Key Takeaways
- PHI stands for protected health information under HIPAA, the federal law that governs how covered entities and their business associates handle individually identifiable patient data.
- The presence of any one of HIPAA's 18 specified identifiers combined with health information creates PHI, regardless of format: paper, electronic, or verbal.
- Protecting PHI requires layered safeguards across three categories: administrative, physical, and technical, each addressing a distinct category of risk.
- Practices that consolidate PHI in a programmable EMR with role-based access, detailed audit history, and controlled integrations reduce exposure more effectively than those managing data across disconnected systems. Every time a clinician documents a diagnosis, a billing team processes a claim, or a lab result gets attached to a patient record, protected health information is in motion. HIPAA sets the rules for how that information must be handled, but the regulation is detailed enough that organizations often underestimate how broadly PHI is defined, how frequently it surfaces in routine workflows, and what protecting it actually requires in practice. Getting that wrong carries real consequences: breach notification obligations, OCR investigations, civil penalties, and erosion of patient trust. This guide covers what PHI is, which identifiers create it, what safeguards HIPAA requires, and how to build operational practices that protect patient data consistently, not just on paper.
What PHI Stands For and Why the Definition Is Precise
PHI stands for protected health information. Under the Health Insurance Portability and Accountability Act (HIPAA), PHI is any individually identifiable health information relating to a person's past, present, or future health condition, the provision of care, or payment for that care. The phrase "individually identifiable" carries most of the definitional weight. A diagnosis code alone is not PHI. That same code linked to a patient name, date of birth, or medical record number is. The information doesn't need to be obviously sensitive. The combination of health context and identity is what triggers protection. HIPAA applies to information created or received by a covered entity or its business associates. Covered entities include health plans, healthcare clearinghouses, and providers that transmit health information electronically. Business associates include billing companies, EMR vendors, and cloud infrastructure providers that handle PHI on a covered entity's behalf. PHI is protected in any format: printed on paper, stored electronically, or spoken aloud during a clinical encounter.
The 18 HIPAA Identifiers That Make Health Information PHI
HIPAA specifies exactly 18 identifiers that transform health information into PHI. Any one of them, when present alongside health data, creates a compliance obligation:
- Names
- Geographic subdivisions smaller than a state (street address, city, county, zip code)
- All date elements except year (birth dates, admission dates, discharge dates)
- Phone numbers
- Fax numbers
- Email addresses
- Social Security numbers
- Medical record numbers
- Health plan beneficiary numbers
- Account numbers
- Certificate or license numbers
- Vehicle identifiers and serial numbers
- Device identifiers and serial numbers
- Web URLs
- IP addresses
- Biometric identifiers (fingerprints, voice prints)
- Full face photographs and comparable images
- Any other unique identifying number or code A spreadsheet containing patient zip codes and diagnoses is PHI. An email referencing a patient's treatment plan that includes an account number is PHI. A photograph in a patient chart is PHI regardless of whether other identifiers accompany it, because the image itself is an identifier.
PHI in Clinical Practice: Where It Appears
PHI shows up in routine clinical operations in ways that don't always register as sensitive until a compliance question arises. A lab result with a patient name is PHI. A medical record number is PHI. A date of birth paired with a diagnosis is PHI. An insurance member ID linked to claims data is PHI. These are not edge cases. Billing staff handles insurance member IDs every day. Clinicians document lab results with patient names in every encounter. Every one of those touchpoints is a moment where PHI must be handled in accordance with HIPAA.
What Information Falls Outside PHI Protections
Not all health-related information qualifies as PHI under HIPAA. De-identified data sits outside HIPAA's scope once all 18 identifiers have been removed, and there is no reasonable basis to believe the information could identify an individual. Research institutions frequently work with de-identified data for this reason. Other information that falls outside PHI protections: education records protected under the Family Educational Rights and Privacy Act (FERPA), employment records maintained by an employer in their capacity as employer, health information collected by consumer apps that don't operate as covered entities or business associates, and information about individuals deceased for more than 50 years.
The Designated Record Set and PHI Access Rights
HIPAA grants patients specific rights over their PHI, centered on what the regulation calls the designated record set. This includes medical and billing records maintained by a provider, enrollment, payment, claims adjudication, and case management records maintained by a health plan, and any record used to make decisions about an individual. Patients have the right to access their designated record set, request amendments, and receive an accounting of disclosures. Healthcare organizations must respond to these requests within timeframes defined by the Privacy Rule. Failure to respond constitutes a violation independent of whether PHI was misused in any other way.
How Healthcare Organizations Protect PHI
HIPAA's Security Rule requires three categories of safeguards for electronic PHI. Each addresses a distinct layer of risk.
- Administrative safeguards govern internal security management: conducting a formal risk analysis, training staff on HIPAA requirements, establishing access management procedures, and maintaining an incident response process. The risk analysis is not a one-time activity. OCR investigations frequently surface inadequate training as a contributing factor in breach cases.
