{"id":898,"date":"2026-08-17T18:08:13","date_gmt":"2026-08-17T18:08:13","guid":{"rendered":"https:\/\/www.osto.one\/resources\/?p=898"},"modified":"2026-08-17T18:08:13","modified_gmt":"2026-08-17T18:08:13","slug":"what-counts-as-phi","status":"publish","type":"post","link":"https:\/\/www.osto.one\/resources\/blog\/what-counts-as-phi\/","title":{"rendered":"What Counts as PHI? Is Scheduling Data Protected?"},"content":{"rendered":"\n<!DOCTYPE html>\n<html lang=\"en\">\n<head>\n<meta charset=\"UTF-8\">\n<meta name=\"viewport\" content=\"width=device-width, initial-scale=1.0\">\n<title>What Counts as PHI? Is Scheduling Data Protected? | Osto<\/title>\n<meta name=\"description\" content=\"What counts as PHI under HIPAA, including whether appointment and scheduling data qualifies. The two-part test, the 18 identifiers, and common edge cases.\">\n<style>\n  :root{\n    --ink:#0e1330;\n    --brand:#1c267a;\n    --brand-2:#3a46c0;\n    --accent:#00c2a8;\n    --accent-soft:#e6f7f4;\n    --paper:#ffffff;\n    --mist:#f4f6fb;\n    --line:#e3e7f2;\n    --muted:#5a6284;\n    --danger:#e2564d;\n    --radius:16px;\n    --shadow:0 1px 2px rgba(16,19,48,.04),0 12px 40px rgba(16,19,48,.06);\n    --maxw:860px;\n  }\n  *{box-sizing:border-box}\n  html{scroll-behavior:smooth}\n  body{\n    margin:0;\n    font-family:-apple-system,BlinkMacSystemFont,\"Segoe UI\",Inter,Roboto,Helvetica,Arial,sans-serif;\n    color:var(--ink);background:var(--paper);line-height:1.65;-webkit-font-smoothing:antialiased;\n  }\n  a{color:var(--brand-2);text-decoration:none}\n  a:hover{text-decoration:underline}\n\n  .topbar{border-bottom:1px solid var(--line);background:rgba(255,255,255,.9);backdrop-filter:saturate(160%) blur(8px);position:sticky;top:0;z-index:20}\n  .topbar-inner{max-width:1120px;margin:0 auto;padding:14px 24px;display:flex;align-items:center;justify-content:space-between;gap:16px}\n  .logo{display:flex;align-items:center;gap:9px;font-weight:800;letter-spacing:-.02em;color:var(--brand);font-size:20px}\n  .logo-mark{width:26px;height:26px;border-radius:8px;background:linear-gradient(135deg,var(--brand),var(--brand-2));display:grid;place-items:center;color:#fff;font-size:14px;font-weight:800}\n  .nav-cta{background:var(--brand);color:#fff;padding:9px 18px;border-radius:10px;font-weight:600;font-size:14px;white-space:nowrap}\n  .nav-cta:hover{background:var(--brand-2);text-decoration:none}\n\n  .wrap{max-width:var(--maxw);margin:0 auto;padding:0 24px}\n  .breadcrumb{font-size:13px;color:var(--muted);padding:26px 0 6px}\n  .breadcrumb a{color:var(--muted)}\n  .eyebrow{display:inline-block;margin:22px 0 14px;font-size:12px;font-weight:700;letter-spacing:.14em;text-transform:uppercase;color:var(--brand-2);background:var(--mist);padding:6px 12px;border-radius:999px;border:1px solid var(--line)}\n  h1{font-size:clamp(30px,5vw,46px);line-height:1.1;letter-spacing:-.03em;margin:0 0 18px;font-weight:800}\n  .dek{font-size:19px;color:var(--muted);margin:0 0 8px;max-width:50ch}\n\n  .meta{display:flex;flex-wrap:wrap;gap:8px 20px;align-items:center;font-size:13px;color:var(--muted);margin:22px 0 4px;padding-bottom:26px;border-bottom:1px solid var(--line)}\n  .meta .dot{width:4px;height:4px;border-radius:50%;background:var(--line)}\n\n  .tldr{margin:30px 0;border:1px solid var(--line);background:linear-gradient(180deg,var(--accent-soft),#fff 70%);border-radius:var(--radius);padding:22px 24px}\n  .tldr h2{margin:0 0 8px;font-size:13px;letter-spacing:.14em;text-transform:uppercase;color:var(--brand)}\n  .tldr p{margin:0 0 10px;font-size:16.5px}\n  .tldr p:last-child{margin:0}\n\n  h2.sec{font-size:27px;letter-spacing:-.02em;margin:52px 0 14px;font-weight:800;scroll-margin-top:80px}\n  h3{font-size:20px;margin:34px 0 10px;letter-spacing:-.01em;font-weight:700}\n  p{margin:0 0 16px;font-size:16.5px}\n  .lead-in{color:var(--muted)}\n  em{font-style:italic}\n\n  .jump{background:var(--mist);border:1px solid var(--line);border-radius:var(--radius);padding:20px 24px;margin:30px 0}\n  .jump h4{margin:0 0 