Glossary

What is PHI?

Protected Health Information is health information that identifies an individual, or could reasonably be used to identify them, when it is held or transmitted by a healthcare provider or one of its business associates.

The threshold is lower than most people assume, and the reason is that identification is contextual. PHI is not limited to diagnoses and treatment plans. It is any health-related information tied to an identifiable person, and identifiability can come from the surrounding circumstances rather than from a name.

The regulation gets there in two steps. Individually identifiable health information is health information created or received by a provider that relates to someone’s physical or mental health, the care they received or the payment for it, and that either identifies them or gives a reasonable basis to believe they could be identified. Protected health information is that same information once a covered entity or business associate holds or transmits it, in any medium — electronic, paper or spoken.

The clearest illustration in a clinic is a photograph. A picture of a child at your premises, sent to their parent, carries no diagnosis in the image. But the location implies the service, and the service implies the diagnosis, so the photograph is PHI. The same logic applies to a schedule, an attendance record or a note about why a session was cut short.

This is also why de-identification is harder than removing a name. The regulation offers two routes — an expert determination, or removing eighteen specified categories of identifier and having no actual knowledge that what remains could still identify anyone. Where a small clinic serves a small community, a description detailed enough to be clinically useful is often detailed enough to identify the child to anyone who knows them.

In an ABA clinic specifically.

Almost everything a technician would naturally tell a parent is PHI: how a transition went, a behaviour count, a protocol change, a photograph from the session. Clinics tend to underestimate this because the information feels pastoral rather than medical, which is exactly how it ends up in a classroom app.

Questions people ask about PHI.

What is considered PHI under HIPAA?

Any health information that identifies an individual, or could reasonably be used to identify them, once a covered entity or business associate holds it. That includes the obvious — diagnoses, treatment notes, session data, billing records — and the less obvious: appointment times, attendance, a photograph taken at your clinic, a parent’s phone number in your system, or a message saying a named child had a hard afternoon. The medium is irrelevant. Paper, email, a push notification and a spoken handover are all in scope.

What is not considered PHI under HIPAA?

Four things are carved out by the definition itself: information in education records covered by FERPA, information in the treatment records described at 20 U.S.C. 1232g(a)(4)(B)(iv), employment records a covered entity holds as an employer, and information about a person who has been dead more than fifty years. Separately, health information that identifies nobody is not PHI at all — but genuinely de-identified data is harder to produce than it sounds, and health information a clinic never held is outside HIPAA rather than exempt from it.

What are the 18 PHI identifiers?

They are the categories that have to be stripped for the safe-harbour route to de-identification: names; all geographic subdivisions smaller than a state; all elements of dates except year, plus ages over 89; telephone numbers; fax numbers; email addresses; Social Security numbers; medical record numbers; health plan beneficiary numbers; account numbers; certificate or licence numbers; vehicle identifiers; device identifiers; URLs; IP addresses; biometric identifiers; full-face photographs and comparable images; and any other unique identifying number, characteristic or code.

Is a photograph of a child PHI?

At an ABA clinic, yes. A full-face photograph is one of the eighteen identifiers outright, and the context supplies the health information: a picture taken at a clinic that treats autism implies why the child is there. This is the single most common way PHI leaves a clinic through a tool nobody evaluated, because sending a photo home does not feel like disclosing a medical record.

What is the difference between PHI and ePHI?

ePHI is the subset of PHI that is transmitted or maintained in electronic media. The distinction matters because the Privacy Rule covers PHI in every medium, while the Security Rule — the one about access controls, audit controls, encryption and transmission security — applies specifically to ePHI. A clinic’s parent messaging is ePHI, so both rules are in play.

Is it PHI or personal health information?

The statutory term is protected health information. "Personal health information" and "private health information" are common renderings and both are wrong in a document that matters, because neither is defined anywhere in the regulation. If you are writing a policy, a BAA or a parent-facing notice, use protected health information.

Does PHI include a name on its own?

A name by itself, with no health context and not held by a covered entity, is not PHI. A name on your caseload is, because being on the caseload of an ABA clinic is health information about that person. This is why an exported client list is a disclosure and a phone contact list on a technician’s personal handset is a problem.

Is a schedule PHI?

Yes, if it names children. An appointment record shows that an identified individual is receiving care from your clinic, which is information about the provision of health care to an individual. Session times, cancellations and attendance are all PHI for the same reason, which is why scheduling screenshots in a group chat are worth taking seriously.

Written by Abdihafid, a behavior technician working in an in-person ABA clinic. This is a plain-language explanation for people evaluating software, not legal advice, and it is not a substitute for your own compliance counsel.

Other terms

Sources

The definitions on this page are quoted from the regulation itself rather than from a summary of it, linked below with the date we last read them there. This is a plain-language explanation for people evaluating software, not legal advice.

  1. [1] 45 CFR 160.103Definitions — “Protected health information” · checked August 31, 2026
  2. [2] 45 CFR 160.103Definitions — “Individually identifiable health information” · checked August 31, 2026
  3. [3] 45 CFR 160.103Definitions — “Protected health information”, paragraph (2) · checked August 31, 2026
  4. [4] 45 CFR 164.514Other requirements relating to uses and disclosures of PHI, paragraph (a) · checked August 31, 2026

Show us what you are using now.

Fifteen minutes. If what you have works for your caseload, we will tell you to keep it.