Protected Health Information

Protected Health Information

Protected Health Information

Protected health information includes any information relating to an individual's physical or mental health, healthcare provision, or payment for care that identifies the individual or could reasonably be used to do so.

De-identification requires removing eighteen specified identifiers or an expert determination that re-identification risk is very small.

Alternative Names:

PHI, Individually Identifiable Health Information

Why it Matters?

Litigation files in injury, malpractice, and long-term care matters consist largely of this material, which means the firm's security obligations flow from its clients' regulated data rather than its own. That affects vendor selection, since any system touching those records requires a business associate agreement, and it affects breach exposure, since a firm compromise involving medical records triggers HIPAA notification alongside state statutes.

Frequently Confused with

Related terms

Frequently asked questions

What makes health information identifiable?

What makes health information identifiable?

The presence of any of eighteen specified identifiers, or other data that could reasonably be used alone or in combination to identify the individual.

Does a law firm need business associate agreements with its vendors?

Does a law firm need business associate agreements with its vendors?

Yes, with any vendor that will access protected health information, including document management, e-discovery, and AI providers.