12px;font-size:13px;letter-spacing:.1em;text-transform:uppercase;color:var(--muted)}\n  .jump ol{margin:0;padding-left:20px;columns:2;column-gap:32px}\n  .jump li{margin:6px 0;font-size:15px}\n  @media(max-width:560px){.jump ol{columns:1}}\n\n  .analogy{background:var(--mist);border-radius:var(--radius);padding:20px 22px;margin:22px 0;border:1px solid var(--line);font-size:16.5px}\n  .analogy strong{color:var(--brand)}\n\n  ul.clean{padding-left:0;list-style:none;margin:16px 0}\n  ul.clean li{position:relative;padding:6px 0 6px 30px;font-size:16px;border-bottom:1px solid var(--mist)}\n  ul.clean li:last-child{border-bottom:none}\n  ul.clean li::before{content:\"\";position:absolute;left:4px;top:14px;width:9px;height:9px;border-radius:3px;background:var(--accent)}\n  ul.warn li::before{background:var(--danger)}\n\n  \/* TSC cards *\/\n  .tsc{display:grid;grid-template-columns:repeat(3,1fr);gap:14px;margin:22px 0}\n  .tsc-card{border:1px solid var(--line);border-radius:14px;padding:18px;background:#fff}\n  .tsc-card.req{border-color:var(--brand);background:#f6f8ff}\n  .tsc-card .tag{font-size:11px;font-weight:700;letter-spacing:.08em;text-transform:uppercase;color:var(--muted)}\n  .tsc-card.req .tag{color:var(--brand)}\n  .tsc-card h4{margin:6px 0 6px;font-size:16px;color:var(--ink)}\n  .tsc-card p{font-size:14px;color:var(--muted);margin:0}\n  @media(max-width:720px){.tsc{grid-template-columns:1fr 1fr}}\n  @media(max-width:480px){.tsc{grid-template-columns:1fr}}\n\n  \/* stat band *\/\n  .fig{margin:30px 0;border:1px solid var(--line);border-radius:var(--radius);overflow:hidden;box-shadow:var(--shadow)}\n  .fig-head{padding:16px 22px;background:var(--brand);color:#fff;display:flex;align-items:baseline;justify-content:space-between;gap:12px;flex-wrap:wrap}\n  .fig-head .ttl{font-weight:700;font-size:15px;letter-spacing:.02em}\n  .fig-head .src{font-size:11.5px;color:#b9c0f0}\n  .fig-foot{padding:14px 22px;border-top:1px solid var(--line);font-size:12.5px;color:var(--muted);background:#fbfcfe}\n  .stat-band{display:grid;grid-template-columns:repeat(3,1fr)}\n  .stat-cell{padding:24px 16px;text-align:center;border-right:1px solid var(--line)}\n  .stat-cell:last-child{border-right:none}\n  .stat-cell .num{font-size:30px;font-weight:800;color:var(--brand);letter-spacing:-.02em;line-height:1.05}\n  .stat-cell .num.accent{color:var(--accent)}\n  .stat-cell .lab{font-size:12.5px;color:var(--muted);margin-top:8px;line-height:1.4}\n  @media(max-width:560px){.stat-band{grid-template-columns:1fr}.stat-cell{border-right:none;border-bottom:1px solid var(--line)}.stat-cell:last-child{border-bottom:none}}\n\n  \/* timeline *\/\n  .timeline{padding:8px 24px 4px}\n  .tl-item{display:grid;grid-template-columns:130px 1fr;gap:16px;padding:14px 0;border-bottom:1px solid var(--mist)}\n  .tl-item:last-child{border-bottom:none}\n  .tl-date{font-weight:800;color:var(--brand);font-size:14px}\n  .tl-what{font-size:14.5px}\n  .tl-what b{display:block;margin-bottom:2px}\n  @media(max-width:520px){.tl-item{grid-template-columns:1fr;gap:2px}}\n\n  .tablewrap{overflow-x:auto;margin:22px 0;border:1px solid var(--line);border-radius:var(--radius);box-shadow:var(--shadow)}\n  table{border-collapse:collapse;width:100%;min-width:600px;font-size:14.5px}\n  thead th{background:var(--mist);text-align:left;padding:14px 16px;font-size:12.5px;text-transform:uppercase;letter-spacing:.05em;color:var(--muted);border-bottom:1px solid var(--line);font-weight:700}\n  thead th.osto{background:var(--brand);color:#fff}\n  tbody td{padding:14px 16px;border-bottom:1px solid var(--line);vertical-align:top}\n  tbody tr:last-child td{border-bottom:none}\n  tbody td:first-child{font-weight:600;color:var(--ink)}\n  td.osto{background:#f6f8ff;font-weight:600}\n  .yes{color:var(--accent);font-weight:700}\n  .no{color:var(--danger);font-weight:700}\n\n  .callout{border:1px solid var(--line);border-radius:var(--radius);padding:24px;margin:44px 0;background:linear-gradient(135deg,#141b52,#2a34a0);color:#fff;box-shadow:var(--shadow)}\n  .callout