{"@context":"https://schema.org","@type":"Article","headline":"Protected health information","description":"Learn when health information becomes PHI, which HIPAA rights matter to families, how authority and minimum necessary work, and where other privacy laws apply.","url":"https://finnihealth.com/resources/glossary/protected-health-information","datePublished":"2026-08-15T00:00:00.000Z","dateModified":"2026-08-24T00:00:00.000Z","author":{"@type":"Organization","name":"Finni Health Editorial Team"},"publisher":{"@type":"Organization","name":"Finni Health","url":"https://www.finnihealth.com"},"isPartOf":{"@type":"CollectionPage","name":"ABA and Practice Operations Glossary","url":"https://www.finnihealth.com/resources/glossary"},"breadcrumb":{"@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Resources","item":"https://www.finnihealth.com/resources"},{"@type":"ListItem","position":2,"name":"Glossary","item":"https://www.finnihealth.com/resources/glossary"},{"@type":"ListItem","position":3,"name":"Protected health information","item":"https://finnihealth.com/resources/glossary/protected-health-information"}]}}
Glossary term

Protected health information

Learn when health information becomes PHI, which HIPAA rights matter to families, how authority and minimum necessary work, and where other privacy laws apply.

5
min read
Updated
August 23, 2026
Sources checked
August 23, 2026
ยท View sources
Also called

individually identifiable health information personal health information PHI

What does Protected health information (PHI) mean for a family's rights and ethical care? Protected health information is individually identifiable health information transmitted or maintained by a HIPAA covered entity or business associate, subject to regulatory exclusions. For families, PHI brings federal rights involving notice, access, amendment requests, restrictions, confidential communication, and complaints. Ethical care also requires role-limited access, understandable communication, respect, and careful handling across every medium.

PHI depends on information and context

Current 45 CFR 160.103 defines individually identifiable health information through its source, health or care relationship, and ability to identify a person. PHI is that information when transmitted or maintained electronically or in another form or medium, subject to listed exclusions.

PHI can be spoken, written, photographed, printed, or electronic. A name on a treatment plan is an obvious example. A rare diagnosis, date, location, family detail, voice, or combination of facts may also identify someone.

The holder's role matters. HIPAA excludes FERPA education records, certain student-treatment records described by FERPA, employment records held by a covered entity in its employer role, and information about someone deceased more than 50 years. Other laws and ethical duties can still protect those records.

Removing a name may leave PHI

HIPAA de-identification uses either a qualified expert's documented determination that identification risk is very small or Safe Harbor removal of specified identifiers plus no actual knowledge that remaining information can identify the person. Replacing a name with initials or a code does not automatically de-identify a record.

Synthetic data should contain no real client information. If generated from real records, classify its provenance and residual risk. Contracts and other laws may impose additional limits.

Families have several distinct rights

The HHS Privacy Rule page explains the federal framework. HHS consumer materials describe rights to receive a privacy notice, inspect or obtain copies of records within rule limits, request amendment, request restrictions, ask for confidential communication, receive certain disclosure accountings, and complain.

Each right has scope, process, timing, fee, exception, and denial rules. A portal feature can support a right but does not define it. Give families an accessible route outside the portal too.

Verify who may act

A caregiver, emergency contact, family member, involved person, and personal representative may be different. HHS personal-representative guidance says applicable law determines the person's authority and its scope. Minor-specific and abuse, neglect, or endangerment exceptions can apply.

HIPAA may also permit directly relevant disclosures to family or others involved in care under defined circumstances. That pathway does not transfer consent authority or make the person a representative. Record the route and scope rather than a generic family-access flag.

Apply minimum necessary correctly

HHS minimum-necessary guidance generally applies to PHI uses, disclosures, and requests. Covered entities need role-based policies identifying which people need which information.

The treatment exception concerns disclosures to or requests by healthcare providers for treatment. It is not universal permission for every workforce member to view a complete record. Use purpose-specific views, reports, and queues.

Map PHI across ordinary ABA work

PHI can appear in intake forms, calendars, text reminders, behavior data, session notes, assessment media, caregiver messages, claims, authorizations, supervision records, incident files, support tickets, audit logs, exports, backups, and vendor portals. The same fact may appear in several copies with different owners and retention rules.

Build a data-flow map that identifies where information begins, who can view or change it, every recipient, each storage location, the authorized purpose, retention, correction, and disposal route. Include printers, downloads, screenshots, email, messaging, analytics, and temporary files. Review the map when a workflow, vendor, integration, device, site, or workforce role changes. A record inventory helps the practice apply access rules and respond when information is corrected, requested, or exposed.

A fictional data-flow review

Marisol's practice locks 20 data flows for classification. Seventeen have documented entity role, information type, purpose, authority, recipients, access, retention, and correction route: 17 of 20, or 85%.

One school exchange may involve FERPA. One workforce file is held in the employer role. One consumer app may fall outside HIPAA. All three go to the correct privacy or legal owner and remain visible. The percentage measures classification completion, not compliance.

Ethical care goes beyond secrecy

Privacy supports dignity, trust, choice, safety, and access. Explain information practices in understandable language. Protect AAC and interpreter access. Discuss sensitive information in appropriate settings. Avoid unnecessary details in calendars, notifications, whiteboards, task names, or messages.

Correct misattribution promptly through the applicable process. Keep clinical authorship clear. Give the person and legally authorized representative, when applicable, a meaningful way to ask questions and express preferences.

HIPAA is a federal floor for covered information. State health, consumer-health, biometric, minor, education, employment, breach, and record laws require their own scope analysis. Ethical and professional duties can also demand careful handling where HIPAA does not apply.

When a family asks to access, restrict, or correct information, route the request by the right invoked rather than treating it as ordinary support. Record receipt, identity and authority checks, scope, deadline, decision, delivery, denial basis, and any appeal or complaint path.

Related terms

Sources

Beyond the glossary

Take the next step with clarity

Whether you are finding care, growing as a clinician, or building a stronger ABA practice, Finni brings the people, tools, and support together to help you move forward.

Explore clinical roles at Finni practices