Skip to main content
Category: De-identification and PHI Types

Unsecured PHI

Also known as: Unsecured Protected Health Information
Simply put

Unsecured PHI is protected health information that has not been made unusable, unreadable, or indecipherable to unauthorized people, generally through methods such as encryption or destruction. In plain terms, it is health information that remains readable or recoverable if it falls into the wrong hands. This distinction matters because, under HIPAA's Breach Notification Rule, notification obligations typically apply to breaches involving unsecured PHI.

Formal definition

Under 45 CFR 164.402, unsecured protected health information means PHI that is not rendered unusable, unreadable, or indecipherable to unauthorized persons through the use of a technology or methodology specified by HHS guidance. In practice, the recognized methods generally include encryption and destruction; PHI that has been secured in accordance with such guidance is typically outside the scope of the Breach Notification Rule's notification requirements, whereas an acquisition, access, use, or disclosure of unsecured PHI that compromises its security or privacy may constitute a reportable breach. This term is specific to the Breach Notification Rule and does not alter obligations under the Privacy Rule or the Security Rule; note that the Privacy Rule covers PHI in all forms (oral, paper, and electronic), while encryption-based securing methods are most relevant to electronic PHI. Practitioners should verify the current HHS-specified technologies and methodologies, as well as any additional obligations that may arise under the HITECH Act or applicable state law, against current regulatory guidance.

Why it matters

The concept of unsecured PHI sits at the heart of HIPAA's Breach Notification Rule because it determines whether a notification obligation is triggered at all. When an impermissible acquisition, access, use, or disclosure involves unsecured PHI and compromises its security or privacy, it may constitute a reportable breach requiring notification to affected individuals, HHS OCR, and in some cases the media. By contrast, PHI that has been rendered unusable, unreadable, or indecipherable through an HHS-recognized method such as encryption or destruction is generally outside the scope of these notification requirements. This is why securing PHI is often described as creating a functional safe harbor from breach notification.

For compliance teams, this distinction has significant practical and financial consequences. A lost laptop or misdirected file containing readable PHI can set off the full notification and reporting process, while the same loss involving properly encrypted data may not. It is important to understand that securing PHI addresses only the notification analysis under the Breach Notification Rule; it does not change an organization's underlying obligations under the Privacy Rule or the Security Rule, and it does not by itself guarantee compliance or prevent all breaches.

Organizations should also recognize that the securing methods that qualify are defined by HHS guidance and may be updated over time. Because the Privacy Rule covers PHI in all forms including oral and paper, while encryption is most relevant to electronic PHI, a securing strategy focused only on encryption may leave paper and other formats unaddressed. Practitioners should also account for potential additional obligations under the HITECH Act and applicable state breach notification laws, which may impose requirements beyond HIPAA.

Who it's relevant to

Privacy and Security Officers
These officers must know which PHI in their environment is secured according to current HHS guidance and which remains unsecured, since that classification directly shapes breach-response obligations. Because securing methods such as encryption are most relevant to electronic PHI, they should also confirm that oral and paper PHI are addressed through other safeguards, recognizing that securing PHI supports but does not by itself establish overall compliance.
Compliance and Breach Response Teams
When an incident occurs, these teams evaluate whether the PHI involved was unsecured as a threshold question in the breach risk assessment. A determination that PHI was properly secured under HHS-recognized methods may remove the incident from the Breach Notification Rule's notification requirements, so this analysis should be documented carefully and revisited against current HHS guidance.
Business Associates and Subcontractors
Entities handling PHI on behalf of covered entities may hold unsecured PHI and have their own responsibilities under business associate agreements and the Breach Notification Rule. Understanding what counts as securing PHI helps them assess whether an incident involving PHI in their custody may be reportable and how it should be communicated up the chain.
IT and Data Governance Staff
Technical teams implement the encryption and destruction practices that can render PHI secured within the meaning of the rule. They should verify that the methods they deploy align with current HHS-specified technologies and methodologies, and should not assume that securing PHI eliminates all breach risk or satisfies separate Security Rule and Privacy Rule obligations.

Inside Unsecured PHI

Definition Tied to Securing Methods
Unsecured PHI generally refers to protected health information that has not been rendered unusable, unreadable, or indecipherable to unauthorized persons through a technology or methodology specified by HHS guidance. The specific approved methods should be verified against current HHS guidance.
Encryption as a Securing Method
Encryption that meets the standards referenced in HHS guidance is one of the primary methods for rendering ePHI secured. Where PHI is properly encrypted consistent with that guidance, it typically falls outside the definition of unsecured PHI.
Destruction as a Securing Method
Destruction of PHI (for example, shredding paper records or clearing, purging, or destroying electronic media) consistent with HHS guidance is another recognized method for rendering PHI unusable, unreadable, or indecipherable.
Relationship to Breach Notification
The concept of unsecured PHI is significant primarily under the HIPAA Breach Notification Rule. Breach notification obligations generally attach to the acquisition, access, use, or disclosure of unsecured PHI; PHI that has been properly secured typically does not trigger the same notification requirements.
Applies Across All Forms of PHI
Unsecured PHI can include information in electronic, paper, or other forms, because the underlying PHI concept spans all media. The securing methodology relevant to a given item depends on its form.

