Skip to main content
Category: De-identification and PHI Types

Individually Identifiable Health Information

Also known as: IIHI, IIHI
Simply put

Individually identifiable health information is health-related information that can be linked to a specific person, either directly through common identifiers such as name, address, birth date, or Social Security Number, or in ways that could reasonably be used to identify that individual. It generally relates to a person's past, present, or future physical or mental health condition, the care they receive, or payment for that care. Under HIPAA, it forms the foundation of what becomes protected health information (PHI) when handled by covered entities and their business associates.

Formal definition

Individually identifiable health information (IIHI) is a defined subset of health information that relates to an individual's past, present, or future physical or mental health or condition, the provision of health care to the individual, or the past, present, or future payment for the provision of health care, and that either identifies the individual or with respect to which there is a reasonable basis to believe the information can be used to identify the individual. It includes many common identifiers such as name, address, birth date, and Social Security Number. When IIHI is created, received, maintained, or transmitted by a covered entity (or, by extension, a business associate) it generally constitutes protected health information (PHI) subject to the HIPAA Privacy Rule; the subset of PHI held in electronic form is electronic protected health information (ePHI), which is additionally governed by the HIPAA Security Rule. Note that identifiable information used in contexts outside a covered entity's or business associate's handling (for example, certain research data treated as personally identifiable information, or PII) may fall outside the scope of the HIPAA Privacy and Security Rules, and state law or other frameworks may impose additional requirements. Readers should verify precise regulatory definitions and any applicable identifiers against the current text of the HIPAA regulations.

Why it matters

Individually identifiable health information (IIHI) is the conceptual starting point for nearly everything HIPAA protects. When IIHI is created, received, maintained, or transmitted by a covered entity or a business associate, it generally becomes protected health information (PHI) and falls under the HIPAA Privacy Rule; the subset held in electronic form becomes ePHI and is additionally governed by the HIPAA Security Rule. Understanding what qualifies as IIHI therefore determines the boundary of an organization's compliance obligations. Misjudging that boundary, treating identifiable health data as if it were anonymous, or overlooking indirect identifiers, can expose an organization to improper use or disclosure.

Who it's relevant to

Privacy Officers and Compliance Teams
Privacy officers rely on the IIHI standard to determine which data holdings become PHI subject to the Privacy Rule once handled by their organization. Accurately scoping IIHI helps define the reach of policies governing use, disclosure, and patient rights, and helps avoid both over-restriction and under-protection of information.
Security Officers and IT Staff
Because IIHI in electronic form generally becomes ePHI subject to the Security Rule, security teams use this classification to identify systems that must be covered by administrative, physical, and technical safeguards. Correctly identifying which electronic data is in scope is a prerequisite to applying the Security Rule's required and addressable implementation specifications.
Researchers and Research Administrators
The distinction between IIHI and other identifiable data matters in research settings. Personally identifiable information (PII) used in research that is not considered PHI may fall outside the scope of the HIPAA Privacy and Security Rules. Research teams should carefully determine whether their data constitutes IIHI held by a covered entity or business associate, and should note that state law or other frameworks may impose additional requirements beyond HIPAA.
Business Associates and Vendors
Business associates that create, receive, maintain, or transmit IIHI on behalf of a covered entity generally handle PHI and take on obligations through a business associate agreement. Recognizing when vendor-held data qualifies as IIHI is essential to understanding which contractual and regulatory obligations attach to that relationship.

Inside IIHI

Health Information Relating to an Individual
Information that relates to the past, present, or future physical or mental health or condition of an individual, the provision of health care to the individual, or the past, present, or future payment for the provision of health care to the individual.
Identifying Characteristics
The information either identifies the individual or provides a reasonable basis to believe it can be used to identify the individual. This linkage to a specific person is what makes health information individually identifiable rather than de-identified.
Created or Received by a Covered Entity or Related Source
The information is generally created or received by a health care provider, health plan, employer, or health care clearinghouse. Readers should verify the specific sources against the current regulatory text.
Relationship to Protected Health Information (PHI)
Individually identifiable health information becomes PHI when it is transmitted or maintained by a covered entity or business associate in any form or medium. Note that the Privacy Rule covers PHI in all forms (oral, paper, electronic), while the Security Rule applies only to the electronic subset (ePHI).

Common questions

Answers to the questions practitioners most commonly ask about IIHI.

