---
title: "PHI and ePHI, Definition | MedTech Terms"
description: "Individually identifiable health information (PHI) and its electronic form (ePHI) - the data class HIPAA protects."
lang: en
json-ld: |
  {
    "@context": "https://schema.org",
    "@graph": [
      {
        "@type": "DefinedTerm",
        "@id": "https://medtechterms.com/terms/phi-ephi#term",
        "name": "PHI and ePHI",
        "alternateName": [
          "Protected Health Information",
          "electronic Protected Health Information"
        ],
        "description": "Protected Health Information (PHI) is individually identifiable health information held or transmitted by a HIPAA Covered Entity or Business Associate, in any form. Electronic PHI (ePHI) is PHI in electronic media. PHI includes the 18 HIPAA identifiers (names, dates, geographic subdivisions smaller than state, contact info, SSNs, MRNs, biometric identifiers, and more) when linked to health information.",
        "url": "https://medtechterms.com/terms/phi-ephi",
        "termCode": "phi-ephi",
        "inDefinedTermSet": {
          "@type": "DefinedTermSet",
          "name": "MedTech Terms",
          "url": "https://medtechterms.com/terms"
        }
      },
      {
        "@type": "Article",
        "@id": "https://medtechterms.com/terms/phi-ephi#article",
        "headline": "PHI and ePHI",
        "description": "Individually identifiable health information (PHI) and its electronic form (ePHI) - the data class HIPAA protects.",
        "url": "https://medtechterms.com/terms/phi-ephi",
        "mainEntityOfPage": {
          "@type": "WebPage",
          "@id": "https://medtechterms.com/terms/phi-ephi"
        },
        "about": {
          "@id": "https://medtechterms.com/terms/phi-ephi#term"
        },
        "articleSection": "Cybersecurity",
        "inLanguage": "en",
        "keywords": "PHI and ePHI, Protected Health Information, electronic Protected Health Information, Cybersecurity, medical device, MedTech",
        "author": {
          "@type": "Person",
          "name": "Christian Espinosa",
          "jobTitle": "Founder, Blue Goat Cyber",
          "url": "https://bluegoatcyber.com"
        },
        "publisher": {
          "@type": "Organization",
          "name": "MedTech Terms",
          "url": "https://medtechterms.com"
        },
        "isPartOf": {
          "@type": "WebSite",
          "name": "MedTech Terms",
          "url": "https://medtechterms.com"
        },
        "datePublished": "2026-05-05",
        "dateModified": "2026-05-05",
        "citation": [
          {
            "@type": "CreativeWork",
            "name": "HHS Guidance: De-Identification of PHI",
            "url": "https://www.hhs.gov/hipaa/for-professionals/privacy/special-topics/de-identification/index.html",
            "publisher": {
              "@type": "Organization",
              "name": "HHS OCR"
            }
          },
          {
            "@type": "CreativeWork",
            "name": "HHS HIPAA for Professionals",
            "url": "https://www.hhs.gov/hipaa/for-professionals/index.html",
            "publisher": {
              "@type": "Organization",
              "name": "HHS OCR"
            }
          },
          {
            "@type": "CreativeWork",
            "name": "FDA - Cybersecurity for Medical Devices",
            "url": "https://www.fda.gov/medical-devices/digital-health-center-excellence/cybersecurity",
            "publisher": {
              "@type": "Organization",
              "name": "FDA"
            }
          }
        ],
        "mentions": [
          {
            "@type": "DefinedTerm",
            "@id": "https://medtechterms.com/terms/hipaa#term",
            "name": "HIPAA",
            "alternateName": "HIPAA",
            "url": "https://medtechterms.com/terms/hipaa"
          },
          {
            "@type": "DefinedTerm",
            "@id": "https://medtechterms.com/terms/de-identification#term",
            "name": "De-Identification of Health Data",
            "url": "https://medtechterms.com/terms/de-identification"
          },
          {
            "@type": "DefinedTerm",
            "@id": "https://medtechterms.com/terms/hitech-act#term",
            "name": "HITECH Act",
            "alternateName": "HITECH",
            "url": "https://medtechterms.com/terms/hitech-act"
          }
        ]
      },
      {
        "@type": "BreadcrumbList",
        "itemListElement": [
          {
            "@type": "ListItem",
            "position": 1,
            "name": "Home",
            "item": "https://medtechterms.com/"
          },
          {
            "@type": "ListItem",
            "position": 2,
            "name": "Terms",
            "item": "https://medtechterms.com/terms"
          },
          {
            "@type": "ListItem",
            "position": 3,
            "name": "Cybersecurity",
            "item": "https://medtechterms.com/terms?cat=Cybersecurity"
          },
          {
            "@type": "ListItem",
            "position": 4,
            "name": "PHI and ePHI",
            "item": "https://medtechterms.com/terms/phi-ephi"
          }
        ]
      },
      {
        "@type": "FAQPage",
        "@id": "https://medtechterms.com/terms/phi-ephi#faq",
        "mainEntity": [
          {
            "@type": "Question",
            "name": "Is a device serial number PHI?",
            "acceptedAnswer": {
              "@type": "Answer",
              "text": "By itself, no. Combined with health information about the patient using that device, it can re-identify and become PHI."
            }
          },
          {
            "@type": "Question",
            "name": "Does encrypted ePHI still count as PHI?",
            "acceptedAnswer": {
              "@type": "Answer",
              "text": "Yes - encryption protects against unauthorized access but does not remove HIPAA status. Encryption does, however, provide Safe Harbor against the Breach Notification Rule for lost/stolen media."
            }
          }
        ]
      }
    ]
  }
---

