Protecting patient data isn’t optional—it’s your core responsibility.

What is PHI

Protected Health Information (PHI) is any information that meets all three of these criteria:

  1. Identifies (or could identify) an individual
    PHI includes data like name, address, birth date, Social Security number, email address, phone number—anything that links health information to a specific person.

  2. Relates to health status or healthcare
    This covers medical records, treatment details, test results, prescriptions, mental-health notes, billing and payment information, even conversations between patient and provider.

  3. Is created, received, stored or transmitted by a covered entity or its business associate
    Covered entities are health plans, healthcare clearinghouses, and healthcare providers who electronically transmit health information. Business associates are vendors or partners (e.g., cloud hosts, billing services, analytics firms) that handle PHI on their behalf.

Key Examples of PHI

The “18 Identifiers”

HIPAA specifies 18 types of identifiers that—when combined with health information—make it PHI. Some common ones are: name, geographic details (beyond zip code), dates (except year) directly related to an individual, phone/fax numbers, email addresses, Social Security numbers, medical record numbers, health plan beneficiary numbers, account numbers, certificate/license numbers, vehicle identifiers, device identifiers, URLs, IP addresses, biometric identifiers (e.g., fingerprints), full-face photos, and any other unique identifying number or code.

What’s Not PHI?

Why It Matters
Any system that stores, processes or transmits PHI must satisfy HIPAA’s Privacy, Security and Breach Notification Rules. You need to treat PHI as highly sensitive: encrypt it, control and log who accesses it, train your team on handling it, and have clear incident-response plans in place. Mishandling PHI isn’t just a compliance risk—it’s a trust and reputational risk.

HIPAA-Compliant Guide

Below is a deep dive into the technical, administrative, and operational controls you need to build—and sustain—a truly HIPAA-compliant software product.

1. Understand the HIPAA Rule Set

Before writing a single line of code, map out how each HIPAA Rule applies to your system:

2. Data Classification & Flow Mapping

3. Risk Assessment & Management

4. Administrative Safeguards in Code & Process

5. Technical Safeguards: Encryption & Key Management

6. Identity & Access Management (IAM)

7. Audit Logging & Monitoring

8. Business Associate Agreements (BAAs)

9. Incident Response & Breach Notification

10. Continuous Compliance & DevSecOps

Conclusion

HIPAA compliance isn’t a one-off project—it’s an ongoing DevSecOps mindset. Bake in security from design through deployment, automate guardrails, and document relentlessly. Do it right, and you transform HIPAA from a compliance checkbox into a competitive advantage: trust.