Skip to main content
Category: De-identification and PHI Types

Health Information

Also known as: Health Data
Simply put

Health information is data related to a person's health, medical history, or care, including symptoms, diagnoses, procedures, and outcomes. In the HIPAA context, it becomes subject to specific legal protections when it can be linked to an individual and is held or transmitted by a covered entity or its business associate. Not all health information is regulated by HIPAA; the protections generally attach to identifiable information within these defined relationships.

Formal definition

In general usage, health information refers to any data related to an individual's medical history, symptoms, diagnoses, procedures, and outcomes, or to information supporting the maintenance and improvement of health. Under HIPAA, the operative regulated concept is narrower: the HIPAA Privacy Rule protects 'individually identifiable health information' held or transmitted by a covered entity or its business associate, in any form (oral, paper, or electronic). Note that 'health information' as used colloquially or in health information management (HIM) contexts is broader than HIPAA's regulated scope; HIPAA obligations attach only through defined covered entity and business associate relationships, and identifiable information generally becomes protected health information (PHI) once it can be tied to an individual. Readers should verify the precise statutory and regulatory definitions against the current HIPAA regulatory text, and be aware that state law or the HITECH Act may impose additional requirements. The HIPAA Security Rule specifically governs only electronic protected health information (ePHI), a subset of this broader category.

Why it matters

Health information sits at the center of HIPAA because it is the raw material the law is designed to protect. However, a critical distinction drives everything downstream: not all health information is regulated by HIPAA. The colloquial and health information management (HIM) understanding of health information, data about a person's medical history, symptoms, diagnoses, procedures, and outcomes, is far broader than the specific concept HIPAA regulates. Under HIPAA, protections generally attach only to 'individually identifiable health information' held or transmitted by a covered entity or its business associate. Understanding where general health information ends and HIPAA-regulated protected health information (PHI) begins is essential to scoping compliance obligations correctly.

For compliance professionals, misjudging this boundary creates risk in both directions. Treating every piece of health-related data as PHI can waste resources and impose unnecessary controls, while failing to recognize when health information has become identifiable and falls within a covered entity or business associate relationship can lead to gaps in privacy and security safeguards. Because HIPAA obligations attach through defined relationships rather than to the data itself in the abstract, the same health information may be regulated in one context and not in another.

Who it's relevant to

Privacy Officers
Privacy officers must determine when general health information rises to the level of individually identifiable health information protected under the HIPAA Privacy Rule. Accurate scoping of what qualifies as PHI, across oral, paper, and electronic forms, directly shapes which policies, uses, and disclosures fall under regulatory obligations.
Security Officers
Security officers focus specifically on electronic protected health information (ePHI), the subset of health information governed by the HIPAA Security Rule. Distinguishing ePHI from health information that is either non-electronic or not individually identifiable helps ensure administrative, physical, and technical safeguards are applied to the correct data.
Health Information Management (HIM) Professionals
HIM professionals work with health information in its broadest sense, the collection, analysis, storage, and quality of patient health data. They should recognize that the HIM concept of health information is wider than HIPAA's regulated scope, and that HIPAA protections attach only to identifiable information within covered entity and business associate relationships.
Business Associates and Vendors
Business associates and their subcontractors handling health information on behalf of covered entities must understand that HIPAA obligations flow through defined relationships and business associate agreements. Health information they receive or transmit that is individually identifiable is generally treated as PHI subject to applicable safeguards.
Compliance and Legal Teams
Compliance and legal professionals must map the boundary between general health information and HIPAA-regulated PHI, verifying definitions against current regulatory text. They should also account for state law and the HITECH Act, which may impose additional requirements beyond HIPAA's baseline.

Inside Health Information

Broad Definition
Under HIPAA, health information generally refers to any information, whether oral or recorded in any form or medium, that relates to the past, present, or future physical or mental health or condition of an individual, the provision of health care to an individual, or payment for that care. This is a broad category that is not limited to electronic data.
Relationship to PHI
Health information becomes protected health information (PHI) when it is individually identifiable and is created, received, maintained, or transmitted by a covered entity or business associate. Not all health information is PHI; de-identified information generally falls outside HIPAA protections.
Form and Medium
Health information may exist in any form, including oral communications, paper records, and electronic records. The HIPAA Privacy Rule covers PHI in all forms, while the Security Rule applies only to the electronic subset (ePHI).
Payment and Provision Data
The concept extends beyond clinical details to include information relating to the provision of health care and to payment for care, so billing, claims, and eligibility information can qualify as health information.