[

MedTech Terms

The authoritative reference



](/)

Browse

Learn

[Latest](/latest)

About

1.  [Home](/)
2.  /
3.  [Terms](/terms)
4.  /
5.  [Cybersecurity](/terms?cat=Cybersecurity)
6.  /
7.  PHI and ePHI

[All terms](/terms)

Cybersecurity [Connected & Cyber-Physical Devices](/ecosystems/connected-devices)

# PHI and ePHI

Individually identifiable health information (PHI) and its electronic form (ePHI) - the data class HIPAA protects.

Reviewed by [Christian Espinosa, Founder, Blue Goat Cyber](/authors/christian-espinosa) Last reviewed May 5, 2026 

## Definition

Protected Health Information (PHI) is individually identifiable health information held or transmitted by a  [HIPAA](/terms/hipaa) Covered Entity or Business Associate, in any form. Electronic PHI (ePHI) is PHI in electronic media. PHI includes the 18 HIPAA identifiers (names, dates, geographic subdivisions smaller than state, contact info, SSNs, MRNs, biometric identifiers, and more) when linked to health information. 

What the regulation says

The  [HIPAA](/terms/hipaa) Privacy Rule governs use and disclosure of PHI; the Security Rule governs the technical/administrative/physical safeguards for ePHI. HHS OCR enforces both. De-identification under the  [Safe](/terms/safe-note) Harbor standard (removal of all 18 identifiers) or Expert Determination removes data from PHI status. 

## What this means in practice

MedTech architects should map every data field in the device and back-end against the 18 identifiers and design data flows to minimize PHI surface area. Common patterns: de-identify telemetry at source, segregate identified-data services, encrypt every PHI store, and log every PHI access. 

Common pitfalls

-   • Treating MAC addresses or device serial numbers as non-identifying - they can re-identify when linked to other data. 
-   • Pseudonymizing PHI and calling it de-identified - pseudonymization is not de-identification under HIPAA. 

## Frequently asked questions

Is a device serial number PHI? 

By itself, no. Combined with health information about the patient using that device, it can re-identify and become PHI. 

Does encrypted ePHI still count as PHI? 

## Related terms

Grouped by theme 

### Editor's picks

· Hand-selected related concepts 

[

Cybersecurity

De-Identification of Health Data

The HIPAA-defined process of removing identifiers from PHI so the resulting data is no longer subject to the Privacy Rule.





](/terms/de-identification)[

Cybersecurity

HIPAA(HIPAA) 

U.S. federal law governing the privacy and security of protected health information.





](/terms/hipaa)[

Cybersecurity

HITECH Act(HITECH) 

U.S. law that strengthened HIPAA enforcement and introduced breach-notification requirements.





](/terms/hitech-act)

### More in Cybersecurity

· Same category 

[

Cybersecurity

AAMI SW96

AAMI/ANSI standard establishing requirements for medical-device cybersecurity activities throughout the lifecycle.





](/terms/aami-sw96)[

Cybersecurity

AAMI TIR57

AAMI Technical Information Report providing MedTech-specific guidance on cybersecurity risk management.





](/terms/aami-tir57)[

Cybersecurity

AAMI TIR97(TIR97) 

AAMI Technical Information Report on post-market security risk management for medical device manufacturers, the operational companion to TIR57.





](/terms/aami-tir97)[

Cybersecurity

Brainjacking

Unauthorized remote control of an implanted neurostimulator (e.g., DBS) to alter stimulation parameters and harm a patient.





](/terms/brainjacking)

Cited by

Where this term appears across MedTech Terms.

