Unsecured PHI
Unsecured PHI is protected health information that has not been made unusable, unreadable, or indecipherable to unauthorized people, generally through methods such as encryption or destruction. In plain terms, it is health information that remains readable or recoverable if it falls into the wrong hands. This distinction matters because, under HIPAA's Breach Notification Rule, notification obligations typically apply to breaches involving unsecured PHI.
Under 45 CFR 164.402, unsecured protected health information means PHI that is not rendered unusable, unreadable, or indecipherable to unauthorized persons through the use of a technology or methodology specified by HHS guidance. In practice, the recognized methods generally include encryption and destruction; PHI that has been secured in accordance with such guidance is typically outside the scope of the Breach Notification Rule's notification requirements, whereas an acquisition, access, use, or disclosure of unsecured PHI that compromises its security or privacy may constitute a reportable breach. This term is specific to the Breach Notification Rule and does not alter obligations under the Privacy Rule or the Security Rule; note that the Privacy Rule covers PHI in all forms (oral, paper, and electronic), while encryption-based securing methods are most relevant to electronic PHI. Practitioners should verify the current HHS-specified technologies and methodologies, as well as any additional obligations that may arise under the HITECH Act or applicable state law, against current regulatory guidance.
Why it matters
The concept of unsecured PHI sits at the heart of HIPAA's Breach Notification Rule because it determines whether a notification obligation is triggered at all. When an impermissible acquisition, access, use, or disclosure involves unsecured PHI and compromises its security or privacy, it may constitute a reportable breach requiring notification to affected individuals, HHS OCR, and in some cases the media. By contrast, PHI that has been rendered unusable, unreadable, or indecipherable through an HHS-recognized method such as encryption or destruction is generally outside the scope of these notification requirements. This is why securing PHI is often described as creating a functional safe harbor from breach notification.
For compliance teams, this distinction has significant practical and financial consequences. A lost laptop or misdirected file containing readable PHI can set off the full notification and reporting process, while the same loss involving properly encrypted data may not. It is important to understand that securing PHI addresses only the notification analysis under the Breach Notification Rule; it does not change an organization's underlying obligations under the Privacy Rule or the Security Rule, and it does not by itself guarantee compliance or prevent all breaches.
Organizations should also recognize that the securing methods that qualify are defined by HHS guidance and may be updated over time. Because the Privacy Rule covers PHI in all forms including oral and paper, while encryption is most relevant to electronic PHI, a securing strategy focused only on encryption may leave paper and other formats unaddressed. Practitioners should also account for potential additional obligations under the HITECH Act and applicable state breach notification laws, which may impose requirements beyond HIPAA.
Who it's relevant to
Inside Unsecured PHI
Common questions
Answers to the questions practitioners most commonly ask about Unsecured PHI.