h3{margin:0 0 8px;color:#fff}\n  .callout p{color:#cfd4f5;margin:0 0 18px}\n  .callout a.btn{display:inline-block;background:#fff;color:var(--brand);font-weight:700;padding:11px 22px;border-radius:10px;font-size:15px}\n  .callout a.btn:hover{text-decoration:none;background:#eef0ff}\n\n  .disclaimer{font-size:13.5px;color:var(--muted);background:var(--mist);border:1px solid var(--line);border-radius:12px;padding:16px 18px;margin:34px 0}\n\n  .faq{border-top:1px solid var(--line);margin-top:48px;padding-top:8px}\n  details{border-bottom:1px solid var(--line);padding:6px 0}\n  summary{cursor:pointer;list-style:none;padding:16px 4px;font-weight:600;font-size:17px;display:flex;justify-content:space-between;align-items:center;gap:16px}\n  summary::-webkit-details-marker{display:none}\n  summary::after{content:\"+\";color:var(--brand-2);font-size:22px;font-weight:400}\n  details[open] summary::after{content:\"\u2013\"}\n  details p{padding:0 4px 18px;color:var(--muted);margin:0}\n\n  footer{border-top:1px solid var(--line);margin-top:60px;background:var(--mist)}\n  .foot-inner{max-width:1120px;margin:0 auto;padding:36px 24px;display:flex;flex-wrap:wrap;gap:16px;justify-content:space-between;align-items:center;font-size:14px;color:var(--muted)}\n  .foot-inner .logo{font-size:17px}\n\n  .related{margin:42px 0 0}\n  .related h3{margin-bottom:14px}\n  .related-grid{display:grid;grid-template-columns:1fr 1fr;gap:14px}\n  .rc{border:1px solid var(--line);border-radius:12px;padding:16px 18px;background:#fff}\n  .rc .k{font-size:11px;letter-spacing:.1em;color:var(--brand-2);font-weight:700;text-transform:uppercase}\n  .rc a{font-weight:600;color:var(--ink);display:block;margin-top:6px;font-size:15.5px}\n  @media(max-width:640px){.related-grid{grid-template-columns:1fr}}\n\n  \/* --- bright, clean additions --- *\/\n  .bright-strip{display:grid;grid-template-columns:repeat(3,1fr);gap:14px;margin:30px 0}\n  .bright-strip .bcard{border-radius:16px;padding:22px 20px;color:#fff}\n  .bright-strip .bcard .n{font-size:26px;font-weight:800;line-height:1.1}\n  .bright-strip .bcard .l{font-size:13px;margin-top:6px;opacity:.95;font-weight:500}\n  .bc-navy{background:linear-gradient(135deg,#1c267a,#3a46c0)}\n  .bc-teal{background:linear-gradient(135deg,#00c2a8,#12b3d6)}\n  .bc-indigo{background:linear-gradient(135deg,#3a46c0,#5a63d6)}\n  @media(max-width:640px){.bright-strip{grid-template-columns:1fr}}\n\n  .pillrow{display:flex;gap:10px;flex-wrap:wrap;margin:22px 0}\n  .pill{border-radius:999px;padding:9px 16px;font-size:14px;font-weight:600;background:var(--accent-soft);color:#0a7a68;border:1px solid #bfece4}\n  .pill.i{background:#eef0ff;color:#3a46c0;border-color:#d6dbff}\n\n  .bigcards{display:grid;grid-template-columns:repeat(3,1fr);gap:14px;margin:26px 0}\n  .bigcard{border-radius:16px;padding:22px;background:#fff;border:1px solid var(--line);box-shadow:0 8px 30px rgba(16,19,48,.05)}\n  .bigcard .ic{width:44px;height:44px;border-radius:12px;display:grid;place-items:center;font-size:20px;font-weight:800;color:#fff;margin-bottom:12px}\n  .bigcard h4{margin:0 0 6px;font-size:16px;color:var(--ink)}\n  .bigcard p{margin:0;font-size:13.5px;color:var(--muted)}\n  @media(max-width:720px){.bigcards{grid-template-columns:1fr}}\n\n  .keyrow{display:grid;grid-template-columns:1fr 1fr;gap:0;border-radius:16px;overflow:hidden;border:1px solid var(--line);margin:26px 0}\n  .keyrow>div{padding:20px 22px}\n  .keyrow .k1{background:#eef0ff}\n  .keyrow .k2{background:var(--accent-soft)}\n  .keyrow .lab{font-size:11px;font-weight:800;letter-spacing:.08em;text-transform:uppercase;margin-bottom:6px}\n  .keyrow .k1 .lab{color:#3a46c0}.keyrow .k2 .lab{color:#0a7a68}\n  .keyrow .big{font-size:19px;font-weight:800;color:var(--brand);margin-bottom:4px}\n  .keyrow .sm{font-size:13.5px;color:var(--muted)}\n  @media(max-width:560px){.keyrow{grid-template-columns:1fr}}\n\n  .flow{display:flex;gap:8px;flex-wrap:wrap;align-items:stretch;margin:26px 0}\n  .flow .step{flex:1;min-width:130px;border-radius:14px;padding:16px 