

PHI vs PII: Classify Data Before It Becomes a HIPAA Breach
PHI is PII that touches health, care, or payment information and is handled by a HIPAA covered entity or business associate. When that context is missing, the same data point is just PII, governed by state breach laws and general privacy standards rather than HIPAA. Get this classification wrong and you either overspend protecting harmless data or underspend on the records that trigger federal breach notification duties and penalties.
TL;DR:
- Properly classifying data as PHI or PII depends on who holds it and the context, not just the data fields themselves.
- HIPAA obligations apply only if the data is held by a covered entity or business associate touching health, care, or payment information.
- De-identification methods like Safe Harbor or Expert Determination are necessary to legally remove PHI but do not eliminate all re-identification risks.
- Encrypting electronic PHI with recognized standards provides a safe harbor against breach notification requirements.
- Small organizations often overlook the importance of accurate classification, risking non-compliance and enforcement penalties.
Table of Contents
Table of Contents
- PHI vs PII: What Each Term Actually Means
- PHI vs PII Examples: The Same Data, Two Different Rules
- When Does HIPAA Actually Apply?
- How Does De-Identification Change the Rules?
- Breach Rules: How PHI Incidents Differ From PII Incidents
- Is Your Data PHI or Just PII? A Practical Checklist
- What Happens Legally When PHI or PII Is Mishandled?
- Do GDPR and CCPA Apply When HIPAA Doesn’t?
- tekRESCUE’s Take: Classification Is Where Compliance Actually Breaks
- Get HIPAA Compliance Handled Before It Becomes a Breach Report
- Sources
- FAQ
PHI vs PII: What Each Term Actually Means
The federal government defines these two categories differently, and the gap between them is the whole story.
NIST SP 800-122 defines PII broadly as information that can distinguish or trace a person’s identity, either alone or when combined with other data. A name alone might not identify anyone uniquely, but a name paired with a birth date usually does. This is the federal standard most agencies and security teams already build controls around, and it covers everything from Social Security numbers to biometric records to IP addresses tied to a specific device.
HHS defines PHI more narrowly: individually identifiable health information created, held, or transmitted by a HIPAA covered entity or business associate, when it relates to a person’s health condition, health care, or payment for care. That last clause is doing the real work. HIPAA built an official list of 18 identifiers (names, dates tied to an individual, medical record numbers, and more) that flags data as PHI when it appears alongside health context in a covered entity’s records.
This is what’s known as the context rule, and it’s the single most misunderstood piece of this whole debate. The same phone number is plain PII sitting in a retail loyalty database and becomes PHI the moment it sits in a patient’s chart at a covered provider. The field doesn’t change. The setting does.
PHI vs PII Examples: The Same Data, Two Different Rules
Understanding PHI and PII in the abstract only gets you so far. Seeing the same data type land on both sides of the line makes the distinction click.
- A customer’s name in a retail CRM is PII. The same name attached to a diagnosis in a clinic’s electronic health record is PHI.
- An employee’s date of birth in an HR payroll system is PII. A patient’s date of birth combined with an admission date at a hospital is PHI, because dates related to an individual sit on HIPAA’s 18-identifier list.
- A full-face photograph on a company badge is PII. That same photo in a dermatology patient’s chart is PHI, since full-face images are explicitly named among the 18 identifiers.
- A bank account number on a mortgage application is PII. An account number tied to a payment for medical services, held by a provider or its billing vendor, is PHI.
- Public records, like a name in a county property filing, generally stay PII. They’re not created or held by a covered entity in a health context, even though they’re fully identifiable.
- Standard employer personnel files (performance reviews, salary history) are PII, not PHI, unless the employer is also acting as a group health plan administrator handling claims data.
Notice the pattern: it’s never the field itself that flips the classification. It’s who’s holding it and why.
When Does HIPAA Actually Apply?
HIPAA applies only to covered entities and business associates; organizations outside those two categories aren’t bound by the HIPAA Rules, even if they handle sensitive health-adjacent data. This scoping question matters more than almost anything else in this article, because it determines whether the rest of HIPAA’s machinery (BAAs, breach timelines, Safe Harbor) even switches on.
- Covered entities include health plans, health care providers who transmit claims electronically, and health care clearinghouses. A solo dental practice billing insurance qualifies. A wellness app that never bills insurance and isn’t run by a provider usually doesn’t.
- Business associates are vendors that create, receive, maintain, or transmit PHI on a covered entity’s behalf. Medical billing companies, cloud hosts storing electronic PHI, and analytics firms processing patient data all typically qualify.
- The activity test decides everything. It’s not about industry labels. It’s about whether the specific function performed touches PHI for a covered entity’s operations.