Is individually identifiable health information the same thing as protected health information (PHI)?
Not exactly. Individually identifiable health information (IIHI) is a broader concept: it is a component of health information that identifies an individual, or for which there is a reasonable basis to believe it can be used to identify the individual. PHI is generally IIHI that is created or received by a covered entity or business associate and that is transmitted or maintained in any form or medium, subject to certain exclusions defined in the Privacy Rule (such as certain education and employment records). In practice, IIHI becomes PHI when it falls within the scope of the entities and relationships the Privacy Rule regulates. Because the precise definitions and exclusions are set in the regulatory text, readers should confirm the current definitions against the applicable CFR provisions.
Does information have to include a name to be individually identifiable?
No. A name is only one type of identifier. Information can be individually identifiable if there is a reasonable basis to believe it could be used, alone or in combination with other data, to identify the individual. This may include identifiers other than names and combinations of data elements that together point to a specific person. The regulatory standard focuses on the reasonable basis to identify, not solely on the presence of an explicit name. Whether particular data qualifies depends on the facts, so readers should evaluate each situation against the current regulatory definition.
How do we determine whether a specific data field in our systems counts as individually identifiable health information?
Generally, the analysis considers two elements: whether the information relates to an individual's health, health care, or payment for care, and whether it identifies the individual or creates a reasonable basis to believe it could be used to identify them. Because the second element depends on context and on what other information is available, organizations typically assess data fields in combination rather than in isolation. When the determination is close, it is common practice to treat the data as identifiable until an assessment shows otherwise. Confirm your analysis against the current Privacy Rule definitions.
Once IIHI is held by our organization, which HIPAA rule governs how we must protect it?
It depends on the form of the information and the nature of your organization. The Privacy Rule generally governs PHI in all forms, including oral, paper, and electronic. The Security Rule applies only to electronic protected health information (ePHI) and sets administrative, physical, and technical safeguards. Whether these obligations attach to your organization depends on whether you are a covered entity, a business associate, or a subcontractor. Obligations for vendors typically flow through business associate agreements rather than attaching automatically.
If we remove certain identifiers, does the information stop being individually identifiable?
In many cases, appropriately de-identified information is no longer treated as individually identifiable and generally falls outside the Privacy Rule's restrictions. However, de-identification must meet the standards set out in the regulatory text, and improperly stripped data may still carry a reasonable basis for identification. Note also that limited data sets, which retain some identifiers, are handled differently from fully de-identified data. Because the de-identification standards are specific, verify your approach against the current Privacy Rule requirements.
Do our vendors that handle individually identifiable health information become subject to the same obligations we are?
Not automatically. HIPAA does not directly regulate every vendor that touches data. Obligations generally attach through defined relationships, most commonly when a vendor meets the definition of a business associate and enters into a business associate agreement with the covered entity. Subcontractors that handle PHI on behalf of a business associate are similarly bound through agreements. The specific obligations that flow to a vendor depend on the terms of that agreement and the applicable regulatory requirements.

Common misconceptions

Removing a patient's name makes health information no longer individually identifiable.
Information can still be individually identifiable if other data provides a reasonable basis to believe it can be used to identify the individual. De-identification generally requires meeting specific regulatory standards, and readers should confirm the applicable de-identification methods against the current regulation.
Individually identifiable health information and PHI are exactly the same thing.
The terms are closely related but not identical. Individually identifiable health information becomes PHI when it is created, received, maintained, or transmitted by a covered entity or business associate. Certain records, such as some employment or education records, may be excluded from the PHI definition even though they contain individually identifiable health information; readers should verify exclusions against the current regulatory text.
Only electronic health information is regulated as individually identifiable health information.
The Privacy Rule generally applies to individually identifiable health information in any form or medium, including oral and paper. Only the Security Rule is limited to the electronic subset (ePHI). State law or the HITECH Act may impose additional requirements beyond HIPAA.

Best practices

Assess whether data can reasonably be used to identify an individual before treating it as de-identified, rather than relying solely on the removal of obvious identifiers such as names.
Apply protections across all forms of the information (oral, paper, and electronic) where the Privacy Rule applies, and apply Security Rule safeguards specifically to the electronic subset (ePHI).
Confirm whether individually identifiable health information in your possession meets the definition of PHI, accounting for any regulatory exclusions, and verify those exclusions against the current regulatory text.
Document the source and relationship (covered entity, business associate, or subcontractor) through which the information is created or received, since obligations generally attach through these defined relationships.
Verify current de-identification standards and any applicable citations against the current regulation rather than relying on outdated references, as regulatory text is adjusted over time.
Check whether state law or the HITECH Act imposes additional requirements beyond HIPAA for the health information you handle.