Protected health information (PHI)
Protected health information (PHI) is the term used by the US HIPAA Privacy Rule (45 CFR 160.103) for individually identifiable health information that is created, received, maintained or transmitted by a covered entity or its business associate, in any form or medium. Health information is individually identifiable if it relates to the past, present or future physical or mental health of an individual, the provision of healthcare, or payment for healthcare, and identifies the individual or could reasonably be used to identify them. Electronic PHI (ePHI) is PHI in electronic form and is the subject of the Security Rule. Employment records held by an employer and education records under FERPA are excluded, and information about a person deceased more than 50 years is no longer PHI.
The Privacy Rule lists 18 identifiers whose removal is the basis of the Safe Harbor de-identification method: names; geographic subdivisions smaller than a state (with limited ZIP code exceptions); all elements of dates except year (and ages over 89); telephone and fax numbers; email addresses; Social Security numbers; medical record numbers; health plan beneficiary numbers; account numbers; certificate or licence numbers; vehicle identifiers; device identifiers and serial numbers; URLs; IP addresses; biometric identifiers; full-face photographs; and any other unique identifying number or code. PHI may be used and disclosed without authorisation for treatment, payment and healthcare operations, for public health and certain other listed purposes, and otherwise generally requires the individual's written authorisation; the "minimum necessary" standard applies to most uses.
PHI is narrower than data concerning health under the GDPR in one respect and broader in another: it covers only information held within the HIPAA perimeter of covered entities and business associates, so health data held by a wellness app developer or a pharmaceutical sponsor is not PHI, but within that perimeter it includes payment and demographic information that the GDPR would classify as ordinary personal data. In a transatlantic clinical trial, the US site holds PHI and needs a HIPAA authorisation or IRB waiver to disclose data to the sponsor, while the EU site holds health data governed by Art. 9 GDPR; the sponsor's coded dataset is de-identified or a limited data set under HIPAA yet pseudonymised personal data under the GDPR. Drafting consent forms, contracts and breach procedures that respect both classifications is a core task in global trials; see iliomad's HIPAA services.
