Skip to main content
Category: Individual Rights

Personal Health Record

Also known as: PHR, Personal Health Records
Simply put

A Personal Health Record (PHR) is a collection of a person's health information that the individual (or a caregiver acting on their behalf) controls, manages, and tracks. Unlike records held by a doctor's office, a PHR is generally maintained by the individual and can be shared with others such as caregivers, family members, or providers at the person's discretion. PHRs are often internet-based applications that let a person gather, store, and manage their own health information.

Formal definition

A Personal Health Record (PHR) is generally defined as an individual-controlled collection of health-related information, typically maintained in electronic form, that enables the individual (or, in some cases, a caregiver) to gather, store, manage, track, and selectively share their own health information across their lifespan. A PHR is distinguished by individual ownership and control, in contrast to records maintained by a provider or covered entity. Note that whether a specific PHR falls within HIPAA's scope depends on the underlying relationships and how the record is provided: a PHR offered by or on behalf of a HIPAA covered entity or business associate may be subject to HIPAA, whereas a PHR that an individual maintains through an independent third-party vendor may fall outside HIPAA's direct coverage and instead be governed by other frameworks, the HITECH Act's PHR-related provisions, or applicable state law. Readers should verify the applicable regulatory treatment against current HHS guidance and relevant statutory text.

Why it matters

Personal Health Records matter because they shift a degree of control over health information from institutions to individuals, allowing a person (or a caregiver acting on their behalf) to gather, store, manage, track, and selectively share their own health data. This individual-centered model can support better care coordination, patient engagement, and continuity of information across providers over a person's lifespan. But that same individual control creates a critical compliance question that professionals must not overlook: not every PHR is governed by HIPAA.

The regulatory treatment of a PHR depends on the underlying relationships and how the record is provided. A PHR offered by or on behalf of a HIPAA covered entity or business associate may fall within HIPAA's scope, meaning the Privacy Rule and, for electronic PHI, the Security Rule could apply. By contrast, a PHR that an individual maintains through an independent third-party vendor may fall outside HIPAA's direct coverage and instead be governed by other frameworks, the HITECH Act's PHR-related provisions, or applicable state law. Misclassifying which category a given PHR occupies can lead an organization either to over-apply obligations that do not attach or, more dangerously, to assume protections and breach-notification duties exist where HIPAA does not reach.

For compliance, privacy, and security professionals, the practical significance is that PHRs sit at the boundary of HIPAA's jurisdiction. Determining whether a specific PHR is subject to HIPAA requires analyzing who provides it and on whose behalf, rather than assuming coverage based on the presence of health data alone. Readers should verify the applicable treatment against current HHS guidance and relevant statutory text, and should account for state-law and HITECH provisions that may impose additional requirements.

Who it's relevant to

Privacy Officers
Privacy officers need to determine whether a given PHR is offered by or on behalf of their organization as a covered entity or business associate, which would bring it within HIPAA's scope, versus a PHR an individual maintains independently. This classification drives whether Privacy Rule obligations attach and whether other frameworks, the HITECH Act, or state law apply instead. The analysis should be confirmed against current HHS guidance.
Security Officers
Where a PHR contains electronic PHI and is provided by or on behalf of a covered entity or business associate, the Security Rule's administrative, physical, and technical safeguards may be implicated. Security officers should assess how any PHR relationship affects safeguard responsibilities, while recognizing that a PHR maintained through an independent vendor may fall outside HIPAA's direct coverage.
Compliance and Legal Professionals
Compliance and legal teams must evaluate the underlying relationships and vendor arrangements that determine a PHR's regulatory status, including whether a business associate agreement is required. They should also account for the HITECH Act's PHR-related provisions and applicable state law, which may impose requirements beyond HIPAA, and verify the current treatment against relevant statutory text.
Health Information Management Staff
HIM professionals work at the intersection of provider-maintained records and individual-controlled PHRs. They should understand that a PHR is generally controlled by the individual or a caregiver and is distinct from records the organization maintains, and that sharing occurs at the individual's discretion, which affects how information flows between the patient and the organization.

Inside PHR

Individual-Managed Health Information
A Personal Health Record (PHR) is generally a health record that is created, controlled, or managed by the individual (the patient or consumer) rather than by a healthcare provider. This distinguishes it from a provider-maintained electronic health record (EHR).
Aggregated Data from Multiple Sources
A PHR may compile health information drawn from various sources, such as multiple providers, laboratories, pharmacies, and information entered directly by the individual. The individual typically decides what to include and with whom to share it.
Variable HIPAA Applicability
Whether a PHR falls under HIPAA depends on who offers it. When a PHR is offered by or on behalf of a HIPAA covered entity, or by a business associate, HIPAA rules generally apply. A PHR offered directly to consumers by a vendor that is not acting as a covered entity or business associate is often outside HIPAA's direct scope.
Potential Coverage Under Other Frameworks
PHRs not governed by HIPAA may still be subject to other legal frameworks, such as FTC oversight or state privacy laws, and the HITECH Act may impose additional requirements in certain circumstances. Readers should verify the specific obligations that apply to a given PHR arrangement against current regulation.