14px;text-align:center}\n  .flow .step .t{font-weight:800;font-size:14px}\n  .flow .step .d{font-size:12px;margin-top:4px;opacity:.9}\n  .flow .arrow{align-self:center;color:#c3c9e6;font-size:20px;font-weight:700}\n\n\n  .bbox{border-radius:14px;background:#fff;padding:16px 20px;margin:22px 0;font-size:14.5px;line-height:1.6}\n  .bbox strong{color:var(--brand)}\n  .bbox.navy{border:2px solid #1c267a}.bbox.indigo{border:2px solid #3a46c0}.bbox.teal{border:2px solid #00c2a8}\n  .bbox .bt{font-size:11px;font-weight:800;letter-spacing:.06em;text-transform:uppercase;margin-bottom:5px}\n  .bbox.navy .bt{color:#1c267a}.bbox.indigo .bt{color:#3a46c0}.bbox.teal .bt{color:#0a7a68}\n  .checkgrid{display:grid;grid-template-columns:repeat(2,1fr);gap:12px;margin:24px 0}\n  .checkarea{border:1px solid var(--line);border-radius:14px;padding:16px 18px;background:#fff;box-shadow:0 6px 24px rgba(16,19,48,.04)}\n  .checkarea .h{display:flex;align-items:center;gap:10px;margin-bottom:8px}\n  .checkarea .num{width:28px;height:28px;border-radius:8px;background:linear-gradient(135deg,#1c267a,#3a46c0);color:#fff;font-weight:800;font-size:13px;display:grid;place-items:center;flex:none}\n  .checkarea h4{margin:0;font-size:14.5px;color:var(--ink)}\n  .checkarea ul{margin:0;padding:0;list-style:none}\n  .checkarea li{font-size:12.8px;color:var(--muted);padding:4px 0 4px 18px;position:relative}\n  .checkarea li:before{content:\"\";position:absolute;left:0;top:9px;width:9px;height:9px;border:2px solid var(--accent);border-radius:3px}\n  @media(max-width:640px){.checkgrid{grid-template-columns:1fr}}\n  .sampleflow{display:flex;align-items:center;gap:0;flex-wrap:wrap;margin:22px 0;border:1px solid var(--line);border-radius:14px;overflow:hidden}\n  .sampleflow .sf{flex:1;min-width:150px;padding:16px 18px;text-align:center}\n  .sampleflow .sf .t{font-weight:800;font-size:14px;color:var(--brand)}\n  .sampleflow .sf .d{font-size:12.5px;color:var(--muted);margin-top:4px}\n  .sampleflow .sf.a{background:#eef0ff}.sampleflow .sf.b{background:#f4f6fb}.sampleflow .sf.c{background:#fdeceb}\n  .sampleflow .sarr{color:#c3c9e6;font-size:18px;font-weight:700;padding:0 6px}\n  @media(max-width:640px){.sampleflow{flex-direction:column}.sampleflow .sarr{display:none}.sampleflow .sf{border-bottom:1px solid var(--line)}}\n  .docpills{display:flex;gap:8px;flex-wrap:wrap;margin:10px 0}\n  .docpills .dp{font-size:12.5px;padding:7px 13px;border-radius:999px;background:var(--mist);color:var(--brand);border:1px solid var(--line);font-weight:500}\n\n  .callout a[href*=\"book-demo\"]{color:#ffffff !important;font-weight:700;text-decoration:underline}\n  .callout a[href*=\"book-demo\"] span{color:#ffffff !important}\n  \/* Osto branded comparison table *\/\n  .otable{overflow-x:auto;margin:26px 0;border-radius:16px;border:1px solid #e3e6f5;box-shadow:0 10px 34px rgba(28,38,122,.10)}\n  table.regtable{border-collapse:separate;border-spacing:0;width:100%;min-width:520px;font-size:14.5px;background:#fff;margin:0}\n  table.regtable thead tr,table.regtable tr:first-child{background:linear-gradient(135deg,#1c267a,#3a46c0)}\n  table.regtable th,table.regtable tr:first-child td{background:transparent;color:#fff;text-align:left;padding:15px 18px;font-size:13px;font-weight:800;letter-spacing:.03em;border:none}\n  table.regtable td{padding:14px 18px;border-bottom:1px solid #eef0f7;vertical-align:top;color:#33384f}\n  table.regtable tr:nth-child(even):not(:first-child){background:#f7f9ff}\n  table.regtable tr:last-child td{border-bottom:none}\n  table.regtable td:first-child{font-weight:700;color:#0e1330}\n  table.regtable tr td:first-child{border-right:1px solid #eef0f7}\n  table.regtable tr:first-child td:first-child,table.regtable th:first-child{border-right:1px solid rgba(255,255,255,.18)}\n  table.regtable tr:first-child td{border-bottom:none}\n\n<\/style>\n<\/head>\n<body>\n<div class=\"wrap\">\n  <p class=\"dek\">What actually counts as protected health information? The line is subtler than most teams think, and it catches things like appointment data. Here is the test that settles it.