Common questions

Answers to the questions practitioners most commonly ask about Health Information.

Is all health information automatically protected health information (PHI) under HIPAA?
No. Health information is a broad category that becomes protected health information (PHI) only when it is created or received by a covered entity or business associate and relates to an individual's health condition, provision of care, or payment for care in a way that identifies the individual or could reasonably be used to identify them. Health information held outside these regulated relationships, or information that has been properly de-identified under the Privacy Rule standards, generally does not meet the definition of PHI. Readers should evaluate whether the information is individually identifiable and whether it is held by a HIPAA-regulated entity before treating it as PHI.
Does HIPAA protect all health information regardless of who holds it?
Not directly. HIPAA obligations attach through defined relationships, covered entities, their business associates, and subcontractors bound by business associate agreements. Health information held by organizations outside these relationships (for example, certain consumer apps, wearable device makers, or life insurers) may not be subject to HIPAA, even though the data itself is health-related. Other laws, including state privacy statutes or other federal frameworks, may impose their own requirements, so readers should verify the applicable regulatory regime for a given data holder.
Does the format of health information (oral, paper, or electronic) affect which HIPAA rules apply?
Yes. The Privacy Rule covers health information in all forms, including oral, paper, and electronic. The Security Rule, by contrast, applies only to electronic protected health information (ePHI). This means safeguards for spoken conversations or paper records are generally addressed through Privacy Rule requirements, while electronic systems must additionally meet the administrative, physical, and technical safeguards of the Security Rule. Teams should map their information flows across formats to determine which rule set governs each.
How can an organization determine whether the health information it holds qualifies as identifiable?
Organizations generally assess whether the information identifies an individual or could reasonably be used to identify them. The Privacy Rule provides de-identification standards (commonly described as an expert determination method and a safe harbor method involving removal of specified identifiers) that, when properly applied, render information no longer individually identifiable. Because applying these methods correctly requires care, organizations should consult the current regulatory text and, where appropriate, qualified expertise before relying on a de-identification determination.
What steps help ensure health information is handled consistently across an organization?
In most cases, organizations establish data inventories or information flow maps that identify where health information originates, how it moves, and who holds it, distinguishing PHI from non-regulated health data. This typically supports applying the correct Privacy Rule and Security Rule obligations, structuring business associate agreements where third parties handle the data, and training workforce members on format-specific handling. These practices support compliance efforts but do not by themselves guarantee compliance.
How does health information relate to business associate agreements in practice?
When a covered entity shares protected health information with a vendor performing a function on its behalf, that vendor generally becomes a business associate, and the sharing is typically governed by a business associate agreement that flows down applicable HIPAA obligations. Subcontractors that receive the same information are generally bound through further agreements. Organizations should confirm which relationships trigger these agreements and ensure the scope of permitted uses and disclosures is documented, verifying terms against current regulatory requirements.

Common misconceptions

Health information only refers to electronic records in a computer system.
Health information can exist in any form or medium, including oral and paper. The Privacy Rule covers PHI in all forms, whereas only the Security Rule is limited to electronic PHI (ePHI).
All health information is automatically protected under HIPAA.
Health information is generally protected as PHI only when it is individually identifiable and is created, received, maintained, or transmitted by a covered entity or business associate. Properly de-identified health information typically falls outside HIPAA's protections.
Health information only covers clinical or diagnostic details.
The definition also encompasses information relating to the provision of health care and to payment for that care, so billing and payment-related data can qualify as health information.

Best practices

Treat health information as potentially subject to HIPAA regardless of its form, applying appropriate protections to oral, paper, and electronic records rather than focusing only on electronic systems.
Determine whether specific health information is individually identifiable PHI before assuming HIPAA obligations apply, and document that analysis.
Apply the Privacy Rule to PHI across all media, and apply the Security Rule's administrative, physical, and technical safeguards specifically to the electronic subset (ePHI).
Verify any de-identification claims against current regulatory standards, since only properly de-identified information generally falls outside HIPAA.
Consult current regulatory text and confirm definitions and requirements against the applicable CFR provisions rather than relying on general summaries.
Consider that state law, the HITECH Act, or other frameworks may impose additional requirements on health information beyond HIPAA's baseline.