Health Information
Health information is data related to a person's health, medical history, or care, including symptoms, diagnoses, procedures, and outcomes. In the HIPAA context, it becomes subject to specific legal protections when it can be linked to an individual and is held or transmitted by a covered entity or its business associate. Not all health information is regulated by HIPAA; the protections generally attach to identifiable information within these defined relationships.
In general usage, health information refers to any data related to an individual's medical history, symptoms, diagnoses, procedures, and outcomes, or to information supporting the maintenance and improvement of health. Under HIPAA, the operative regulated concept is narrower: the HIPAA Privacy Rule protects 'individually identifiable health information' held or transmitted by a covered entity or its business associate, in any form (oral, paper, or electronic). Note that 'health information' as used colloquially or in health information management (HIM) contexts is broader than HIPAA's regulated scope; HIPAA obligations attach only through defined covered entity and business associate relationships, and identifiable information generally becomes protected health information (PHI) once it can be tied to an individual. Readers should verify the precise statutory and regulatory definitions against the current HIPAA regulatory text, and be aware that state law or the HITECH Act may impose additional requirements. The HIPAA Security Rule specifically governs only electronic protected health information (ePHI), a subset of this broader category.
Why it matters
Health information sits at the center of HIPAA because it is the raw material the law is designed to protect. However, a critical distinction drives everything downstream: not all health information is regulated by HIPAA. The colloquial and health information management (HIM) understanding of health information, data about a person's medical history, symptoms, diagnoses, procedures, and outcomes, is far broader than the specific concept HIPAA regulates. Under HIPAA, protections generally attach only to 'individually identifiable health information' held or transmitted by a covered entity or its business associate. Understanding where general health information ends and HIPAA-regulated protected health information (PHI) begins is essential to scoping compliance obligations correctly.
For compliance professionals, misjudging this boundary creates risk in both directions. Treating every piece of health-related data as PHI can waste resources and impose unnecessary controls, while failing to recognize when health information has become identifiable and falls within a covered entity or business associate relationship can lead to gaps in privacy and security safeguards. Because HIPAA obligations attach through defined relationships rather than to the data itself in the abstract, the same health information may be regulated in one context and not in another.
Who it's relevant to
Inside Health Information
Common questions
Answers to the questions practitioners most commonly ask about Health Information.