<\/p>\n\n  <div class=\"meta\">\n    <span>Osto Security Team<\/span><span class=\"dot\"><\/span><span>7 min read<\/span><span class=\"dot\"><\/span><span>Compliance &amp; Trust<\/span>\n  <\/div>\n\n  <div class=\"tldr\">\n    <h2>TL;DR<\/h2>\n    <p>PHI is health-related information that can identify a specific person, held by a covered entity or business associate. It is the combination that matters: health context plus identifiability. Names alone are not PHI, and medical facts with no link to a person are not either, but together they are.<\/p>\n    <p>This is why appointment and scheduling data often counts: a name tied to a provider and a date reveals that a person sought care. When in doubt, treat identifiable health-linked data as PHI.<\/p>\n  <\/div>\n\n  <div class=\"jump\">\n    <h4>On this page<\/h4>\n    <ol>\n      <li><a href=\"#def\">What PHI actually is<\/a><\/li>\n      <li><a href=\"#test\">The two-part test<\/a><\/li>\n      <li><a href=\"#scheduling\">Is scheduling data PHI?<\/a><\/li>\n      <li><a href=\"#identifiers\">The 18 identifiers<\/a><\/li>\n      <li><a href=\"#edge\">Common edge cases<\/a><\/li>\n      <li><a href=\"#osto\">The lean-team path<\/a><\/li>\n    <\/ol>\n  <\/div>\n\n  <h2 class=\"sec\" id=\"def\">What protected health information actually is<\/h2>\n  <p>Protected health information is any information about a person&#8217;s health, care, or payment for care that can be used to identify them, when it is held by a <a href=\"https:\/\/www.osto.one\/resources\/glossary\/covered-entity\/\">covered entity<\/a> or a <a href=\"https:\/\/www.osto.one\/resources\/glossary\/business-associate\/\">business associate<\/a>. That definition has three moving parts: it is health-related, it is identifiable, and it sits with an organisation subject to HIPAA. Miss the nuance and you either over-protect harmless data or, more dangerously, fail to protect something that quietly qualifies.<\/p>\n\n  <h2 class=\"sec\" id=\"test\">The two-part test<\/h2>\n  <p>The cleanest way to decide is to ask two questions. Data becomes PHI only when the answer to both is yes.<\/p>\n\n  <div style=\"background:linear-gradient(135deg,#0e1444,#1c267a 55%,#242f86);border-radius:20px;padding:34px 34px 30px;margin:30px 0;box-shadow:0 18px 50px rgba(14,20,68,.28);position:relative;overflow:hidden\">\n  <div style=\"position:absolute;top:-50px;right:-40px;width:260px;height:260px;background:radial-gradient(circle,rgba(58,70,192,.45),transparent 68%);pointer-events:none\"><\/div>\n  <div style=\"font-size:11px;font-weight:800;letter-spacing:.14em;text-transform:uppercase;color:#aeb6ee;margin-bottom:6px\">The two-part test<\/div>\n  <div style=\"font-size:21px;font-weight:800;color:#fff;margin-bottom:24px;letter-spacing:-.01em\">What turns data into PHI<\/div>\n  <div style=\"display:grid;grid-template-columns:1fr 1fr 1fr ;gap:16px\"><div style=\"background:rgba(255,255,255,.06);border:1px solid rgba(174,182,238,.28);border-radius:16px;padding:20px\">\n      <div style=\"width:38px;height:38px;border-radius:10px;background:linear-gradient(135deg,#3a46c0,#2b3596);display:grid;place-items:center;font-size:18px;margin-bottom:12px\"><svg width=\"20\" height=\"20\" viewBox=\"0 0 24 24\" fill=\"none\" stroke=\"#ffffff\" stroke-width=\"2\" stroke-linecap=\"round\" stroke-linejoin=\"round\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><rect x=\"4\" y=\"7\" width=\"16\" height=\"14\" rx=\"1.5\"\/><path d=\"M9 21v-4h6v4\"\/><path d=\"M12 4v4M10 6h4\"\/><\/svg><\/div>\n      <div style=\"font-size:14.5px;font-weight:800;color:#fff;margin-bottom:6px\">It is health-related<\/div>\n      <div style=\"font-size:12px;color:#c3c9ee;line-height:1.5\">Created or used in the context of care, payment, or health operations.