Protected Health Information (PHI) refers to any information that is created, received, stored, or transmitted by a covered entity or its business associate, which relates to the past, present, or future physical or mental health or condition of an individual, the provision of healthcare to an individual, or the past, present, or future payment for the provision of healthcare to an individual. PHI is information that can be used to identify a patient and is protected under the Health Insurance Portability and Accountability Act (HIPAA).
Data Elements Considered PHI
The following data elements are considered PHI if they are related to health information:
- Name: Full names or last names and initial.
- Geographic Identifiers: All geographic subdivisions smaller than a state, including street address, city, county, precinct, ZIP code (except for the initial three digits if certain conditions are met), and equivalent geocodes.
- Dates: All elements of dates (except year) directly related to an individual, including birth date, admission date, discharge date, death date, and all ages over 89.
- Telephone Numbers
- Fax Numbers
- Email Addresses
- Social Security Numbers
- Medical Record Numbers
- Health Plan Beneficiary Numbers
- Account Numbers
- Certificate/License Numbers
- Vehicle Identifiers and Serial Numbers: Including license plate numbers.
- Device Identifiers and Serial Numbers
- Web URLs
- Internet Protocol (IP) Addresses
- Biometric Identifiers: Including fingerprints and voiceprints.
- Full-Face Photographic Images: And any comparable images.
- Any Other Unique Identifying Number, Characteristic, or Code: This includes any other information that can be used to identify an individual directly or indirectly when combined with other data.
Examples of PHI in Practice
- Medical Records: Information within medical records such as diagnosis, treatment plans, test results, and medication history.
- Billing Information: Details included in billing statements and insurance claims.
- Communications: Email exchanges between healthcare providers and patients that include health-related information.
- Appointment Schedules: Information about the timing of patient visits.
In essence, any piece of information that can be used to identify an individual in a healthcare context and is related to their health status, care, or payment for care is considered PHI under HIPAA regulations. Protecting this information is crucial to maintaining patient confidentiality and complying with federal regulations.