The practical consequence: covered entities need signed business associate agreements with every vendor that meets that definition, and business associates carry direct legal liability under HIPAA, not just contractual exposure. Skip the BAA, and you’ve created a compliance gap that regulators notice fast during a breach investigation.
How Does De-Identification Change the Rules?
Data stops being PHI under HIPAA once it’s properly de-identified, and HHS recognizes two paths to get there.
Safe Harbor requires removing all 18 specified identifiers (names, geographic subdivisions smaller than a state, dates tied to an individual, and so on) plus a “no actual knowledge” standard that the remaining information couldn’t identify someone. It’s the faster, more mechanical route, and most small organizations lean on it because it doesn’t require hiring a statistician.
Expert Determination takes a different path: a qualified statistician applies accepted methods to certify that re-identification risk is very small, using the data’s actual context rather than a fixed checklist. HHS guidance notes Safe Harbor is widely used but can strip more analytical value from a dataset than Expert Determination, which tends to fit high-utility research or analytics datasets better, though it costs more and demands documented methodology.

Here’s the catch worth remembering: de-identified data isn’t PHI anymore under HIPAA, but that doesn’t make it risk-free. Combine a “de-identified” dataset with an outside data source, and re-identification becomes possible again. De-identification removes a legal label. It doesn’t remove all practical risk.
Breach Rules: How PHI Incidents Differ From PII Incidents
A breach involving PHI triggers a specific federal machine that plain PII incidents don’t automatically engage.
HHS’s Breach Notification Rule requires covered entities to notify affected individuals following a breach of unsecured PHI generally within a reasonable time after discovery. Breaches affecting many individuals must also be reported to the HHS Office for Civil Rights and, in some cases, to local media. Business associates carry their own duty to notify the covered entity without unreasonable delay.
- PII breaches outside a HIPAA context are governed by state breach-notification laws, which vary in scope, timing, and trigger conditions from state to state.
- “Unsecured PHI” is the operative phrase: PHI rendered unusable, unreadable, or indecipherable through encryption or destruction generally falls outside notification duties entirely.
- Encryption isn’t just a good habit here. It’s a legal safe harbor against the notification requirement itself.
Pro Tip: Encrypting ePHI at rest and in transit doesn’t just reduce breach risk. If encryption meets HHS-recognized standards and the encryption key stays protected, an incident involving that data may not even count as a reportable breach.
Practical incident response follows the same logic either way: isolate the affected systems, determine scope, document who accessed what and when, and preserve logs before anything gets overwritten. A risk assessment checklist built before an incident happens saves days of guesswork during one.
Is Your Data PHI or Just PII? A Practical Checklist
Run any dataset through these questions before deciding how to secure it and what rules apply.
- Who gathered this data, and for what original purpose?
- Does it relate to a person’s health condition, treatment, or payment for care?
- Does it contain any of HIPAA’s 18 identifiers, either alone or combined with health context?
- Is the organization holding it a covered entity, or a vendor acting as a business associate?
If the answers point to PHI, the next steps are concrete: secure a signed BAA with every vendor touching the data, encrypt it in transit and at rest, and document the policies governing access. If it’s PII without health context, follow applicable state breach laws, apply strong access and encryption controls anyway, and keep the classification decision on record.
Pro Tip: Build a data inventory that maps source, purpose, and recipient for every dataset you hold, and write down the reasoning behind each PHI-or-PII call. Regulators and auditors care as much about your documented judgment as they do about the answer itself.
What Happens Legally When PHI or PII Is Mishandled?
The penalty structure for mishandling PHI is far more codified than the penalty structure for mishandling generic PII, and that gap catches a lot of small businesses off guard.
HIPAA violations carry tiered civil penalties tied to the covered entity’s or business associate’s level of culpability, ranging from unknowing violations to willful neglect that goes uncorrected. Criminal penalties can apply in cases involving knowing violations or intent to sell or misuse PHI, and enforcement runs through the HHS Office for Civil Rights, which can also mandate corrective action plans, ongoing monitoring, and public settlement disclosures that damage a practice’s reputation independent of the fine itself.
Mishandled PII outside a health context doesn’t route through HHS at all. Instead, it falls under a patchwork of state attorney general enforcement, sector-specific federal rules like the FTC’s Safeguards Rule for financial data, and in some cases private lawsuits under state consumer protection statutes. Penalties tend to be less standardized, but they’re not necessarily lighter. A state attorney general pursuing a large PII breach can extract settlements and mandated security overhauls that rival HIPAA penalties in cost, even without a HIPAA violation on the books.