Common questions

Answers to the questions practitioners most commonly ask about Unsecured PHI.

Does encryption automatically make PHI 'secured' and exempt from breach notification?
Not automatically. PHI is generally considered 'secured' only when it is rendered unusable, unreadable, or indecipherable to unauthorized persons through a method specified in HHS guidance, which typically points to encryption consistent with recognized standards and, for data destruction, specified destruction methods. Encryption that does not meet the applicable specifications, or where the decryption key has also been compromised, may not qualify. If PHI is properly secured under the applicable HHS guidance, a breach involving that data generally does not trigger the Breach Notification Rule's notification obligations. You should verify the current HHS guidance on securing PHI, because the recognized methods and standards are updated over time.
Is 'unsecured PHI' the same thing as PHI that has actually been breached?
No. 'Unsecured PHI' describes the status of the information itself, meaning PHI that has not been rendered unusable, unreadable, or indecipherable through an approved method. It does not mean a breach has occurred. A breach involves an impermissible acquisition, access, use, or disclosure under the Privacy Rule. The significance of the term is that breach notification obligations under the Breach Notification Rule generally apply only when the data involved is unsecured; if the PHI was properly secured, notification is generally not required even if an incident occurred. These are related but distinct concepts.
How do we determine whether the PHI we hold qualifies as secured or unsecured?
In general, you compare how the PHI is stored, transmitted, and destroyed against the methods identified in the applicable HHS guidance for rendering PHI unusable, unreadable, or indecipherable to unauthorized persons. This typically involves confirming that encryption meets the referenced standards and that destruction follows the specified approaches. PHI that does not meet those specifications is generally treated as unsecured. Because the guidance and referenced standards are updated over time, confirm the current version rather than relying on prior determinations. This is a factual and technical assessment that may warrant input from security and, where appropriate, legal personnel.
If a laptop containing encrypted PHI is lost, do we still have to notify?
It depends on the facts. If the PHI on the device was secured through encryption meeting the applicable HHS specifications and the decryption key was not also compromised, the data is generally considered secured, and the loss would typically not trigger notification obligations under the Breach Notification Rule. If the encryption did not meet the specifications, or if the key was accessible along with the device, the PHI may be treated as unsecured, and you would generally proceed to the breach risk assessment. Document your analysis and verify the encryption method against current HHS guidance.
Do our business associates need to account for unsecured PHI, and how does that flow through agreements?
Yes, in most cases. Business associates that create, receive, maintain, or transmit PHI on behalf of a covered entity generally have obligations related to unsecured PHI, and business associate agreements typically address breach notification responsibilities. Under the Breach Notification Rule, a business associate generally must notify the covered entity of a breach of unsecured PHI, and the specific timing and process are commonly defined in the agreement. Subcontractors of business associates generally carry down comparable obligations through their own agreements. Review your agreements to confirm how these responsibilities are allocated.
How does securing PHI relate to Security Rule safeguards and to the addressable encryption specification?
They are related but serve different functions. Encryption appears in the Security Rule as an addressable implementation specification for ePHI, and 'addressable' does not mean optional; it means an entity must assess whether the specification is reasonable and appropriate and, if not, implement an equivalent alternative or document why. Separately, rendering PHI secured for purposes of the Breach Notification Rule generally depends on meeting the encryption or destruction methods in HHS guidance. Implementing encryption that satisfies both the Security Rule analysis and the HHS securing guidance can support your overall program, but you should treat these as distinct requirements and verify each against current regulatory text and guidance.

Common misconceptions

If PHI is exposed but was encrypted, breach notification is always required.
Where PHI has been rendered unusable, unreadable, or indecipherable through encryption meeting the applicable HHS guidance, it generally is not considered unsecured PHI, and the standard breach notification obligations typically do not attach. Organizations should still confirm the encryption meets current guidance and evaluate the specific circumstances, as other analysis may apply.
Any security measure an organization adopts makes PHI 'secured' for these purposes.
Only technologies and methodologies specified in HHS guidance render PHI secured under the Breach Notification Rule. Access controls, passwords, or other safeguards may be good practice and may satisfy Security Rule obligations, but they do not by themselves make PHI 'secured' in a way that removes it from the unsecured PHI category. Verify against current HHS guidance.
Unsecured PHI only concerns electronic data.
Because PHI exists in multiple forms, unsecured PHI can include paper and other non-electronic records as well. The appropriate securing method (such as destruction) depends on the form of the information.

Best practices

Encrypt ePHI using methods consistent with current HHS guidance so that, where feasible, information is rendered secured and outside the definition of unsecured PHI; confirm the specific standards against the latest guidance.
Establish and follow documented destruction procedures for PHI in all forms, aligned with recognized HHS-specified methodologies for clearing, purging, destroying, or shredding.
Maintain an inventory of where PHI resides across electronic, paper, and other media so you can assess whether it is secured or unsecured if an incident occurs.
Verify the approved securing technologies and methodologies against current HHS guidance rather than assuming any internal safeguard qualifies.
Integrate the unsecured PHI analysis into your breach response and risk assessment process, since notification obligations generally turn on whether affected PHI was unsecured.
Consult current regulatory text and legal counsel, and consider that state law or other frameworks may impose additional requirements beyond the HIPAA Breach Notification Rule.