Massive Bio has made its inaugural strategic investment in Rivvi. Read the announcement

← Glossary

Definition · Allowed AI at work

Protected health information (PHI)

Protected health information (PHI) is individually identifiable health information that a HIPAA covered entity or business associate creates, receives, maintains, or transmits. It covers data about a person's health, care, or payment for care that could identify them. It applies in any form: electronic, paper, or spoken. Electronic PHI is called ePHI.

What protected health information is

PHI is defined in HIPAA at 45 CFR 160.103. Information is PHI when it relates to a person's past, present, or future health, care, or payment for care. It must also identify the person or give a reasonable basis to identify them. It must also be held or handled by a covered entity or a business associate.

Names, addresses, dates of service, phone numbers, medical record numbers, and health plan IDs all make health data identifiable. A patient list with diagnoses is PHI. So is a recorded call about a refill. Health data a person keeps in their own consumer app is usually not PHI, because no covered entity holds it. Employment records a covered entity keeps as an employer are also excluded.

Any software that handles PHI for a practice, pharmacy, or plan is a business associate and needs a signed BAA. AI tools are no exception. Pasting a patient list into a consumer chatbot with no BAA is a disclosure HIPAA does not permit. Rivvi is a HIPAA-compliant AI workspace with a BAA included on the free plan, and PHI access is logged.

Questions

PHI, answered

What counts as PHI under HIPAA?
Any health, care, or payment information that identifies a person and is held by a covered entity or business associate. Examples include visit notes, lab results, claims, appointment lists, prescription records, and recorded patient calls. The form does not matter: a spreadsheet, a fax, and a voicemail can all be PHI.
Is a patient's name alone PHI?
It depends on context. A name in a phone book is not PHI. The same name on a practice's appointment list is PHI, because it shows the person received care there. Being a patient of a specific provider is itself health information when a covered entity holds it.
PHI vs ePHI: what is the difference?
ePHI is simply PHI in electronic form, such as data in an EHR, a spreadsheet, an email, or an AI tool. The Privacy Rule protects PHI in every form. The Security Rule adds administrative, physical, and technical safeguards that apply specifically to ePHI.
Is de-identified data still PHI?
No. Health information de-identified under HIPAA's Safe Harbor or Expert Determination method is no longer PHI, and the Privacy Rule stops applying to it. Removing names alone is not enough. Dates, ZIP codes, phone numbers, and record numbers can still identify a person.

Try it on your own data today.

Free to start. Most teams are using it the same day.