- Physical safeguards address the environments where PHI is stored or accessed. This includes facility access controls, workstation use policies, screen-lock and auto-timeout requirements, and device disposal procedures. These requirements apply regardless of whether a practice operates in the cloud.
- Technical safeguards govern the systems themselves. HIPAA requires access controls that restrict PHI to authorized users, audit controls that log who accessed or modified what and when, integrity controls that detect unauthorized alteration of PHI, and transmission security for data moving between systems. Authentication, encryption at rest and in transit, and comprehensive audit logging are regulatory requirements, not optional engineering choices.
How to Protect PHI in a Medical Practice
Protecting PHI effectively requires treating compliance as an operational design problem, not a documentation exercise.
- Map where PHI moves. Every integration point, vendor relationship, and workflow that routes clinical data is a potential exposure. Understanding the full surface area of PHI is a prerequisite to controlling it.
- Implement role-based access. Not everyone needs access to everything. Limiting access to what each role requires reduces both intentional misuse and accidental disclosure. Permissions should be reviewed regularly and revoked promptly when staff leave or change roles.
- Automate enforcement where possible. Systems that enforce encryption, log access, apply retention policies, and trigger alerts for anomalous behavior reduce the burden on individual staff while improving consistency. A training policy read once a year is not the same as a system that enforces access controls continuously.
- Sign business associate agreements with every vendor handling PHI. This includes EMR vendors, billing services, cloud storage providers, and analytics platforms. BAAs establish shared accountability and are required before PHI can be lawfully transmitted to a third party.
- Maintain a breach response plan before a breach occurs. Under HIPAA's Breach Notification Rule, incidents affecting fewer than 500 individuals must be reported to HHS no later than 60 days after the end of the calendar year in which they were discovered (HHS). Incidents affecting 500 or more must be reported within 60 days of discovery and are posted publicly to OCR's breach portal.
How Canvas Supports PHI Protection
Canvas is a programmable EMR and care modeling platform that is HIPAA compliant, HITRUST certified, ONC certified, and SOC 2 Type II compliant. Every instance runs in its own isolated environment, and each customer has a dedicated development environment for testing integrations before they reach production. Canvas's full approach to security covers how those controls are implemented and maintained.
Role-based access and audit history
Canvas enforces access controls at the platform level. Teams define which roles can view, create, or modify specific data types, and those permissions apply consistently across every workflow. Every access and modification to patient data is logged in an audit trail that's embedded in the platform and available for review at any time. ONC-certified auditable events and tamper-resistance are built into Canvas's certified capabilities.
A unified architecture that reduces PHI fragmentation
The Canvas Deep Unified Architecture links ICD-10, LOINC, CPT, and HCC into a coherent, navigable data model. Through the Data Module in the Canvas SDK, developers get controlled access to both PHI and non-PHI within a single governed environment, rather than letting patient data replicate across exports, spreadsheets, and unreviewed integrations.
Secure patient communications
For practices sending patient communications at scale, the Lob Secure Mail Integration connects a HIPAA-certified direct mail partner directly into EMR workflows, so outgoing statements and clinical communications route through an auditable, compliant channel. Canvas gives care teams the ability to extend and customize their workflows without trading away control over where PHI lives or who can access it.
PHI Compliance Requires Operational Discipline, Not Just Policy
PHI protections are not self-executing. The 18 identifiers, the three safeguard categories, and the breach notification timelines are the regulatory structure. What the regulation cannot mandate is the operational culture that determines whether those requirements are embedded in how a practice actually works or exist only on paper. Practices that handle PHI well treat every new integration, every new role, and every new workflow as a question worth asking: where does PHI go here, and who controls access to it? For teams that want a platform built around that question from the ground up, Canvas Medical is worth a closer look.
Frequently Asked Questions:
What does PHI stand for in healthcare?
PHI stands for protected health information. It refers to any individually identifiable health information created or received by a covered entity or business associate under HIPAA that relates to a person's health condition, the provision of care, or payment for that care.
What are the 18 HIPAA identifiers?
Names, geographic subdivisions smaller than a state, dates except year, phone numbers, fax numbers, email addresses, Social Security numbers, medical record numbers, health plan beneficiary numbers, account numbers, certificate or license numbers, vehicle identifiers, device identifiers, web URLs, IP addresses, biometric identifiers, full face photographs, and any other unique identifying number or code.
What is considered PHI in healthcare?
Any individually identifiable health information about health status, care, or payment that is created or received by a HIPAA covered entity or business associate, in any format.
What are examples of PHI?
A lab result with a patient name, a medical record number, a date of birth paired with a diagnosis, an insurance member ID linked to claims data, and a full face photograph in a patient chart.
What is not covered by PHI?
De-identified data with all 18 identifiers removed, education records governed by FERPA, employment records held by an employer, health information collected by consumer apps not acting as covered entities or business associates, and information about individuals deceased for more than 50 years.

