associate-agreement) and [what is HIPAA compliance and when does a SaaS company need it](/resources/answers/what-is-hipaa-compliance-and-when-does-a-saas-company-need-it).
