Honest Taskers
About UsOur StoryWhy UsVisionPricing
Apply
Book Discovery Call
Honest TaskersMenu
Book Discovery Call
Services
Multi-Purpose Virtual Medical Assistant
Virtual Medical Scribe
Virtual Medical Receptionist
Virtual Dental Receptionist
Virtual Medical Biller
Virtual Mental Health Assistant
Remote Patient Monitoring Assistant
Telehealth Medical Assistant
Virtual Medical Coder
Telephone Triage Medical Assistant
Virtual Patient Care Coordinator
Remote MDS Coordinator
Remote Clinical Chat Auditor
Virtual Dental Assistant
About Us
Our Story
Why Us
Vision
Values
Pricing
Apply NOW
Honest Taskers
Instagram iconFacebook iconTikTok iconLinkedIn iconTwitter icon
about us:
Our Story
Team
Mission
Vision
Values
Services
services:
Virtual Medical Receptionist
Virtual Medical Scribe
Virtual Medical Biller
Virtual Medical Coder
Virtual MDS Coordinator
Virtual Mental Health Assistant
Remote Patient Monitoring Assistant
Telehealth Medical Assistant
Telephone Triage Medical Assistant
Virtual Dental Assistant
resources:
Contact Us
Articles
Blog
FAQs
Fulfillment Policy
Schedule Discovery Call
Schedule
Join our Team: Apply NOW
Call
817 420-7608
Terms of service
Privacy
What Counts as Protected Health Information (PHI)?
Home
>
Articles
>
What Counts as Protected Health Information (PHI)?
What Counts as Protected Health Information (PHI)?
Practice Operations
Staffing & Turnover

What Counts as Protected Health Information (PHI)?

Share this article:
Contents

    What Counts as Protected Health Information (PHI)?

    Last updated: 2026-09-21

    Protected health information is individually identifiable health information a covered entity or business associate creates, receives, or holds in a designated record set, from a patient's name and diagnosis to any of the 18 identifiers in the HIPAA Privacy Rule.

    Every practice that touches a patient record runs into the same question sooner or later, and getting it wrong is what turns a small slip into a reportable breach. What counts as protected health information starts with a plain definition, and it's both narrower and broader than most front-desk staff assume. The 18 identifiers named in the HIPAA Privacy Rule are the checklist that settles whether a single data point is protected, so we lay out all 18. Health information doesn't stay protected forever, and knowing when it stops being protected health information, through de-identification, keeps a team from over-locking data that's already safe to share. The difference between PHI and ePHI comes next, because the form the data takes decides which safeguards apply. Who has to protect health information under HIPAA falls to covered entities and their business associates, so that duty matters before anyone signs a contract. How a virtual assistant handles protected health information safely is the practical question for remote assistants working inside the chart. What happens when protected health information is exposed carries consequences worth weighing before they arrive. Where these protected health information facts come from closes the piece.

    What counts as protected health information?

    Protected health information is any individually identifiable health information a covered entity or business associate creates, receives, maintains, or transmits. Two conditions have to hold at the same time. The information has to identify a person, or give a reasonable basis to identify them, and it has to relate to their health, their care, or payment for that care. Drop either condition and the data falls outside the definition.

    Health itself reaches wider than a diagnosis. It covers a physical or mental condition, the care a person received, and the payment side of that care, whether past, present, or future. A patient's outstanding balance is health information. So is the bare fact that someone is a patient at a cardiology practice at all.

    Format changes nothing. A sticky note, a voicemail, a fax, a chart entry, and one line in a billing spreadsheet all count when they meet both conditions. The files a practice uses to make decisions about a patient are what the Privacy Rule calls a designated record set, and that is where most protected health information lives day to day.

    Not everything in a practice's files is protected, though, and the edges are where people trip. Employment records a practice keeps as an employer, and student health records covered by education law, sit outside the definition even when they mention a condition. Information with every identifier already removed sits outside it too. That test never moves. Can this point to a person, and does it touch their health, their care, or the payment for it? When both answers are yes, it's protected, and how boring or how sensitive the field feels has nothing to do with the result.

    What are the 18 identifiers that make data protected health information?

    Eighteen identifiers make health information protected under the HIPAA Safe Harbor method, and any single one of them is enough to tie a record back to a person. The Department of Health and Human Services lists them in the Privacy Rule at 45 CFR 164.514 (Source: US Department of Health and Human Services, 2026), where they read as a working checklist rather than legal theory.

