9.1 HIPAA Privacy Rule & Protected Health Information (PHI)

Key Takeaways

  • The HIPAA Privacy Rule establishes national standards to protect Protected Health Information (PHI) held or transmitted by Covered Entities and Business Associates.
  • Protected Health Information encompasses 18 specific individually identifiable data points across paper, oral, and electronic formats.
  • Covered Entities comprise healthcare providers who transmit electronic transactions, health plans, and healthcare clearinghouses.
  • Permitted uses and disclosures without patient authorization are restricted to Treatment, Payment, and Healthcare Operations (TPO) and specific public interest activities.
  • Data de-identification requires either the Safe Harbor method (removing all 18 identifiers) or the Expert Determination method (formal statistical risk analysis).
Last updated: August 2026

HIPAA Privacy Rule & Protected Health Information (PHI)

Overview of the HIPAA Privacy Rule

Enacted in 1996 and enforced by the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR), the Health Insurance Portability and Accountability Act (HIPAA) Privacy Rule established national standards to safeguard individuals' medical records and personal health information. The Privacy Rule balances individual privacy rights with the necessity of sharing health information to deliver high-quality patient care and ensure public health safety.

Covered Entities (CE)

HIPAA regulations apply directly to Covered Entities (CE) and, through statutory extensions under HITECH, their Business Associates (BA). Covered entities are divided into three primary categories:

Covered Entity CategoryStatutory DescriptionOperational Examples
Healthcare ProvidersAny provider of medical or health services that transmits health information electronically in connection with covered financial or administrative transactions.Physicians, hospitals, clinics, dentists, pharmacies, nursing homes, chiropractors.
Health PlansIndividual or group plans that provide or pay the cost of medical care.Commercial health insurers, HMOs, Medicare, Medicaid, employer-sponsored group health plans.
Healthcare ClearinghousesEntities that process non-standard health information received from another entity into a standard electronic format, or vice versa.Billing services, re-pricing agents, community health management information systems, value-added networks.

Protected Health Information (PHI) Defined

Protected Health Information (PHI) is defined as individually identifiable health information created, received, maintained, or transmitted by a covered entity or business associate in any form or media—whether electronic, paper, or oral. PHI relates to:

  1. The individual's past, present, or future physical or mental health condition.
  2. The provision of healthcare services to the individual.
  3. The past, present, or future payment for the provision of healthcare to the individual.

The 18 Specific PHI Identifiers

Under the HIPAA Privacy Rule, health information is considered individually identifiable if it contains any of the following 18 specific identifiers:

  1. Names (full name, last name, initial, nicknames).
  2. Geographic subdivisions smaller than a state (street address, city, county, precinct, ZIP code, and geocodes).
  3. All elements of dates (except year) directly related to an individual, including birth date, admission date, discharge date, date of death, and all ages over 89 (including year).
  4. Telephone numbers.
  5. Fax numbers.
  6. Email addresses.
  7. Social Security Numbers (SSN).
  8. Medical Record Numbers (MRN).
  9. Health plan beneficiary numbers.
  10. Account numbers.
  11. Certificate or license numbers.
  12. Vehicle identifiers and serial numbers, including license plate numbers.
  13. Device identifiers and serial numbers.
  14. Web Uniform Resource Locators (URLs).
  15. Internet Protocol (IP) addresses.
  16. Biometric identifiers, including finger and voice prints.
  17. Full-face photographs and any comparable images.
  18. Any other unique identifying number, characteristic, or code.

Permitted Uses & Disclosures: Treatment, Payment & Operations (TPO)

Covered entities are permitted to use and disclose PHI without obtaining a specific written patient authorization under one core operational framework known as TPO (Treatment, Payment, and Healthcare Operations):

  • Treatment: The provision, coordination, or management of healthcare and related services by one or more healthcare providers. Examples include physician consultations, specialty referrals, laboratory order transmissions, and inpatient handoffs.
  • Payment: Activities undertaken by a health plan or provider to obtain premiums or reimbursement for healthcare services. Examples include eligibility determinations, billing, claims management, medical necessity reviews, and utilization review.
  • Healthcare Operations: Administrative, financial, legal, and quality improvement activities necessary to run a healthcare facility. Examples include quality assessment, peer review, practitioner credentialing, auditing, legal defense, and EHR system maintenance.

Mandatory vs. Public Interest Disclosures

A covered entity must disclose PHI in two circumstances:

  1. Directly to the individual patient upon formal request.
  2. To the HHS Secretary / Office for Civil Rights (OCR) for compliance audits and enforcement investigations.

Disclosures permitted without authorization or opportunity to agree/object also extend to public interest and benefit activities, including public health surveillance (disease tracking), child abuse reporting, judicial proceedings (under court order), law enforcement requests, organ donation coordination, and coroner investigations.


Standards for De-Identification of PHI

Health information that has been properly de-identified is no longer considered PHI and falls outside HIPAA regulation. HIPAA specifies two legal methods to achieve de-identification:

De-Identification MethodTechnical RequirementsVerification & Documentation
Safe Harbor MethodRemoval of all 18 specified PHI identifiers of the individual, relatives, employers, and household members. The covered entity must have no actual knowledge that remaining information could be used alone or in combination with other data to identify the individual.Checklist verification confirming complete removal of all 18 identifiers and zero actual knowledge of re-identification capability.
Expert Determination MethodA qualified statistical/scientific expert applies accepted statistical principles to evaluate the risk of re-identification.Formal written determination signed by the expert documenting that the risk of re-identification is extremely small, detailing methods and analysis used.
Loading diagram...
HIPAA Privacy Rule: Covered Entities, PHI & De-Identification Workflow
Test Your Knowledge

Which of the following data points is classified as one of the 18 specific PHI identifiers under the HIPAA Privacy Rule?

A
B
C
D
Test Your Knowledge

To achieve de-identification under the Safe Harbor method, what requirement must a covered entity fulfill?

A
B
C
D
Test Your Knowledge

Which entity is classified as a Covered Entity under the HIPAA Privacy Rule?

A
B
C
D