{"id":823,"date":"2026-08-17T04:34:39","date_gmt":"2026-08-17T04:34:39","guid":{"rendered":"https:\/\/www.osto.one\/resources\/?p=823"},"modified":"2026-08-17T04:34:39","modified_gmt":"2026-08-17T04:34:39","slug":"protected-health-information","status":"publish","type":"post","link":"https:\/\/www.osto.one\/resources\/glossary\/protected-health-information\/","title":{"rendered":"PHI Explained: The 18 HIPAA Identifiers"},"content":{"rendered":"\n<!-- =========================================================================\n     OSTO GLOSSARY: PHI\n     Shared glossary design system. Paste into one Custom HTML block. No H1.\n     ========================================================================= -->\n\n<style>\n.og{\n  --navy:#1c267a; --text:#0f1538; --muted:#0f1538; --light:#0f1538;\n  --border:#e7e9f2; --divider:#eceef5; --white:#ffffff;\n\n  --peri-50:#f4f5fd;  --peri-100:#e9ecfa; --peri-200:#cfd5f2; --peri-700:#4a52a8;\n  --sage-50:#f2f8f5;  --sage-100:#e3f0e9; --sage-200:#c3ddce; --sage-700:#3a6f5d;\n  --apri-50:#fdf6f0;  --apri-100:#fbe9dc; --apri-200:#f2cdb2; --apri-700:#a2603a;\n  --plum-50:#f8f3f9;  --plum-100:#f0e6f3; --plum-200:#dcc6e2; --plum-700:#6b4576;\n  --sky-50:#f1f7fb;   --sky-100:#e2eff7;  --sky-200:#bfd9e9;  --sky-700:#2f6a89;\n\n  --shadow:0 6px 22px rgba(15,21,56,.05);\n  --font:'Inter',-apple-system,BlinkMacSystemFont,'Segoe UI',Roboto,sans-serif;\n  font-family:var(--font); font-size:17px; line-height:1.75; color:var(--text);\n}\n.og p{margin:0 0 22px}\n.og h2{font-family:var(--font);font-size:clamp(25px,3vw,31px);font-weight:700;line-height:1.25;letter-spacing:-.5px;color:var(--navy);margin:52px 0 8px;scroll-margin-top:92px}\n.og h2::after{content:\"\";display:block;width:46px;height:5px;border-radius:3px;margin:12px 0 18px;background:var(--peri-200)}\n.og h2.c-sage::after{background:var(--sage-200)}\n.og h2.c-apri::after{background:var(--apri-200)}\n.og h2.c-plum::after{background:var(--plum-200)}\n.og h2.c-sky::after{background:var(--sky-200)}\n.og ul,.og ol{padding-left:22px;margin:0 0 24px}\n.og li{margin-bottom:9px}\n.og strong{font-weight:600}\n\n.og .dek{font-size:20px;line-height:1.6;color:var(--muted);margin:0 0 18px}\n.og .tags{margin:0 0 30px;padding:0;list-style:none;display:flex;flex-wrap:wrap;gap:8px}\n.og .tags li{margin:0}\n.og .tag{display:inline-block;font-size:12px;font-weight:600;letter-spacing:.7px;text-transform:uppercase;padding:6px 13px;border-radius:20px}\n.og .t-peri{background:var(--peri-100);color:var(--peri-700)}\n.og .t-sage{background:var(--sage-100);color:var(--sage-700)}\n\n.og .short{background:linear-gradient(135deg,var(--peri-100) 0%,var(--sage-100) 100%);border-radius:22px;padding:28px 32px;margin:0 0 30px}\n.og .short .k{font-size:13px;font-weight:700;letter-spacing:1.4px;text-transform:uppercase;color:var(--peri-700);margin:0 0 10px}\n.og .short p{font-size:19px;line-height:1.65;margin:0;color:var(--text)}\n\n.og .toc{background:var(--peri-50);border-radius:20px;padding:24px 28px;margin:0 0 34px}\n.og .toc .k{font-size:12px;font-weight:700;letter-spacing:1.3px;text-transform:uppercase;color:var(--peri-700);margin:0 0 12px}\n.og .toc ol{margin:0;padding-left:20px;columns:2;column-gap:34px}\n.og .toc li{margin-bottom:8px;break-inside:avoid;font-size:16px}\n.og .toc a{color:var(--navy);text-decoration:none;border-bottom:1px solid rgba(28,38,122,.22)}\n\n.og .callout{border-radius:4px;padding:24px 28px;margin:0 0 30px;background:var(--white);border:2px solid var(--navy)}\n.og .callout .k{font-weight:700;font-size:17px;margin:0 0 8px;color:var(--navy)}\n.og .callout p:last-child{margin-bottom:0}\n.og .callout.c-plum{background:var(--plum-50);border:none;border-radius:20px}\n.og .callout.c-plum .k{color:var(--plum-700)}\n\n.og figure{margin:0 0 30px}\n.og .sx{overflow-x:auto;-webkit-overflow-scrolling:touch;border-radius:20px;background:var(--white);box-shadow:var(--shadow)}\n.og .sx