    The 18 identifiers under the HIPAA Safe Harbor method
    Identifier Everyday example
    NamesA patient's first and last name
    Geographic subdivisions smaller than a stateStreet address, city, county, and most ZIP codes
    Dates tied to a person, except the year, and any age over 89Date of birth, admission date, age 91
    Telephone numbersA home or mobile number
    Fax numbersA practice fax line
    Email addressesA patient's personal inbox
    Social Security numbersA nine-digit SSN
    Medical record numbersThe chart's MRN
    Health plan beneficiary numbersA member ID on an insurance card
    Account numbersA billing account number
    Certificate or license numbersA driver's license number
    Vehicle identifiersA license plate or VIN
    Device identifiers and serial numbersA pacemaker serial number
    Web URLsA personal health page address
    IP addressesA home device's IP address
    Biometric identifiersFingerprints and voiceprints
    Full-face photographs and comparable imagesA clinical facial photo
    Any other unique identifying number, characteristic, or codeAn internal patient code

    That last catch-all is the one people forget. A code a practice invents to label its own patients still counts when it can be traced back to them, so a clever internal shorthand doesn't move the data outside the rule. This list applies whether a record is electronic or on paper, and it treats a ZIP code and a full-face photo as equals, because each one can lead back to a single person. Read alongside the two-condition test, the 18 turn a vague worry about privacy into something a front-desk staffer can check field by field.

    When does health information stop being protected health information?

    Health information stops being protected health information when it's de-identified, so it no longer identifies a person and gives no reasonable basis to do so. Two methods reach that point under the Privacy Rule. Safe Harbor removes all 18 identifiers and requires that the practice hold no actual knowledge the leftover data could still single someone out. Expert Determination has a qualified statistician document that the risk of re-identification is minimal.

    Practices reach for de-identification when they want to use records for something beyond treatment, payment, or day-to-day operations, such as sharing a data set with a researcher or handing figures to a vendor building a dashboard. Done correctly, de-identified data leaves HIPAA's reach entirely, and that is the whole appeal. Do it loosely, and it's still PHI in a thin disguise, so the practice keeps every obligation it thought it had shed. A limited data set is the middle path, with direct identifiers pulled but some dates and geography kept, and it stays protected under a data use agreement.

    De-identification isn't a formatting step, and this is the limitation worth naming plainly. One stray identifier keeps the whole record protected, and free-text notes are where they hide, a referring doctor's name, a rare diagnosis, a hometown dropped into a comment field. A date of service left in a spreadsheet quietly undoes the rest of the work. Aggregate counts are normally safe, though a cell showing one patient in a small ZIP code can re-identify that person by itself. When staff aren't sure, the honest default is to treat the record as still protected.

    What is the difference between PHI and ePHI?

    The difference between PHI and ePHI is the medium, not the meaning. ePHI is protected health information held or moved in electronic form, and that's the whole of the distinction. A printed chart and its scanned copy carry identical information, yet only the scan is ePHI.

    Why the split matters is that a different rule governs each half. HIPAA's Privacy Rule covers protected health information in any form, paper and spoken included. Its Security Rule applies only to ePHI and calls for three kinds of safeguards, administrative, physical, and technical, such as access controls, encryption, and audit logs. A fax sitting in a tray is PHI a practice still has to protect, but it doesn't trip the Security Rule the way an email attachment does.

    How PHI and ePHI differ under HIPAA
    Question PHI ePHI
    What form Any form, including paper, spoken, and electronic Electronic only, such as EHR entries, email, and files
    Which rule HIPAA Privacy Rule Privacy Rule plus the Security Rule
    Core safeguards Use and disclosure limits, minimum necessary Administrative, physical, and technical controls
    Everyday example A signed intake form in a folder The same form scanned into the chart

    For a remote team, this line is where most of the daily work sits, because nearly everything a virtual hire touches is already electronic. Practices weighing that setup start by asking whether offshore virtual assistants can access PHI at all, and the answer turns on the safeguards around the ePHI, not on where the worker sits.

    Who has to protect health information under HIPAA?

    Covered entities and their business associates have to protect health information under HIPAA. A covered entity is a health care provider that bills electronically, a health plan, or a health care clearinghouse. In plain terms that's the doctor's office, the dental practice, the insurer, and the billing service that shuttles claims between them.

    A business associate is any outside party that handles protected health information on a covered entity's behalf, from a cloud EHR vendor to a transcription service to a remote staffing company whose people work inside the chart. That duty follows the data. Once a vendor touches PHI, HIPAA reaches it too, and a signed Business Associate Agreement puts that duty in writing.

    The agreement names what the business associate may do with the information, holds it to the same safeguards the covered entity owes, and sets out breach reporting back to the practice. Skipping it is a common early mistake with any remote hire. Before a practice grants system access, it helps to know exactly what a business associate agreement is and what it commits each side to do.

