What actually counts as protected health information? The line is subtler than most teams think, and it catches things like appointment data. Here is the test that settles it.
TL;DR
PHI is health-related information that can identify a specific person, held by a covered entity or business associate. It is the combination that matters: health context plus identifiability. Names alone are not PHI, and medical facts with no link to a person are not either, but together they are.
This is why appointment and scheduling data often counts: a name tied to a provider and a date reveals that a person sought care. When in doubt, treat identifiable health-linked data as PHI.
On this page
What protected health information actually is
Protected health information is any information about a person’s health, care, or payment for care that can be used to identify them, when it is held by a covered entity or a business associate. That definition has three moving parts: it is health-related, it is identifiable, and it sits with an organisation subject to HIPAA. Miss the nuance and you either over-protect harmless data or, more dangerously, fail to protect something that quietly qualifies.
The two-part test
The cleanest way to decide is to ask two questions. Data becomes PHI only when the answer to both is yes.
Is the information health-related, created or used in connection with care, payment, or health operations? And can it identify a specific individual, on its own or combined with other data you hold? Health context without identifiability is not PHI; an identifier without health context is not PHI; the two together are.
Is scheduling or appointment data PHI?
This is the question that trips up many product teams, and the answer is usually yes. Consider an appointment record: a patient’s name, the provider they are seeing, and a date and time. Individually, a date is meaningless. But linked to a named person and a healthcare provider, it reveals that this specific individual sought care from that provider, which is health information about an identifiable person. That is PHI.
The 18 identifiers
HIPAA names 18 specific identifiers that, when tied to health information, make it PHI. They include the obvious ones and several that surprise people.
| Category | Examples |
|---|---|
| Direct identity | Names, Social Security numbers, medical record numbers |
| Contact | Addresses, phone numbers, email addresses |
| Dates | Birth, admission, discharge, and other dates tied to the person |
| Digital | IP addresses, device identifiers, account numbers |
| Biometric | Fingerprints, voiceprints, and full-face photographs |
Any of these, attached to health information, makes the data identifiable and therefore PHI. Removing all 18 correctly is the basis of Safe Harbor de-identification.
Common edge cases
- Appointment and scheduling data: usually PHI, because it links a person to a provider.
- IP addresses and device IDs: can be PHI when tied to health context, they are on the identifier list.
- Aggregated or de-identified data: not PHI, if properly de-identified so no one can be re-identified.
- Employment records held by an employer: generally not PHI, though the same data in a health plan can be.
- Health app data: PHI when handled for a covered entity; the context decides.
The lean-team path to knowing where PHI lives
Deciding what counts as PHI is only useful if you then know everywhere it actually lives and can keep it protected, across databases, logs, backups, and the scheduling systems that quietly hold it. That visibility and protection is where lean teams struggle when data is spread across disconnected tools.
Protect PHI everywhere it hides, including the schedule.
Osto is the one-stop cybersecurity and compliance platform built for fast-moving startups. Secure identifiable health data across every system that holds it, with evidence, on one platform mapped to HIPAA. No security team required.
Frequently asked questions
What counts as PHI under HIPAA?
Health-related information that can identify a specific person, held by a covered entity or business associate. It requires both a health context and identifiability. Health data with no link to a person, or an identifier with no health context, is not PHI on its own; together they are.
Is appointment or scheduling data PHI?
Usually yes. A patient’s name tied to a provider and an appointment date reveals that a specific person sought care, which is health information about an identifiable individual. Even without medical details, that combination is protected health information.
What are the 18 HIPAA identifiers?
Eighteen data elements that make health information identifiable, including names, Social Security and medical record numbers, addresses, phone and email, dates tied to the person, IP and device identifiers, account numbers, and biometrics like fingerprints and full-face photos.
Is an IP address PHI?
It can be. IP addresses are on HIPAA’s identifier list, so when an IP address is tied to health information about a person, it can qualify as PHI. Context determines whether it is protected in a given case.
Is de-identified data PHI?
No. Properly de-identified data, with identifiers removed so no one can reasonably be re-identified, is not PHI and falls outside HIPAA’s restrictions. But partial removal that still allows identification leaves the data as PHI.
What should I do if I am unsure whether something is PHI?
Treat it as PHI. Over-protecting a harmless field matters little, while leaving genuine PHI exposed risks a breach. Erring toward protection is the safe default when the classification is uncertain.