Ecosystems (1)

-   [Connected & Cyber-Physical Devices](/ecosystems/connected-devices)

## Primary references

3 sources 

Link health:  3 verified · last checked 2026-06-20 

HHS OCR· 2 FDA· 1 

1.  [1 
    
    HHS Guidance: De-Identification of PHI
    
    Verified 
    
    HHS OCR · hhs.gov 
    
    
    
    ](https://www.hhs.gov/hipaa/for-professionals/privacy/special-topics/de-identification/index.html)
2.  [2 
    
    HHS HIPAA for Professionals
    
    Verified 
    
    HHS OCR · hhs.gov 
    
    
    
    ](https://www.hhs.gov/hipaa/for-professionals/index.html)
3.  [3 
    
    FDA - Cybersecurity for Medical Devices
    
    Verified 
    
    FDA · fda.gov 
    
    
    
    ](https://www.fda.gov/medical-devices/digital-health-center-excellence/cybersecurity)

Inline markers like \[1\]  jump to the matching reference above.

Sponsor note

### Working on medical device cybersecurity?

Blue Goat Cyber specializes in MedTech cybersecurity - threat modeling, SBOMs, penetration testing, and FDA premarket submissions.

[Book a 30-minute discovery session](https://go.bluegoatcyber.com/meetings/blue-goat-cyber/discovery-session)

-   No obligation
-   Expert-led from minute one
-   NDA available on request

MedTech Terms is a community resource sponsored by [Blue Goat Cyber](https://bluegoatcyber.com). Definitions are independent of any vendor.

On this term

Category

Cybersecurity

Sources

3

Updated

5/5/2026

[Compare with another term](/compare?a=phi-ephi)

Learn in 60 seconds

Card Lesson Quiz

Individually identifiable health information (PHI) and its electronic form (ePHI) - the data class HIPAA protects.

-   · MedTech architects should map every data field in the device and back-end against the 18 identifiers and design data flows to minimize PHI surface area. 
-   · Common patterns: de-identify telemetry at source, segregate identified-data services, encrypt every PHI store, and log every PHI access. 
-   · Electronic PHI (ePHI) is PHI in electronic media. 

Remember this

Watch out: Treating MAC addresses or device serial numbers as non-identifying - they can re-identify when linked to other data.

Related terms

-   [HIPAA(HIPAA) ](/terms/hipaa)
-   [De-Identification of Health Data ](/terms/de-identification)
-   [HITECH Act(HITECH) ](/terms/hitech-act)

You may also need

Auto-suggested from Cybersecurity and shared keywords.

-   [HITRUST CSF(HITRUST) ](/terms/hitrust)
-   [LINDDUN ](/terms/linddun)
-   [Brainjacking ](/terms/brainjacking)
-   [Health Information Sharing and Analysis Center(H-ISAC) ](/terms/h-isac)
-   [Healthcare and Public Health Cybersecurity Performance Goals(HPH-CPG) ](/terms/hph-cpg)
-   [Manufacturer Disclosure Statement for Medical Device Security(MDS2) ](/terms/mds2)

[All Cybersecurity terms](/terms?cat=Cybersecurity)

From the Blue Goat network

Related resources and services on this topic.

-   [
    
    MedTech Cybersecurity Standards 
    
    Authoritative reference for the standards and guidances behind medical device cybersecurity.
    
    ](https://medtechcyberstandards.com)
-   [
    
    MedTech Cyber Tips 
    
    Practical, organized tips for medical device cybersecurity teams.
    
    ](https://medtechcybertips.com)
-   [
    
    MedTech Cybersecurity Crosswalk 
    
    International crosswalk of medical device cybersecurity requirements across regulators.
    
    ](https://mdccrosswalk.com)
-   [
    
    Code Blue 
    
    Real medical device cybersecurity incidents and their lessons.
    
    ](https://codebluechart.com)

MedTech Terms 

An authoritative, plain-language reference for the regulatory, quality, cybersecurity, and software terms that shape modern medical devices.

Browse

-   [All terms](/terms)
-   [A–Z index](/a-z)
-   [Categories](/categories)
-   [Ecosystems](/ecosystems)
-   [Learning paths](/paths)
-   [Compare terms](/compare)
-   [Quiz](/quiz)

Resources

-   [FDA Medical Devices](https://www.fda.gov/medical-devices)
-   [EU MDR](https://eur-lex.europa.eu/eli/reg/2017/745/oj)
-   [IMDRF](https://www.imdrf.org/)
-   [Methodology](/methodology)
-   [Changelog](/changelog)
-   [Editor: Christian Espinosa](/authors/christian-espinosa)
-   [About this site](/about)

© 2026 MedTech Terms. Reference content for educational purposes - not regulatory advice. A community resource sponsored by [Blue Goat Cyber](https://bluegoatcyber.com)