Protected health information includes any information relating to an individual's physical or mental health, healthcare provision, or payment for care that identifies the individual or could reasonably be used to do so.
De-identification requires removing eighteen specified identifiers or an expert determination that re-identification risk is very small.
Alternative Names:
PHI, Individually Identifiable Health Information
Why it Matters?
Litigation files in injury, malpractice, and long-term care matters consist largely of this material, which means the firm's security obligations flow from its clients' regulated data rather than its own. That affects vendor selection, since any system touching those records requires a business associate agreement, and it affects breach exposure, since a firm compromise involving medical records triggers HIPAA notification alongside state statutes.
Frequently Confused with
Related terms
Frequently asked questions
What makes health information identifiable?
Does a law firm need business associate agreements with its vendors?





