PHI is health information tied to a person, while PII is any data that can identify a person. That single difference shapes how hospitals, insurers, labs, app vendors, and support teams must collect, store, share, and delete sensitive records. When health context appears beside an identifier, ordinary personal data can become regulated healthcare data fast.
TLDR: PII identifies a person, such as a name, phone number, Social Security number, or email address. PHI identifies a person and relates to health care, payment, diagnosis, treatment, or medical status. For example, an email address alone is PII, but that same email address attached to a diabetes treatment reminder is PHI. In a review of 10,000 patient messages, even a 2% tagging error could expose 200 records to the wrong workflow, which is exactly the kind of mistake compliance teams dread.
What PHI Means
Protected Health Information, or PHI, is individually identifiable health information created, received, stored, or sent by a covered healthcare entity or its business associate. It is governed by the Health Insurance Portability and Accountability Act, often called HIPAA, in the United States.
PHI can describe a patient’s past, present, or future health condition. It can also involve medical care or payment for care. A lab result, prescription record, discharge summary, claim number, X ray report, or appointment reminder may all be PHI when tied to a person.
The key is the connection. A blood pressure reading without any link to a person may be de identified data. A blood pressure reading next to a patient name, medical record number, or email address is PHI.
What PII Means
Personally Identifiable Information, or PII, is data that can identify a specific person. PII appears in many industries, not just health care. Banks, schools, retailers, employers, and software platforms all handle PII.
Common PII includes:
- Full name
- Home address
- Email address
- Phone number
- Date of birth
- Social Security number
- Driver’s license number
- Passport number
- Account credentials
- Device identifiers and IP addresses in some settings
PII can be sensitive or non sensitive. A work email address may be less sensitive than a Social Security number. Still, both can identify a person. The risk grows when PII is combined with financial, health, location, or biometric data.
PHI vs PII: The Core Difference
The simplest rule is this: all PHI contains some form of identifying information, but not all PII is PHI. PHI needs a healthcare link. PII does not.
A patient’s name in a hospital appointment system can be PHI because it is connected to care. The same name in a retail rewards program is PII. The data point may look identical, but the context changes the legal and operational burden.
Honestly, it feels like the most common source of confusion is the spreadsheet export. A billing team may export names, dates of service, diagnosis codes, and balances into a file called “accounts.xlsx.” That plain file name hides PHI. If it gets emailed to the wrong vendor, the issue is no longer minor.
Examples That Show the Difference
| Data Example | PII? | PHI? | Why It Matters |
|---|---|---|---|
| Name and phone number in a gym signup form | Yes | No | It identifies a person, but it is not tied to healthcare treatment or payment. |
| Name and chemotherapy appointment date | Yes | Yes | It identifies a person and reveals health care. |
| Medical record number alone inside a hospital system | Yes | Yes | It can identify a patient within that system. |
| Aggregated count of flu cases by county | No | No | It does not identify a specific person if properly aggregated. |
HIPAA Identifiers Linked to PHI
HIPAA lists identifiers that can turn health information into PHI when connected to healthcare data. These include names, geographic details smaller than a state, dates tied to a person, phone numbers, fax numbers, email addresses, Social Security numbers, and medical record numbers.
Other identifiers include health plan numbers, account numbers, certificate numbers, vehicle identifiers, device identifiers, web URLs, IP addresses, biometric identifiers, full face photos, and any other unique identifying number or code.
That last category is broad. It drives privacy teams crazy that a random internal ID can still identify a patient if the organization can match it back to a record in three clicks. A field labeled “user token” may not look risky, but it can still be risky.
Why the Distinction Matters
PHI usually carries stricter handling rules than general PII. Covered entities and business associates must protect PHI through administrative, technical, and physical safeguards. These controls affect access rights, audit logs, encryption, vendor contracts, training, breach response, and retention.
PII is regulated too, but the rules vary by location and industry. Privacy laws may cover consumer rights, consent, data deletion, access requests, and breach notices. PHI adds healthcare-specific duties, especially under HIPAA.
For a software vendor, the distinction can change the entire business model. If the vendor stores appointment reminders for a clinic, it may need a Business Associate Agreement. If it only stores generic marketing emails for a shoe store, it likely does not. Same type of database. Very different risk.
How PHI Appears in Daily Workflows
PHI is not limited to electronic health records. It often appears in tools that were not built mainly for clinical care. That includes help desk tickets, chat transcripts, call recordings, analytics dashboards, scanned PDFs, calendar invites, cloud storage folders, text messages, and insurance portals.
Expect to waste time on cleanup when staff paste patient details into the wrong system. A support ticket that says “John Smith cannot access his portal” may be manageable. A ticket that adds “after his HIV test result” creates a much bigger issue.
Common PHI locations include:
- Electronic health record systems
- Billing and claims platforms
- Patient portals
- Lab information systems
- Telehealth platforms
- Email and messaging tools
- Backups and archived files
- Customer support software
Best Practices for Handling PHI and PII
Organizations should classify data before it moves. A simple label such as PII, PHI, payment data, or public can prevent sloppy sharing. Labels also help systems apply correct retention, encryption, and access rules.
Strong controls should include:
- Minimum necessary access: Staff should see only the data needed for their role.
- Encryption: PHI should be protected at rest and in transit.
- Audit logs: Systems should record who viewed, changed, exported, or deleted records.
- Vendor review: Third parties that touch PHI need contracts and security checks.
- Staff training: Workers need clear examples, not vague policy slides.
- Data loss controls: Systems should block risky exports, uploads, and email attachments.
- Incident response: Teams need a tested plan before a breach happens.
De Identification and Limited Data Sets
Health data may fall outside PHI rules if it is properly de identified. HIPAA allows two main methods: expert determination and removal of specified identifiers. In practice, de identification must be handled with care. Removing names may not be enough if rare diagnosis details, dates, or locations can still point to one person.
A limited data set keeps some information, such as certain dates or city level details, for research or healthcare operations. It still requires controls. It is not the same as fully de identified data.
FAQ
Is PHI always medical data?
PHI must relate to health, healthcare services, or payment for care, and it must identify a person or be reasonably linkable to a person.
Is an email address PHI?
An email address alone is usually PII. It becomes PHI when connected to healthcare activity, such as a lab result notice or treatment reminder.
Is diagnosis data without a name PHI?
It can still be PHI if other details can identify the person. A rare condition, date, and small town may be enough to reveal identity.
Can a non healthcare company handle PHI?
Yes. A billing vendor, cloud provider, answering service, or analytics firm may handle PHI for a covered entity. That company may become a business associate.
What is worse to expose, PHI or PII?
Both can cause harm. PHI often creates higher regulatory risk because it may reveal diagnoses, treatments, medications, or insurance details.
How should organizations reduce PHI risk?
They should collect less data, restrict access, encrypt records, monitor exports, train staff, and review every vendor that stores or processes patient information.