svg{display:block;width:100%;height:auto;min-width:600px}\n.og figcaption{font-size:14px;line-height:1.6;color:var(--muted);margin-top:12px}\n.og .swipe{display:none}\n\n.og table{width:100%;border-collapse:collapse;margin:0 0 28px;font-size:15px;background:var(--white);border-radius:18px;overflow:hidden;box-shadow:var(--shadow)}\n.og th{text-align:left;padding:14px 16px;font-weight:700;font-size:12.5px;letter-spacing:.8px;text-transform:uppercase}\n.og td{border-bottom:1px solid var(--divider);padding:13px 16px;vertical-align:top;line-height:1.6}\n.og tr:last-child td{border-bottom:none}\n.og .h-peri th{background:var(--peri-100);color:var(--peri-700)}\n.og .h-sage th{background:var(--sage-100);color:var(--sage-700)}\n.og .h-plum th{background:var(--plum-100);color:var(--plum-700)}\n\n.og .trio{display:grid;grid-template-columns:repeat(3,1fr);gap:14px;margin:0 0 28px}\n.og .tcard{border-radius:18px;padding:20px 22px}\n.og .tcard .n{font-size:16px;font-weight:700;margin:0 0 4px}\n.og .tcard .g{font-size:13px;font-weight:600;margin:0 0 10px;opacity:.8}\n.og .tcard p{font-size:14px;line-height:1.55;margin:0;color:var(--muted)}\n.og .tcard.a{background:var(--sky-50)}   .og .tcard.a .n,.og .tcard.a .g{color:var(--sky-700)}\n.og .tcard.b{background:var(--sage-50)}  .og .tcard.b .n,.og .tcard.b .g{color:var(--sage-700)}\n.og .tcard.c{background:var(--plum-50)}  .og .tcard.c .n,.og .tcard.c .g{color:var(--plum-700)}\n\n.og .pill{display:inline-block;font-size:11px;font-weight:700;letter-spacing:.8px;text-transform:uppercase;padding:5px 11px;border-radius:20px;white-space:nowrap}\n.og .p-req{background:var(--plum-200);color:#4d2f57}\n.og .p-exp{background:var(--sky-100);color:var(--sky-700)}\n.og .p-imp{background:#eef0f4;color:var(--muted)}\n.og .p-ask{background:var(--apri-100);color:var(--apri-700)}\n\n.og details{background:var(--white);border-radius:14px;margin:0 0 10px;box-shadow:0 2px 10px rgba(15,21,56,.04)}\n.og summary{cursor:pointer;padding:16px 20px;font-weight:600;font-size:17px;color:var(--navy);list-style:none;display:flex;justify-content:space-between;gap:16px;align-items:flex-start}\n.og summary::-webkit-details-marker{display:none}\n.og summary::after{content:\"+\";font-size:22px;line-height:1;color:var(--peri-700);flex:0 0 auto}\n.og details[open] summary::after{content:\"\\2013\"}\n.og details p{padding:0 20px 18px;margin:0;font-size:16px;line-height:1.7}\n\n.og .related{font-size:15px;color:var(--muted);border-top:1px solid var(--divider);padding-top:22px;margin-top:40px}\n\n@media(max-width:700px){\n  .og{font-size:16px}\n  .og .dek{font-size:18px}\n  .og .short p{font-size:17px}\n  .og .short,.og .toc,.og .callout{padding:22px 20px}\n  .og .toc ol{columns:1}\n  .og .trio{grid-template-columns:1fr}\n  .og .swipe{display:inline;font-weight:600;color:var(--peri-700)}\n  .og table{font-size:14px}\n  .og th,.og td{padding:11px 12px}\n}\n<\/style>\n\n<div class=\"og\">\n\n<p class=\"dek\">Protected health information is any health information that can be tied back to a specific person and is held by a covered entity or its business associate.<\/p>\n\n<ul class=\"tags\">\n  <li><span class=\"tag t-peri\">Glossary<\/span><\/li>\n  <li><span class=\"tag t-sage\">HIPAA<\/span><\/li>\n<\/ul>\n\n<div class=\"short\">\n  <p class=\"k\">The short answer<\/p>\n  <p>Protected health information, or PHI, is individually identifiable health information created, received, stored or transmitted by a HIPAA covered entity or business associate. Two conditions both have to hold: the information relates to health, care or payment for care, and it can be linked to a specific individual. Remove the link reliably and it stops being PHI.<\/p>\n<\/div>\n\n<p>The word doing the work is identifiable. A blood pressure reading with no name, account number, date or postcode attached is not protected health information. The same reading in a record with a patient ID is.