Individually Identifiable Health Information
Individually identifiable health information is health-related information that can be linked to a specific person, either directly through common identifiers such as name, address, birth date, or Social Security Number, or in ways that could reasonably be used to identify that individual. It generally relates to a person's past, present, or future physical or mental health condition, the care they receive, or payment for that care. Under HIPAA, it forms the foundation of what becomes protected health information (PHI) when handled by covered entities and their business associates.
Individually identifiable health information (IIHI) is a defined subset of health information that relates to an individual's past, present, or future physical or mental health or condition, the provision of health care to the individual, or the past, present, or future payment for the provision of health care, and that either identifies the individual or with respect to which there is a reasonable basis to believe the information can be used to identify the individual. It includes many common identifiers such as name, address, birth date, and Social Security Number. When IIHI is created, received, maintained, or transmitted by a covered entity (or, by extension, a business associate) it generally constitutes protected health information (PHI) subject to the HIPAA Privacy Rule; the subset of PHI held in electronic form is electronic protected health information (ePHI), which is additionally governed by the HIPAA Security Rule. Note that identifiable information used in contexts outside a covered entity's or business associate's handling (for example, certain research data treated as personally identifiable information, or PII) may fall outside the scope of the HIPAA Privacy and Security Rules, and state law or other frameworks may impose additional requirements. Readers should verify precise regulatory definitions and any applicable identifiers against the current text of the HIPAA regulations.
Why it matters
Individually identifiable health information (IIHI) is the conceptual starting point for nearly everything HIPAA protects. When IIHI is created, received, maintained, or transmitted by a covered entity or a business associate, it generally becomes protected health information (PHI) and falls under the HIPAA Privacy Rule; the subset held in electronic form becomes ePHI and is additionally governed by the HIPAA Security Rule. Understanding what qualifies as IIHI therefore determines the boundary of an organization's compliance obligations. Misjudging that boundary, treating identifiable health data as if it were anonymous, or overlooking indirect identifiers, can expose an organization to improper use or disclosure.
Who it's relevant to
Inside IIHI
Common questions
Answers to the questions practitioners most commonly ask about IIHI.