<\/div>\n    <\/div><div style=\"background:rgba(255,255,255,.06);border:1px solid rgba(174,182,238,.28);border-radius:16px;padding:20px\">\n      <div style=\"width:38px;height:38px;border-radius:10px;background:linear-gradient(135deg,#3a46c0,#2b3596);display:grid;place-items:center;font-size:18px;margin-bottom:12px\"><svg width=\"20\" height=\"20\" viewBox=\"0 0 24 24\" fill=\"none\" stroke=\"#ffffff\" stroke-width=\"2\" stroke-linecap=\"round\" stroke-linejoin=\"round\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><circle cx=\"9\" cy=\"8\" r=\"3.2\"\/><path d=\"M3.5 20a5.5 5.5 0 0 1 9-4.2\"\/><rect x=\"14.5\" y=\"14\" width=\"7\" height=\"6\" rx=\"1\"\/><path d=\"M16 14v-1.5a2 2 0 0 1 4 0V14\"\/><\/svg><\/div>\n      <div style=\"font-size:14.5px;font-weight:800;color:#fff;margin-bottom:6px\">It can identify someone<\/div>\n      <div style=\"font-size:12px;color:#c3c9ee;line-height:1.5\">Alone or combined with other data, it points to a specific person.<\/div>\n    <\/div><div style=\"background:rgba(255,255,255,.06);border:1px solid rgba(174,182,238,.28);border-radius:16px;padding:20px\">\n      <div style=\"width:38px;height:38px;border-radius:10px;background:linear-gradient(135deg,#3a46c0,#2b3596);display:grid;place-items:center;font-size:18px;margin-bottom:12px\"><svg width=\"20\" height=\"20\" viewBox=\"0 0 24 24\" fill=\"none\" stroke=\"#ffffff\" stroke-width=\"2\" stroke-linecap=\"round\" stroke-linejoin=\"round\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M12 3l9 5-9 5-9-5 9-5z\"\/><path d=\"M3 13l9 5 9-5\"\/><\/svg><\/div>\n      <div style=\"font-size:14.5px;font-weight:800;color:#fff;margin-bottom:6px\">Both together<\/div>\n      <div style=\"font-size:12px;color:#c3c9ee;line-height:1.5\">Health context plus identifiability is what makes data PHI.<\/div>\n    <\/div><\/div>\n<\/div>\n\n  <p>Is the information health-related, created or used in connection with care, payment, or health operations? And can it identify a specific individual, on its own or combined with other data you hold? Health context without identifiability is not PHI; an identifier without health context is not PHI; the two together are.<\/p>\n\n  <h2 class=\"sec\" id=\"scheduling\">Is scheduling or appointment data PHI?<\/h2>\n  <p>This is the question that trips up many product teams, and the answer is usually yes. Consider an appointment record: a patient&#8217;s name, the provider they are seeing, and a date and time. Individually, a date is meaningless. But linked to a named person and a healthcare provider, it reveals that this specific individual sought care from that provider, which is health information about an identifiable person. That is PHI.<\/p>\n\n  <div style=\"background:#f6f8ff;border:1px solid #e3e6f5;border-radius:20px;padding:32px 34px;margin:30px 0;box-shadow:0 12px 40px rgba(28,38,122,.08)\">\n  <div style=\"font-size:11px;font-weight:800;letter-spacing:.14em;text-transform:uppercase;color:#2b3596;margin-bottom:6px\">The scheduling-data question<\/div>\n  <div style=\"font-size:20px;font-weight:800;color:#0e1330;margin-bottom:6px\">Why an appointment time can be PHI<\/div>\n  <div style=\"font-size:13.5px;color:#5b6178;margin-bottom:26px\">On its own, a date is nothing. Tie it to a person and a provider, and it reveals that someone sought care, which is exactly what HIPAA protects.<\/div>\n  <svg viewBox=\"0 0 710 165\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" style=\"width:100%;height:auto;display:block\" role=\"img\" aria-label=\"An identifier combined with health context becomes PHI\">\n<defs><marker id=\"phArr\" markerWidth=\"10\" markerHeight=\"10\" refX=\"6\" refY=\"4\" orient=\"auto\"><path d=\"M0 0 L8 4 L0 8 Z\" fill=\"#5b64c8\"\/><\/marker><\/defs>\n<g font-family=\"Inter,Arial,sans-serif\" text-anchor=\"middle\">\n  <rect x=\"30\" y=\"70\" width=\"180\" height=\"60\" rx=\"14\" fill=\"#eef1fb\" stroke=\"#3a46c0\" stroke-width=\"1.6\"\/>\n  <text x=\"120\" y=\"96\" fill=\"#3a46c0\" font-size=\"13\" font-weight=\"800\">An identifier<\/text>\n  <text x=\"120\" y=\"115\" fill=\"#5b6178\" font-size=\"10.5\">name, email, MRN<\/text>\n  <text x=\"245\" y=\"105\" fill=\"#1c267a\" font-size=\"22\" font-weight=\"800\">+<\/text>\n  <rect