Glossary

PHI (protected health information)

Health information that can identify a person and is held or shared by a HIPAA covered entity or its business associate.

What is PHI (protected health information)?

Protected health information, or PHI, is a HIPAA term for health information that can identify a person and is created, held or shared by a covered entity or business associate. It covers information about a person's health, the care they receive and payment for that care.

PHI can be on paper, spoken or electronic. Electronic PHI is often called ePHI, and the HIPAA Security Rule applies to it specifically.

Examples in a lab

  • A test result together with the patient's name.
  • A requisition with a date of birth and the tests ordered.
  • A specimen label, an invoice for a test, or an email that names the test.

Information stops being PHI once it is properly de-identified, for example by removing the 18 identifiers listed in HIPAA's Safe Harbor method, such as names, dates tied to a person, phone numbers and record numbers.

In the UK and Canada, the matching ideas are personal data and personal health information under local laws.

This is a plain-language summary for general information, not legal advice. Check the current rules with a qualified adviser for your lab.

How Lab Desk handles it

Lab Desk keeps PHI out of places it does not need to be: result emails carry only a generic notice and a secure link, and Stripe payments carry only an invoice number and amount. See security.

Related terms

  • HIPAA: The US law that sets national rules for protecting the privacy and security of health information.
  • BAA (business associate agreement): A contract HIPAA requires between a covered entity and a vendor that handles its protected health information.
  • PIPEDA: Canada's federal privacy law for how private-sector organizations collect, use and share personal information.

Manage patients. Share results. Get paid. All from one desk.

Join early access and be one of the first labs on Lab Desk.