<\/p>\n\n<div class=\"toc\">\n  <p class=\"k\">On this page<\/p>\n  <ol>\n    <li><a href=\"#test\">The two-part test<\/a><\/li>\n    <li><a href=\"#identifiers\">The 18 identifiers<\/a><\/li>\n    <li><a href=\"#notphi\">What is not PHI<\/a><\/li>\n    <li><a href=\"#deid\">De-identification<\/a><\/li>\n    <li><a href=\"#osto\">How Osto protects health data<\/a><\/li>\n    <li><a href=\"#faq\">FAQ<\/a><\/li>\n  <\/ol>\n<\/div>\n\n<h2 id=\"test\">The two-part test<\/h2>\n\n<figure>\n<div class=\"sx\">\n<svg viewBox=\"0 0 760 210\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" role=\"img\" aria-label=\"Health information plus an identifier equals protected health information; remove either and it is not PHI.\">\n  <rect x=\"18\" y=\"46\" width=\"196\" height=\"86\" rx=\"15\" fill=\"#e9ecfa\"\/>\n  <text x=\"116\" y=\"80\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"13.5\" font-weight=\"700\" fill=\"#4a52a8\">Health information<\/text>\n  <text x=\"116\" y=\"102\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" fill=\"#0f1538\">Condition, care,<\/text>\n  <text x=\"116\" y=\"118\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" fill=\"#0f1538\">or payment for care<\/text>\n\n  <text x=\"240\" y=\"97\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"26\" font-weight=\"700\" fill=\"#4a52a8\">+<\/text>\n\n  <rect x=\"266\" y=\"46\" width=\"196\" height=\"86\" rx=\"15\" fill=\"#e3f0e9\"\/>\n  <text x=\"364\" y=\"80\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"13.5\" font-weight=\"700\" fill=\"#3a6f5d\">An identifier<\/text>\n  <text x=\"364\" y=\"102\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" fill=\"#0f1538\">Name, email, record<\/text>\n  <text x=\"364\" y=\"118\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" fill=\"#0f1538\">number, IP address<\/text>\n\n  <text x=\"488\" y=\"97\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"24\" font-weight=\"700\" fill=\"#4a52a8\">=<\/text>\n\n  <rect x=\"514\" y=\"46\" width=\"228\" height=\"86\" rx=\"15\" fill=\"#1c267a\"\/>\n  <text x=\"628\" y=\"80\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"14\" font-weight=\"700\" fill=\"#ffffff\">PHI<\/text>\n  <text x=\"628\" y=\"104\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" fill=\"#b9c1e6\">Full HIPAA obligations apply<\/text>\n\n  <text x=\"380\" y=\"172\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12\" fill=\"#0f1538\">Both halves are required. Health data with no identifier, and an identifier with no health context, fall outside.<\/text>\n  <text x=\"380\" y=\"192\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12\" font-weight=\"700\" fill=\"#4a52a8\">It only becomes PHI once a covered entity or business associate holds it.<\/text>\n<\/svg>\n<\/div>\n<figcaption><span class=\"swipe\">Swipe to see the full diagram. <\/span>Who holds the data matters as much as what the data says.<\/figcaption>\n<\/figure>\n\n<h2 id=\"identifiers\" class=\"c-sage\">The 18 identifiers<\/h2>\n\n<p>HIPAA names eighteen categories of identifier. Presence of any one of them alongside health information makes the record PHI.<\/p>\n\n<table class=\"h-sage\">\n  <thead>\n    <tr><th>Type<\/th><th>Identifiers<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td><strong>Direct<\/strong><\/td><td>Name, social security number, medical record number, health plan beneficiary number, account number, certificate or licence number<\/td><\/tr>\n    <tr><td><strong>Contact<\/strong><\/td><td>Address more specific than state, telephone, fax, email address, URL<\/td><\/tr>\n    <tr><td><strong>Digital<\/strong><\/td><td>IP address, device identifiers and serial numbers<\/td><\/tr>\n    <tr><td><strong>Temporal<\/strong><\/td><td>All dates tied to an individual except year, and any age over 89<\/td><\/tr>\n    <tr><td><strong>Biometric<\/strong><\/td><td>Fingerprints, voiceprints, full-face photographs and comparable images<\/td><\/tr>\n    <tr><td><strong>Other<\/strong><\/td><td>Vehicle identifiers, biometric identifiers and any other unique identifying code<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<div class=\"callout\">\n  <p class=\"k\">The one engineers usually miss<\/p>\n  <p>IP address is on the list. A web server log that records which IP viewed a page about a specific treatment, held by a covered entity, can be PHI. Application logs are in scope for the <a href=\"https:\/\/www.osto.one\/resources\/glossary\/hipaa-security-rule\/\">Security Rule<\/a> just like the database is.