# Protected health information (PHI)

> Protected health information (PHI) is health data that identifies a person. HIPAA covers it when a provider, plan or their vendor holds it.

Source: https://incidentkit.ai/glossary/phi · Updated Oct 5, 2026

Also known as: PHI, protected health information, ePHI

## The HIPAA definition

45 CFR 160.103 defines PHI as health information, in any form, that identifies a person or could reasonably be used to. A provider, health plan, employer or clearinghouse creates or receives it. It relates to a person's health, care or payment for care.

PHI does not include:

- Education records covered by FERPA
- Employment records a covered entity holds as an employer
- Data about a person who died more than 50 years ago

## Incident reports

A fall report that names the resident, room and injuries is PHI. So is a medication error report with the patient's name, record number and diagnosis.

Remove identifiers you do not need. Treat the rest under HIPAA, including a [business associate agreement](https://incidentkit.ai/glossary/business-associate-agreement) with any vendor that holds it.

Example: a hospital's file on an employee hurt at work is an employment record, not PHI. The same person's treatment record, made because the hospital treated them as a patient, is PHI.

Mix-up: PHI is not every personal detail. It is health information tied to a covered entity or business associate. A worker's injury report at a plant is not PHI.

## Frequently asked questions

### Is an incident report PHI?

Yes, if it identifies a patient or resident and relates to health, care or payment. A report on only a worker injury at a non-healthcare employer holds no PHI.

### Are employee injury records PHI?

Records a covered entity holds as an employer, like an injury report, are not PHI. Its treatment records of the same person are PHI.

### What makes health information identifiable?

It identifies the person, or can reasonably be used to. A name is the clear case, but a mix of details can also identify someone.

## Sources

- [45 CFR 160.103: HIPAA definitions (protected health information, business associate)](https://www.ecfr.gov/current/title-45/section-160.103)

## Related terms

- [Business associate agreement](https://incidentkit.ai/glossary/business-associate-agreement)
- [Patient safety organization](https://incidentkit.ai/glossary/patient-safety-organization)
- [Incident report](https://incidentkit.ai/glossary/incident-report)
- [Variance report](https://incidentkit.ai/glossary/variance-report)

## Related

- [HIPAA and BAA for incident reporting](https://incidentkit.ai/hipaa)
- [IncidentKit security overview](https://incidentkit.ai/security)
- [Incident audit trail: every change, who and when](https://incidentkit.ai/product/audit-trail)
- [Incident reporting software: forms, drafts, workflow](https://incidentkit.ai/product/incident-reporting)
- [Patient safety event reporting software for hospitals](https://incidentkit.ai/solutions/hospitals)
