Personal Health Record
A Personal Health Record (PHR) is a collection of a person's health information that the individual (or a caregiver acting on their behalf) controls, manages, and tracks. Unlike records held by a doctor's office, a PHR is generally maintained by the individual and can be shared with others such as caregivers, family members, or providers at the person's discretion. PHRs are often internet-based applications that let a person gather, store, and manage their own health information.
A Personal Health Record (PHR) is generally defined as an individual-controlled collection of health-related information, typically maintained in electronic form, that enables the individual (or, in some cases, a caregiver) to gather, store, manage, track, and selectively share their own health information across their lifespan. A PHR is distinguished by individual ownership and control, in contrast to records maintained by a provider or covered entity. Note that whether a specific PHR falls within HIPAA's scope depends on the underlying relationships and how the record is provided: a PHR offered by or on behalf of a HIPAA covered entity or business associate may be subject to HIPAA, whereas a PHR that an individual maintains through an independent third-party vendor may fall outside HIPAA's direct coverage and instead be governed by other frameworks, the HITECH Act's PHR-related provisions, or applicable state law. Readers should verify the applicable regulatory treatment against current HHS guidance and relevant statutory text.
Why it matters
Personal Health Records matter because they shift a degree of control over health information from institutions to individuals, allowing a person (or a caregiver acting on their behalf) to gather, store, manage, track, and selectively share their own health data. This individual-centered model can support better care coordination, patient engagement, and continuity of information across providers over a person's lifespan. But that same individual control creates a critical compliance question that professionals must not overlook: not every PHR is governed by HIPAA.
The regulatory treatment of a PHR depends on the underlying relationships and how the record is provided. A PHR offered by or on behalf of a HIPAA covered entity or business associate may fall within HIPAA's scope, meaning the Privacy Rule and, for electronic PHI, the Security Rule could apply. By contrast, a PHR that an individual maintains through an independent third-party vendor may fall outside HIPAA's direct coverage and instead be governed by other frameworks, the HITECH Act's PHR-related provisions, or applicable state law. Misclassifying which category a given PHR occupies can lead an organization either to over-apply obligations that do not attach or, more dangerously, to assume protections and breach-notification duties exist where HIPAA does not reach.
For compliance, privacy, and security professionals, the practical significance is that PHRs sit at the boundary of HIPAA's jurisdiction. Determining whether a specific PHR is subject to HIPAA requires analyzing who provides it and on whose behalf, rather than assuming coverage based on the presence of health data alone. Readers should verify the applicable treatment against current HHS guidance and relevant statutory text, and should account for state-law and HITECH provisions that may impose additional requirements.
Who it's relevant to
Inside PHR
Common questions
Answers to the questions practitioners most commonly ask about PHR.