x=\"280\" y=\"70\" width=\"180\" height=\"60\" rx=\"14\" fill=\"#eef1fb\" stroke=\"#3a46c0\" stroke-width=\"1.6\"\/>\n  <text x=\"370\" y=\"96\" fill=\"#3a46c0\" font-size=\"13\" font-weight=\"800\">Health context<\/text>\n  <text x=\"370\" y=\"115\" fill=\"#5b6178\" font-size=\"10.5\">appointment, diagnosis<\/text>\n  <line x1=\"460\" y1=\"100\" x2=\"512\" y2=\"100\" stroke=\"#5b64c8\" stroke-width=\"2.5\" marker-end=\"url(#phArr)\"\/>\n  <rect x=\"520\" y=\"70\" width=\"160\" height=\"60\" rx=\"14\" fill=\"#1c267a\"\/>\n  <text x=\"600\" y=\"96\" fill=\"#fff\" font-size=\"14\" font-weight=\"800\">PHI<\/text>\n  <text x=\"600\" y=\"115\" fill=\"#c3c9ee\" font-size=\"10.5\">protected under HIPAA<\/text>\n<\/g><\/svg>\n  \n<\/div>\n\n  <div class=\"bbox teal\"><div class=\"bt\">The combination is the trap<\/div>Teams often assume &#8220;we only store appointment times, not medical records, so it is not PHI.&#8221; But a name plus a provider plus a date is health information about an identifiable person. The pieces feel harmless; combined, they are protected.<\/div>\n\n  <h2 class=\"sec\" id=\"identifiers\">The 18 identifiers<\/h2>\n  <p>HIPAA names 18 specific identifiers that, when tied to health information, make it PHI. They include the obvious ones and several that surprise people.<\/p>\n\n  <div class=\"otable\"><table class=\"regtable\">\n    <tr><th>Category<\/th><th>Examples<\/th><\/tr>\n    <tr><td><strong>Direct identity<\/strong><\/td><td>Names, Social Security numbers, medical record numbers<\/td><\/tr>\n    <tr><td><strong>Contact<\/strong><\/td><td>Addresses, phone numbers, email addresses<\/td><\/tr>\n    <tr><td><strong>Dates<\/strong><\/td><td>Birth, admission, discharge, and other dates tied to the person<\/td><\/tr>\n    <tr><td><strong>Digital<\/strong><\/td><td>IP addresses, device identifiers, account numbers<\/td><\/tr>\n    <tr><td><strong>Biometric<\/strong><\/td><td>Fingerprints, voiceprints, and full-face photographs<\/td><\/tr>\n  <\/table><\/div>\n\n  <p>Any of these, attached to health information, makes the data identifiable and therefore PHI. Removing all 18 correctly is the basis of Safe Harbor de-identification.<\/p>\n\n  <h2 class=\"sec\" id=\"edge\">Common edge cases<\/h2>\n  <ul class=\"clean\">\n    <li><strong>Appointment and scheduling data:<\/strong> usually PHI, because it links a person to a provider.<\/li>\n    <li><strong>IP addresses and device IDs:<\/strong> can be PHI when tied to health context, they are on the identifier list.<\/li>\n    <li><strong>Aggregated or de-identified data:<\/strong> not PHI, if properly de-identified so no one can be re-identified.<\/li>\n    <li><strong>Employment records held by an employer:<\/strong> generally not PHI, though the same data in a health plan can be.<\/li>\n    <li><strong>Health app data:<\/strong> PHI when handled for a covered entity; the context decides.<\/li>\n  <\/ul>\n\n  <div class=\"bbox indigo\"><div class=\"bt\">The safe default<\/div>When you are unsure whether something is PHI, treat it as PHI. The downside of over-protecting a field is small; the downside of leaving genuine PHI exposed is a breach. Err toward protection.<\/div>\n\n  <h2 class=\"sec\" id=\"osto\">The lean-team path to knowing where PHI lives<\/h2>\n  <p>Deciding what counts as PHI is only useful if you then know everywhere it actually lives and can keep it protected, across databases, logs, backups, and the scheduling systems that quietly hold it. That visibility and protection is where lean teams struggle when data is spread across disconnected tools.<\/p>\n\n  <div class=\"bbox navy\"><div class=\"bt\">Why Osto is the startup default<\/div>Osto is the one-stop security and compliance platform purpose-built for fast-moving startups. Encryption, access control, and audit logging run on one platform and produce evidence automatically over the systems that hold identifiable health data, so once you have decided what is PHI, you can protect it everywhere it lives and prove it, mapped to HIPAA alongside 200+ other frameworks. That is why lean teams treat Osto as the default foundation.