Learn about HIPAA, ePHI, PHI and 18 identifiers, de-identified health information, who must comply, covered entities, business associates, and more, through the Frequently Asked Questions (FAQs) below. Please schedule a free consultation, if you are looking for experienced professionals to help you comply with HIPAA, conduct a HIPAA Security Analysis, and for other customized services.
Table of Contents
What is HIPAA?
HIPAA, the Health Insurance Portability and Accountability Act, is a U.S. federal law enacted in 1996 that establishes national standards to protect sensitive patient health information from unauthorized disclosure. It serves two primary purposes: protecting workers’ ability to retain health insurance coverage when changing or losing jobs and setting privacy and security requirements to improve the quality and efficiency of health information exchange. HIPAA has been significantly expanded through the HITECH Act in 2009 and the Omnibus Rule in 2013.
What does PHI (Protected Health Information) mean under HIPAA?
Protected Health Information, or PHI, is any individually identifiable health information held or transmitted by a covered entity or its business associate, in any form, electronic, paper, or oral. To qualify as PHI, the information must relate to an individual’s past, present, or future physical or mental health condition, the provision of healthcare, or payment for care. PHI includes diagnoses, lab results, treatment plans, billing records, insurance information, and clinical images. The defining characteristic is that the information must be linked, or reasonably linkable, to a specific individual.
What are the 18 identifiers that make health information “individually identifiable”?
HIPAA specifies 18 data elements whose presence makes health information individually identifiable and therefore protected as PHI. Removing all 18 is one of two approved methods for de-identifying health information under HIPAA. The 18 identifiers are:
- Names
- Geographic subdivisions smaller than a state, including street addresses, cities, counties, and ZIP codes
- All date elements, except year, directly related to an individual, including birthdates, admission and discharge dates, and dates of death; plus, all ages over 89 and any date elements that would reveal such age
- Phone numbers
- Fax numbers
- Email addresses
- Social Security numbers
- Medical record numbers
- Health plan beneficiary numbers
- Account numbers
- Certificate or license numbers
- Vehicle identifiers and serial numbers, including license plate numbers
- Device identifiers and serial numbers
- Web URLs
- IP addresses
- Biometric identifiers, including fingerprints and voiceprints
- Full-face photographs and comparable images
- Any other unique identifying number, characteristic, or code
What is de-identified health information under HIPAA?
De-identified health information is data from which all 18 HIPAA-specified personal identifiers have been removed, with no reasonable basis to believe the remaining information could re-identify an individual, and it is not subject to HIPAA’s privacy protections. HIPAA recognizes two de-identification methods: the Safe Harbor method, which requires removal of all 18 identifiers and confirmation that re-identification is not possible; and the Expert Determination method, in which a qualified statistician certifies that the re-identification risk is very small. Organizations commonly use de-identified data for research, public health reporting, and quality improvement activities.
What is ePHI, and how does it differ from PHI?
ePHI (electronic Protected Health Information) is any PHI created, stored, transmitted, or received in electronic form, including data in EHR systems, files on computers or servers, information sent via email, data in cloud environments, and information transmitted across networks. The distinction matters because HIPAA’s Security Rule applies specifically to ePHI, while the Privacy Rule covers PHI in all forms, electronic, paper, and oral. Physical records that are scanned become ePHI; electronic records that are printed become paper PHI. Organizations handling ePHI must implement administrative, physical, and technical safeguards in addition to their broader privacy obligations.
Who must comply with HIPAA?
HIPAA compliance is mandatory for covered entities and their business associates. Covered entities include health plans (insurance companies, HMOs, Medicare, Medicaid), healthcare clearinghouses, and healthcare providers, such as doctors, hospitals, clinics, dentists, pharmacies, and laboratories, that conduct certain transactions electronically. Business associates are individuals or organizations that perform services for covered entities involving access to PHI, and they are directly bound by HIPAA. The law’s reach is intentionally broad: compliance is required regardless of an organization’s size or budget, as long as PHI is created, received, maintained, or transmitted.
What is a Covered Entity under HIPAA?
A covered entity is one of three types of organizations directly regulated by HIPAA: (1) Health Plans , including health insurance companies, HMOs, and government programs such as Medicare and Medicaid; (2) Healthcare Clearinghouses , organizations that process nonstandard health data into standard electronic formats; and (3) Healthcare Providers , including physicians, hospitals, clinics, dentists, pharmacies, and nursing homes that transmit health information electronically in connection with covered transactions. Covered entities are bound by all HIPAA requirements for their own activities and must ensure that business associates they engage handle PHI appropriately.
What is a Business Associate under HIPAA?
A HIPAA business associate is any individual or organization that performs functions involving the use or disclosure of PHI on behalf of a covered entity or provides services that give it access to PHI. Business associates include billing companies, IT service providers, cloud storage vendors, EHR software companies, law firms, accountants, transcription services, and similar third parties. Since the HITECH Act of 2009 and the 2013 Omnibus Rule, business associates are directly liable for HIPAA compliance, not merely bound by contract. Subcontractors of business associates who handle PHI are treated as business associates in their own right and must comply with HIPAA accordingly.