<\/p>\n<\/div>\n\n<h2 id=\"notphi\" class=\"c-apri\">What is not PHI<\/h2>\n\n<table class=\"h-peri\">\n  <thead>\n    <tr><th>Data<\/th><th>Why it falls outside<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td>Fitness tracker data you collect direct from consumers<\/td><td>You are not a covered entity or acting for one<\/td><\/tr>\n    <tr><td>Employment records held by an employer<\/td><td>Explicitly excluded, even when they contain health details<\/td><\/tr>\n    <tr><td>Student health records under FERPA<\/td><td>Governed by FERPA rather than HIPAA<\/td><\/tr>\n    <tr><td>Properly de-identified data sets<\/td><td>No longer individually identifiable<\/td><\/tr>\n    <tr><td>Aggregate statistics with no re-identification path<\/td><td>No link back to any individual remains<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<h2 id=\"deid\" class=\"c-plum\">De-identification<\/h2>\n\n<div class=\"trio\">\n  <div class=\"tcard a\">\n    <p class=\"n\">Safe Harbor<\/p>\n    <p>Strip all 18 identifier categories and have no actual knowledge the remainder can identify anyone.<\/p>\n  <\/div>\n  <div class=\"tcard b\">\n    <p class=\"n\">Expert Determination<\/p>\n    <p>A qualified statistician documents that the re-identification risk is very small. Keeps more analytic value.<\/p>\n  <\/div>\n  <div class=\"tcard c\">\n    <p class=\"n\">Limited data set<\/p>\n    <p>Neither of the above. Some identifiers remain, so it stays PHI and needs a data use agreement.<\/p>\n  <\/div>\n<\/div>\n\n<h2 id=\"osto\">How Osto protects health data<\/h2>\n\n<p>Once you hold PHI, protecting it is an engineering problem: know where it lives, control who reaches it, encrypt it, and log every access. Osto covers those directly with <a href=\"https:\/\/www.osto.one\/resources\/glossary\/dlp\/\">data loss prevention<\/a>, <a href=\"https:\/\/www.osto.one\/resources\/glossary\/mfa\/\">access control and MFA<\/a>, <a href=\"https:\/\/www.osto.one\/resources\/glossary\/encryption-at-rest-and-in-transit\/\">encryption<\/a> and <a href=\"https:\/\/www.osto.one\/resources\/glossary\/siem\/\">logging and monitoring<\/a>, mapped to the HIPAA safeguards inside the compliance platform alongside 200+ other frameworks.<\/p>\n\n<!-- ============ CTA ============ -->\n<div style=\"background:linear-gradient(135deg,#1c267a 0%,#3f4796 48%,#6b4576 100%);border-radius:22px;padding:38px 34px;margin:40px 0 12px;box-shadow:0 10px 26px rgba(28,38,122,.2);text-align:center;\">\n  <p style=\"display:inline-block;background:rgba(255,255,255,.16);color:#ffffff;font-family:'Inter',-apple-system,sans-serif;font-size:11px;font-weight:700;letter-spacing:1.2px;text-transform:uppercase;padding:6px 14px;border-radius:20px;margin:0 0 16px;\">Free security assessment<\/p>\n  <p style=\"color:#ffffff;font-family:'Inter',-apple-system,sans-serif;font-size:26px;line-height:1.3;font-weight:700;letter-spacing:-.4px;margin:0 0 12px;\">Know where patient data lives, and who reached it<\/p>\n  <p style=\"color:#cfd3ea;font-family:'Inter',-apple-system,sans-serif;font-size:16px;line-height:1.65;margin:0 auto 26px;max-width:520px;\">Osto covers discovery, access control, encryption and audit logging for health data, mapped to the HIPAA safeguards.