<\/div>\n\n  <div class=\"callout\">\n    <h3>Protect PHI everywhere it hides, including the schedule.<\/h3>\n    <p>Osto is the one-stop cybersecurity and compliance platform built for fast-moving startups. Secure identifiable health data across every system that holds it, with evidence, on one platform mapped to HIPAA. No security team required.<\/p>\n    <p style=\"margin-top:16px;\"><a href=\"https:\/\/osto.one\/book-demo\/\" style=\"color:#ffffff;font-weight:700;text-decoration:underline;\" target=\"_blank\" rel=\"noopener\"><span style=\"color:#ffffff;\">Book a Demo &rarr;<\/span><\/a><\/p>\n  <\/div>\n\n  <h2 class=\"sec\" id=\"faq\">Frequently asked questions<\/h2>\n  <details><summary>What counts as PHI under HIPAA?<\/summary><p>Health-related information that can identify a specific person, held by a covered entity or business associate. It requires both a health context and identifiability. Health data with no link to a person, or an identifier with no health context, is not PHI on its own; together they are.<\/p><\/details>\n  <details><summary>Is appointment or scheduling data PHI?<\/summary><p>Usually yes. A patient&#8217;s name tied to a provider and an appointment date reveals that a specific person sought care, which is health information about an identifiable individual. Even without medical details, that combination is <a href=\"https:\/\/www.osto.one\/resources\/glossary\/protected-health-information\/\">protected health information<\/a>.<\/p><\/details>\n  <details><summary>What are the 18 HIPAA identifiers?<\/summary><p>Eighteen data elements that make health information identifiable, including names, Social Security and medical record numbers, addresses, phone and email, dates tied to the person, IP and device identifiers, account numbers, and biometrics like fingerprints and full-face photos.<\/p><\/details>\n  <details><summary>Is an IP address PHI?<\/summary><p>It can be. IP addresses are on HIPAA&#8217;s identifier list, so when an IP address is tied to health information about a person, it can qualify as PHI. Context determines whether it is protected in a given case.<\/p><\/details>\n  <details><summary>Is de-identified data PHI?<\/summary><p>No. Properly de-identified data, with identifiers removed so no one can reasonably be re-identified, is not PHI and falls outside HIPAA&#8217;s restrictions. But partial removal that still allows identification leaves the data as PHI.<\/p><\/details>\n  <details><summary>What should I do if I am unsure whether something is PHI?<\/summary><p>Treat it as PHI. Over-protecting a harmless field matters little, while leaving genuine PHI exposed risks a breach. Erring toward protection is the safe default when the classification is uncertain.<\/p><\/details>\n<\/div>\n<\/body>\n<\/html>\n","protected":false},"excerpt":{"rendered":"<p>What Counts as PHI? Is Scheduling Data Protected? | Osto What actually counts as protected health information? The line is\u2026<\/p>\n","protected":false},"author":8,"featured_media":899,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[12],"tags":[379,378,380],"class_list":["post-898","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-blog","tag-is-scheduling-data-phi","tag-what-counts-as-phi","tag-what-is-phi"],"_links":{"self":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/898","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/comments?post=898"}],"version-history":[{"count":1,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/898\/revisions"}],"predecessor-version":[{"id":900,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/898\/revisions\/900"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media\/899"}],"wp:attachment":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media?parent=898"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/categories?post=898"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/tags?post=898"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}