Does HIPAA apply to schools, employers, or life insurers?
HIPAA does not apply to all organizations that handle health information. Schools generally maintain student health records under FERPA, not HIPAA. Employers maintaining employee health records in their capacity as employers, rather than as health plan sponsors, are generally not covered entities. Life insurance companies that do not provide health benefits are not covered entities, nor are most law enforcement agencies, state social services agencies, or workers’ compensation carriers. The determining factor is always whether an organization meets the definition of a covered entity or business associate under the HIPAA regulations.
Can patients share their own health information without HIPAA restrictions?
HIPAA regulates only covered entities and their business associates; it places no restrictions on what patients choose to do with their own health information. A patient may share their medical records, diagnoses, test results, or any other personal health data with anyone at their own discretion. HIPAA also allows patients to direct covered entities to transmit their PHI electronically to third parties of the patient’s choosing. However, once PHI leaves a HIPAA-regulated entity and is held by a non-regulated party, such as a consumer wellness app the patient uses independently, that party is generally not bound by HIPAA. Many consumer health apps, fitness trackers, and wellness platforms are not covered entities and are regulated, if at all, only by the FTC’s prohibition on unfair or deceptive practices.
Does HIPAA allow healthcare providers to share information with a patient’s family?
The HIPAA Privacy Rule explicitly permits covered healthcare providers to share PHI with a patient’s family members, close friends, or others involved in the patient’s care or payment, without written authorization, provided the patient has not objected and the provider exercises professional judgment that disclosure is appropriate. HIPAA is designed to support care, not obstruct it. When a patient is present and has decision-making capacity, a provider may share relevant information with family members unless the patient objects. When a patient is incapacitated, for example, during surgery or in an emergency, the provider may share information consistent with the patient’s known preferences, or that appears to be in the patient’s best interest. OCR has confirmed that written patient consent is not required before sharing care-relevant information with involved family members.
When does state law override HIPAA?
State laws that are more protective of individual privacy rights than HIPAA are not preempted , they remain in full force, and covered entities must comply with the stricter of the two standards. Under HIPAA’s preemption provisions (45 CFR § 160.203), a state law is “more protective” if it provides greater privacy protection or greater rights to individuals with respect to their PHI. In practice, this means covered entities operating in states with strong health privacy laws face significantly more stringent requirements than HIPAA alone imposes.
Areas where state law commonly exceeds HIPAA include mental health and psychiatric records; HIV and AIDS status; genetic information; substance use disorder records; reproductive health information (with significant variation post-Dobbs, and some states enacting stronger protections); and minor consent laws that determine when minors have independent privacy rights. A covered entity may not use HIPAA as justification for disclosing information when state law prohibits that disclosure. Conversely, state laws that would require disclosure that HIPAA prohibits are generally preempted by HIPAA.
Explore Blogs, Webinars and other Resources
Trusted by Reputed Companies
What Our Clients Say
We used databrackets (formerly EHR 2.0) in our small medical practice for our risk analysis assessment to be in compliance with meaningful use. Their response was fast, the final report is detailed but simple and easy to follow. They were always available to answer our questions.
E. Compres
Pulmonary and Sleep Center of the Valley
I never miss the opportunity to learn something new …that’s why I am always registering to all free seminars offered on the web. databrackets (formerly EHR 2.0) happened to be the friendliest, comprehensive and up-to- date source of HIPAA Privacy and Security updates.
Alexandra V.
Community Healthcare Network
Today’s presentation was great! Thank you for sending the slides. My only feedback is that it would be fabulous to have the slides ahead of time so I could print them and take notes on the slides.Thanks for your time and knowledge today!
T.B., PM
Community Health Network
Particularly interesting was the flow chart on Administrative Simplification. I utilize all of the Security subcategories you list under the Security tile and appreciate knowing that I am hitting all of the relevant topics during my employee training.
Jessica B.
JD, CHC
I have re-worked our original risk assessment….We are using databrackets' (formerly EHR 2.0) Meaningful Use Security Risk Analysis Toolkit and it meets our needs. It was easy to use and I believe that it very beneficial to our meeting meaningful use.
Bill Curtis
Neurosurgical Associates Of Texarkana, TX
Information (webinars) presented by databrackets (formerly EHR 2.0) highlights some of today’s most demanding healthcare topics. The webinars help to direct those operating in today’s rapidly changing environment in the right direction.
Candace M.
Privacy and Security Officer, Springhill Medical Center
Our Growing List of Credentials
0
+
Assessments
0
+
Clients
0
+
Assessment Libraries
0
+
Years of Experience
0
+
No. of Staff Trained
0
+
HIPAA
0
+
SOC 2 Readiness
0
+
Pen Testing
0
+
ISO 27001 Certifications
0
+
Dollars Saved in Compliance Penalties