Velant is live → Cut healthcare lead response time to under 30 seconds. See how

Definition

What is PHI (Protected Health Information)?

Any individually identifiable health information held or transmitted by a covered entity or business associate — including name, DOB, address linked to a health condition, treatment, or payment.

The full definition

Under HIPAA, PHI is any health-related information that can be tied to a specific individual. The 18 HIPAA identifiers include name, geographic data, dates (DOB, admission, discharge), phone, email, SSN, medical record number, health plan number, account numbers, license numbers, vehicle identifiers, device serial numbers, URLs, IP addresses, biometrics, photos, and any other unique identifier. PHI requires HIPAA's privacy and security safeguards.

Why it matters in practice

The mistake practices make: they treat names and DOBs as 'not really PHI' since they're not clinical. Under HIPAA, name + the fact of being a patient is PHI. A marketing form that captures 'I'm interested in your IOP program — my name is John Smith, my phone is X' is PHI. The CRM holding that data needs to be HIPAA-aligned with a BAA.

Real-world examples

  • Name and phone number on an intake form for behavioral health services
  • Appointment confirmation SMS that includes the patient's name and the provider's specialty
  • Insurance card photo uploaded during patient registration

Inside Velant

Velant treats every data point in the system as potential PHI — encrypted in transit and at rest, role-based access, audit logged.

Related terms

See PHI (Protected Health Information) in action — inside Velant

Book a 20-minute walkthrough and we'll show you the workflow end to end.