PHI and ePHI
Individually identifiable health information (PHI) and its electronic form (ePHI) - the data class HIPAA protects.
Definition
Protected Health Information (PHI) is individually identifiable health information held or transmitted by a HIPAA Covered Entity or Business Associate, in any form. Electronic PHI (ePHI) is PHI in electronic media. PHI includes the 18 HIPAA identifiers (names, dates, geographic subdivisions smaller than state, contact info, SSNs, MRNs, biometric identifiers, and more) when linked to health information.What this means in practice
MedTech architects should map every data field in the device and back-end against the 18 identifiers and design data flows to minimize PHI surface area. Common patterns: de-identify telemetry at source, segregate identified-data services, encrypt every PHI store, and log every PHI access.- •Treating MAC addresses or device serial numbers as non-identifying - they can re-identify when linked to other data.
- •Pseudonymizing PHI and calling it de-identified - pseudonymization is not de-identification under HIPAA.
Frequently asked questions
Related terms
Grouped by themeEditor's picks
· Hand-selected related conceptsThe HIPAA-defined process of removing identifiers from PHI so the resulting data is no longer subject to the Privacy Rule.
U.S. federal law governing the privacy and security of protected health information.
U.S. law that strengthened HIPAA enforcement and introduced breach-notification requirements.
More in Cybersecurity
· Same categoryAAMI/ANSI standard establishing requirements for medical-device cybersecurity activities throughout the lifecycle.
AAMI Technical Information Report providing MedTech-specific guidance on cybersecurity risk management.
AAMI Technical Information Report on post-market security risk management for medical device manufacturers, the operational companion to TIR57.
Unauthorized remote control of an implanted neurostimulator (e.g., DBS) to alter stimulation parameters and harm a patient.
Where this term appears across MedTech Terms.
Primary references
3 sources- 1
HHS Guidance: De-Identification of PHIVerifiedHHS OCRhhs.gov
- 2
HHS HIPAA for ProfessionalsVerifiedHHS OCRhhs.gov
- 3
FDA - Cybersecurity for Medical DevicesVerifiedFDAfda.gov
Inline markers like [1] jump to the matching reference above.