The practical takeaway for small and mid-sized organizations: don’t assume that skipping HIPAA applicability means skipping enforcement risk. It just means a different regulator, a different statute, and often a less predictable timeline for what happens next.

Do GDPR and CCPA Apply When HIPAA Doesn’t?
HIPAA is not the only privacy law in play, and understanding where it stops is as important as understanding where it starts.
The FTC Safeguards Rule governs financial institutions and businesses handling nonpublic financial information, and it applies regardless of whether HIPAA does. A CPA firm or lender handling client Social Security numbers and account data answers to the FTC even if it never touches a single medical record.
The California Consumer Privacy Act (CCPA) and its amendments give California residents rights over their personal information held by covered businesses, and it explicitly carves out data already regulated as PHI under HIPAA to avoid duplicate frameworks. That carve-out matters: a business can be fully HIPAA compliant on its patient data while still owing CCPA obligations for other personal information it collects, like marketing lists or website visitor data.
The General Data Protection Regulation (GDPR) applies to organizations processing the personal data of individuals in the European Union, regardless of where the organization itself is based. A U.S. telehealth company with European patients could face GDPR obligations layered on top of HIPAA, since GDPR’s scope is about the data subject’s location, not the organization’s home state.
The pattern across all three: HIPAA governs the health context specifically, while these other frameworks fill in everywhere HIPAA’s scope ends. A business handling both categories often needs more than one compliance framework running at once, not a single blanket policy.
tekRESCUE’s Take: Classification Is Where Compliance Actually Breaks
Most compliance failures we see don’t start with a hacker. They start with a business that never classified its data correctly in the first place, so nobody encrypted the right files or signed the right BAA. Getting the PHI versus PII call right, documenting it, and locking down vendor agreements before an incident happens is the difference between a manageable event and a reportable one.
— Randy Bryan
Get HIPAA Compliance Handled Before It Becomes a Breach Report
tekrescue is the alternative to guessing your way through HIPAA compliance: instead of piecing together classification decisions, BAAs, and encryption policies on your own, you get a team that specializes in exactly this intersection of security and health data law. Our cybersecurity services include HIPAA compliance assessments and FTC Safeguards Rule reviews built for small and mid-sized businesses across Austin, San Marcos, New Braunfels, Kyle, Schertz, and the surrounding Hays and Bastrop County areas. We help you map which datasets are PHI, get business associate agreements signed correctly, set up encryption and secure hosting for electronic PHI, and build an incident response plan before you ever need one. If a breach does happen, our incident response team steps in immediately. Reach out through tekrescue’s site to schedule a risk assessment and find out exactly where your PHI and PII exposure stands today.
This article is general information, not a substitute for advice from a qualified lawyer. Consult a qualified legal professional about your own circumstances before acting on anything here.
Sources
- Hhs
- Guide to Protecting the Confidentiality of Personally Identifiable Information (PII) | NIST SP 800-122
FAQ
What Are Five Examples of PHI?
Common PHI examples include a patient’s name linked to a diagnosis, medical record numbers, health insurance account numbers, full-face photographs in a clinical chart, and dates of treatment tied to an identifiable patient. Each qualifies because it combines a HIPAA identifier with health, care, or payment context held by a covered entity or business associate.
What Are the Three Types of PHI?
PHI is generally grouped by form: oral PHI (spoken between a provider and patient), paper PHI (physical charts and forms), and electronic PHI, or ePHI (digital records, emails, and databases). All three carry the same HIPAA obligations, though ePHI carries additional security requirements under the HIPAA Security Rule.
What Is Considered PII in the United States?
PII is any information that can distinguish or trace a person’s identity, alone or combined with other data, according to NIST SP 800-122. That includes names, Social Security numbers, biometric records, financial account numbers, and device identifiers linked to a specific individual.
What Are the 18 PHI Identifiers Under HIPAA?
HIPAA’s Safe Harbor method lists 18 identifiers, including names, geographic subdivisions smaller than a state, all dates tied to an individual, phone and fax numbers, email addresses, Social Security numbers, medical record numbers, full-face photographs, and biometric identifiers. Removing all 18 from a dataset, combined with no actual knowledge that remaining data could identify someone, satisfies the Safe Harbor de-identification standard.
Does tekrescue Help Determine Whether Data Is PHI or PII?
Yes, tekrescue’s cybersecurity and compliance services include HIPAA risk assessments that help classify your data, identify which vendors need business associate agreements, and recommend encryption and hosting setups suited to electronic PHI. Pricing depends on the size and scope of the assessment and is available on request through the site.
Recommended
Table of Contents