    The chain doesn't stop at the first vendor either. A business associate that passes PHI to its own subcontractor has to bind that subcontractor with an agreement of the same weight, so protection follows the data all the way down. For a practice, the practical read is short. Anyone who can see the chart, in-house or outside, sits somewhere in this structure, and a name missing from it is a gap worth closing before anyone logs in.

    How does a virtual assistant handle protected health information safely?

    A virtual assistant handles protected health information safely by working under the same safeguards HIPAA asks of any employee, backed by training, a signed agreement, and a controlled work setup. Location doesn't change the standard. The safeguards do.

    Honest Taskers builds this around a handful of concrete practices. Its virtual healthcare assistants are HIPAA-trained, with quarterly HIPAA and data privacy training led by a dedicated compliance officer. A Business Associate Agreement gets signed when a professional will access PHI. Remote work screening covers a dedicated, password-protected work computer, a minimum internet connection with a backup, power backup, and a private workspace. Its HIPAA compliance is verified by Accountable, an outside compliance platform, and it describes its own security environment as SOC 2 audit ready.

    Scope is a safeguard in its own right. Honest Taskers staff do administrative and clinically adjacent work, never clinical advice or clinical decisions, which keeps the PHI they touch tied to scheduling, billing, and records rather than to judgment about care. Your practice still decides which systems the hire can open, and it can revoke that access in an afternoon. What a candidate should meet on compliance is set out in our explainer on whether a virtual assistant can be HIPAA compliant.

    The people behind the safeguards matter as much as the paperwork does. Honest Taskers recruits in the Philippines, Latin America, India, and Pakistan, and its virtual healthcare assistants work the client's US time zone and approved schedule, so the person handling PHI is at a desk while the practice and its payers are open. Rates run $10.00 to $12.65 an hour depending on the role, candidate background, schedule, and location, and new clients may receive a two-week working trial with their first selected professional. The company reports 99.6% average monthly retention, and on a compliance-sensitive role that number earns its keep, because the same trained person keeps handling the same records instead of a rotating cast relearning the access rules every few months.

    What happens when protected health information is exposed?

    When protected health information is exposed, the covered entity has to investigate what happened, notify the people affected, and report the breach, and it can face enforcement action from federal regulators. The Breach Notification Rule sets that sequence in motion. A business associate that caused the exposure has to report it back to the covered entity, which is one more reason the agreement between them matters.

    Notice isn't optional, and it isn't quiet. Affected individuals get written notice, the Department of Health and Human Services gets notified, and a large enough breach draws media notification and a public listing. Penalties rise with how careless the conduct was, from an honest accident up to willful neglect left uncorrected. We're keeping this qualitative on purpose, because specific fine amounts and breach counts shift from year to year and no figure in our sources is current enough to publish here.

    The honest limitation is that no safeguard reduces exposure risk to zero. Training, agreements, and access controls lower the odds and shrink the fallout, but a determined mistake still slips through. That's why the response plan earns its keep as much as the prevention does. A practical place to start is a remote staff HIPAA compliance checklist that names who does what before any access is granted.

    Where do these protected health information facts come from?

    The definition of protected health information, the 18 identifiers, the Safe Harbor and Expert Determination methods, the covered-entity and business-associate categories, and the breach-notification duty all come from the HIPAA Privacy and Security Rules published by the Department of Health and Human Services, including the de-identification standard at 45 CFR 164.514. Those rules trace to the US Department of Health and Human Services, whose "HIPAA Privacy Rule" defines protected health information and names its 18 identifiers, while its companion "HIPAA Security Rule" sets the safeguards that apply to ePHI (Source: US Department of Health and Human Services, 2026). Honest Taskers rates, recruiting geography, training cadence, Business Associate Agreement practice, remote work screening, and security posture come from the company's own published service terms, and its HIPAA compliance verification comes from Accountable, the outside platform named above. No breach statistic, fine amount, or penalty figure appears here, because none in our sources was current enough to state responsibly, and a stale number on a compliance page does more harm than leaving it out.

    Practices weighing an overseas hire worry less about the definition of protected health information and more about who's allowed near it. Distance feels like exposure, even when the safeguards travel with the data rather than the worker. That worry deserves a straight answer instead of reassurance, so our piece on whether offshore virtual assistants can access PHI walks through what the law allows, what a Business Associate Agreement has to cover, and where a practice keeps control of system access no matter where the hire sits.

    Speak with Honest Taskers about building a remote healthcare support team.

    Frequently Asked Questions
    What counts as protected health information?▼
    Is a patient's name on its own protected health information?▼
    What is the difference between PHI and ePHI?▼
    When does health information stop being protected?▼
    Can a virtual assistant handle protected health information?▼
    What happens when protected health information is exposed?▼
    Share this article:
    Sponsored
    No banner available for this post.