Common questions

Answers to the questions practitioners most commonly ask about PHR.

Is a personal health record (PHR) always covered by HIPAA?
No. HIPAA does not automatically apply to every PHR. Whether a PHR falls within HIPAA's scope generally depends on who offers it and the nature of the relationship. A PHR offered directly to a consumer by a vendor that is not acting as a covered entity or business associate is typically not regulated by HIPAA itself, though other laws may apply. In contrast, a PHR offered by or on behalf of a covered entity, or through a business associate relationship, may bring HIPAA obligations into play. Readers should evaluate the specific arrangement rather than assume HIPAA coverage.
Is a personal health record the same thing as an electronic health record (EHR)?
No, the terms are not interchangeable. A PHR is generally understood as a record that the individual controls and manages, whereas an EHR is typically maintained by a healthcare provider or organization as part of clinical operations. The distinction matters for compliance analysis because the party that controls and maintains the record, and the relationship under which it is offered, influence whether and how HIPAA rules attach. This entry does not address the full regulatory treatment of EHRs, which should be evaluated separately.
If we offer a PHR to our patients, how do we determine our HIPAA obligations?
Begin by identifying the relationship: whether the PHR is offered by your organization as a covered entity, on your behalf by a vendor acting as a business associate, or by an independent third party. Obligations under HIPAA generally attach through these defined relationships. Where a vendor handles protected health information on your behalf, a business associate agreement is typically required. Because the analysis is fact-specific, organizations should document how the PHR is provisioned and confirm the arrangement against current HIPAA requirements.
Which HIPAA rules are most relevant when a PHR is within HIPAA's scope?
When a PHR containing electronic protected health information (ePHI) falls within HIPAA's scope, the Security Rule generally governs the administrative, physical, and technical safeguards for that ePHI, while the Privacy Rule addresses the use and disclosure of protected health information in all forms. The Breach Notification Rule may also apply in the event of an impermissible acquisition, access, use, or disclosure. Organizations should map the specific obligations to the applicable rule rather than treat them as a single undifferentiated requirement.
What should we consider when selecting a PHR vendor?
Consider whether the vendor will act as a business associate, and if so, ensure a business associate agreement is in place before protected health information is exchanged. Evaluate the vendor's approach to administrative, physical, and technical safeguards for ePHI, noting that addressable implementation specifications under the Security Rule are not optional and must be assessed. Where a vendor holds a certification such as HITRUST CSF certification, treat it as supporting evidence of a control program rather than as proof of HIPAA compliance, which HHS OCR enforces separately.
Do requirements beyond HIPAA apply to PHRs, and how should we account for them?
Yes, in many cases. State law, the HITECH Act, and other frameworks may impose additional or stricter requirements on PHRs, including in situations where HIPAA itself may not apply to a consumer-facing product. Organizations should not assume that satisfying HIPAA, where applicable, addresses all legal obligations. It is advisable to review the specific PHR arrangement against current federal regulation, applicable state law, and any other governing framework, and to verify current requirements before relying on them.

Common misconceptions

All Personal Health Records are protected by HIPAA.
HIPAA does not automatically regulate every PHR. Its Privacy and Security Rules attach through defined relationships, generally when a PHR is offered by or on behalf of a covered entity or a business associate. A consumer-facing PHR from a vendor outside those relationships is typically not directly regulated by HIPAA, though other frameworks such as FTC rules or state law may apply. Verify applicability against the current regulatory text.
A Personal Health Record is the same thing as an electronic health record (EHR).
These terms have distinct meanings. A PHR is generally created, controlled, or managed by the individual, whereas an EHR is typically maintained and controlled by a healthcare provider. Conflating the two can lead to incorrect assumptions about who bears compliance responsibilities and which HIPAA obligations apply.
Data placed in a PHR is always covered by the HIPAA Security Rule's ePHI safeguards.
The Security Rule governs electronic protected health information only when held by a covered entity or business associate. If the PHR is not offered by or on behalf of such an entity, the Security Rule's administrative, physical, and technical safeguards may not apply to that data, even though it is electronic health information. The applicable protections depend on the specific arrangement and other governing frameworks.

Best practices

Determine at the outset whether a specific PHR is offered by or on behalf of a covered entity or business associate, since this generally governs whether HIPAA's Privacy and Security Rules apply.
Where a PHR is offered by a covered entity or business associate, ensure business associate agreements accurately reflect the PHR vendor's role and the obligations flowing to it.
For PHRs that fall outside HIPAA's direct scope, evaluate whether FTC oversight, state privacy laws, or HITECH Act provisions impose additional requirements, and confirm these against current regulation.
Clearly document the distinction between individual-controlled PHR data and provider-controlled EHR data to avoid misassigning compliance responsibilities.
When a PHR is subject to the Security Rule, apply the relevant administrative, physical, and technical safeguards, remembering that addressable implementation specifications are not optional and must be evaluated and documented.
Verify any specific applicability determinations, penalty considerations, or breach obligations against the current HIPAA regulatory text and HHS OCR guidance, rather than assuming a fixed rule for all PHRs.