<\/p>\n  <a href=\"https:\/\/osto.one\/contact\/\" style=\"display:inline-block;background:#ffffff;color:#1c267a;font-family:&#039;Inter&#039;,-apple-system,sans-serif;font-weight:700;font-size:16px;text-decoration:none;border-bottom:none;padding:14px 30px;border-radius:12px;margin:0 6px 10px;\" target=\"_blank\" rel=\"noopener\"><span style=\"color:#1c267a;\">Get a free security assessment<\/span><\/a>\n  <a href=\"https:\/\/osto.one\/book-demo\/\" style=\"display:inline-block;background:transparent;color:#ffffff;font-family:&#039;Inter&#039;,-apple-system,sans-serif;font-weight:600;font-size:16px;text-decoration:none;border:1.5px solid rgba(255,255,255,.5);border-radius:12px;padding:13px 28px;margin:0 6px 10px;\" target=\"_blank\" rel=\"noopener\"><span style=\"color:#ffffff;\">Book a platform walkthrough<\/span><\/a>\n  <p style=\"color:#b3b8d8;font-family:'Inter',-apple-system,sans-serif;font-size:13px;margin:14px 0 0;\">HIPAA plus 200+ frameworks &middot; Evidence from live controls &middot; One platform, everything<\/p>\n<\/div>\n\n\n<h2 id=\"faq\">Frequently asked questions<\/h2>\n\n<details>\n  <summary>What is protected health information?<\/summary>\n  <p>Individually identifiable health information created, received, stored or transmitted by a HIPAA covered entity or business associate. It must both relate to health, care or payment, and be linkable to a specific person.<\/p>\n<\/details>\n\n<details>\n  <summary>What are the 18 HIPAA identifiers?<\/summary>\n  <p>Eighteen categories including name, address below state level, all dates tied to an individual, telephone, email, social security number, medical record number, account number, IP address, device serial numbers, biometrics and full-face photographs.<\/p>\n<\/details>\n\n<details>\n  <summary>Is an email address PHI?<\/summary>\n  <p>On its own, no. An email address held by a covered entity alongside health information, such as an appointment confirmation, is PHI because it links a person to their care.<\/p>\n<\/details>\n\n<details>\n  <summary>Is health data in a consumer app PHI?<\/summary>\n  <p>Usually not. HIPAA applies to covered entities and their business associates. A direct-to-consumer wellness app collecting data itself is generally outside HIPAA, though other privacy laws still apply.<\/p>\n<\/details>\n\n<details>\n  <summary>What is the difference between PHI and ePHI?<\/summary>\n  <p><a href=\"https:\/\/www.osto.one\/resources\/glossary\/ephi\/\">ePHI<\/a> is the subset of PHI held or transmitted electronically. PHI on paper or spoken aloud is covered by the Privacy Rule; only ePHI triggers the Security Rule.<\/p>\n<\/details>\n\n<p class=\"related\"><strong>Related glossary terms:<\/strong> ePHI &middot; HIPAA Privacy Rule &middot; HIPAA Security Rule &middot; Covered Entity &middot; Business Associate &middot; Minimum Necessary Standard<\/p>\n\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Protected health information is any health information that can be tied back to a specific person and is held by\u2026<\/p>\n","protected":false},"author":8,"featured_media":824,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[180],"tags":[323,322],"class_list":["post-823","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-glossary","tag-phi","tag-protected-health-information"],"_links":{"self":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/823","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/comments?post=823"}],"version-history":[{"count":1,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/823\/revisions"}],"predecessor-version":[{"id":825,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/823\/revisions\/825"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media\/824"}],"wp:attachment":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media?parent=823"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/categories?post=823"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/tags?post=823"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}