PII vs PHI: what is the difference, and what can a healthcare company license?

PII is any information that identifies a person or can be linked to one, defined differently across US laws; PHI is HIPAA's term for individually identifiable health information held or transmitted by a covered entity or business associate. PHI is a regulated subset of PII. Records that are mainly PHI are a licensing red flag unless authorized or de-identified.

The short answer: PHI is health information tied to who holds it

Personally identifiable information (PII) is a general term for information that identifies a person or can reasonably be linked to one: a name, an email address, a phone number, an account number or a combination of details. There is no single US definition; federal and state laws each define personal information in their own way.

Protected health information (PHI) is a defined HIPAA term. As the HHS Office for Civil Rights explains in its de-identification guidance, the HIPAA Privacy Rule protects individually identifiable health information held or transmitted by a covered entity or its business associate, in any form or medium, and calls it PHI. Two conditions make information PHI: it relates to a person's health, care or payment for care, and it sits with a covered entity or a business associate.

So the same email address can be ordinary PII in a software vendor's sales CRM and part of PHI in a clinic's patient portal.

PII vs PHI, side by side

FactorPIIPHI
What it isInformation that identifies or can be linked to a personIndividually identifiable health information
Legal sourceMany laws, each with its own definitionThe HIPAA Privacy Rule
Who it applies toDepends on the law: businesses, financial institutions, government agenciesCovered entities and their business associates
Typical examplesName, email, phone, address, account numberDiagnosis, treatment dates, claim details linked to a patient identifier
Health content requiredNoYes: health status, care or payment for care
How it stops being regulatedVaries by lawDe-identification under HIPAA's standard
Licensing screenCheck notices, contracts and the privacy laws that applyA red flag if records are mainly PHI without HIPAA authorization or de-identification

Is an email address PHI?

On its own, no: an email address is PII. It becomes part of PHI when a covered entity or business associate holds it together with health information about the person, such as a patient's address in an appointment reminder system. Email addresses are one of the 18 identifiers that HIPAA's Safe Harbor de-identification method requires removing, along with items such as names, phone numbers, Social Security numbers, medical record numbers and full-face photographs.

Data itemPII?PHI?Why
Customer contact in a SaaS vendor's CRMYesNoNo health content, and the vendor is not acting for a covered entity
Patient name and appointment date at a clinicYesYesIdentifiable and about care, held by a provider
Claim number and denial reason at a billing company serving providersYesUsually yesHealth payment data held as a business associate
A staff member's sick-leave note at a logistics firmYesGenerally noHealth content, but the employer is not acting as a covered entity
Denial rates by payer, with no patient-level dataNoNoAggregated, with no individual identifiers
An internal procedure for appealing denials, with no patient detailsNoNoProcess knowledge, not about an individual

How PHI stops being PHI: de-identification

HHS recognizes two methods. Under Expert Determination, a qualified expert determines and documents that the risk of re-identification is very small. Under Safe Harbor, the 18 specified identifiers are removed and the organization has no actual knowledge that the remaining information could identify an individual. Health information de-identified by either method is no longer PHI under the Privacy Rule.

De-identification is not the only route; HIPAA also permits some uses with an individual's authorization. For licensing, whichever route applies has to be settled before any work on PHI begins, and SourceX agrees de-identification and redaction requirements with the company first.

The screen for healthcare administration companies

Billing, revenue cycle, credentialing, scheduling and practice-management businesses frequently work as business associates for provider clients. Two consequences follow. Much of the PHI they hold belongs to their clients, which makes it a whose-data-is-it problem as well as a HIPAA one. And their own operating records, which carry little or no PHI, can still qualify.

Record typeTypical PHI exposureScreen outcome
Patient claims, charts and remittancesHighRed flag unless authorized or de-identified, and usually the client's data
Denial-management playbooks and appeal templatesLow, if examples are scrubbedCandidate
Internal SOPs, training decks and QA rubricsLowCandidate
Staff chat about workflow that mentions patientsMixedCandidate only with redaction rules agreed
Project, finance and vendor-management recordsLowCandidate
Coding guidance and payer policy notes the company wroteLowCandidate if the company owns them

The explainer on what a HIPAA business associate is covers the contract side, and data controller vs data processor explains the same ownership question in general privacy terms.

Where PII and PHI turn up in ordinary systems

Most companies hold PII in nearly every system, and healthcare-adjacent companies can hold PHI in places nobody mapped. A quick system-by-system pass shows where redaction effort would land.

SystemPII usually presentWhere PHI can creep in
EmailNames, signatures, phone numbersForwarded claim files, patient questions sent by clients
Slack or TeamsStaff names and handlesScreenshots or pasted records during troubleshooting
CRMClient contacts and deal notesRarely, unless patient-level work is logged there
Support or ticketingRequester detailsTicket bodies quoting claims, eligibility or patient records
HR and benefitsEmployee filesBenefits and leave records, which follow their own rules
FinanceVendor and customer billing detailsPatient statements at a provider or billing company

The pattern matters more than the totals: PHI that sits in a few predictable fields can be separated or redacted, while PHI scattered through free text across every system makes a license far harder.

Owner checklist before raising a license

  • Are we a covered entity, a business associate, both or neither?
  • Which of our systems hold PHI, and which hold only operating records?
  • Do our business associate agreements limit how we may use client data?
  • Can operating records be separated from patient-level data at export?
  • Who internally would own a de-identification plan, with outside expert help if needed?
  • Did we reach 50+ full-time employees at peak (contractors excluded), with several years of records across many systems?

If the honest answer is that most valuable records are client PHI, the company is probably not a fit today. If its own operating history is deep and separable, it may be.

Financial PII has its own rules

Health data is not the only regulated category of PII. Under the Gramm-Leach-Bliley Act, financial institutions within the FTC's jurisdiction must give customers notices about information-sharing practices and, before sharing with certain nonaffiliated third parties, opt-out rights, as the FTC's GLBA business guidance sets out. A healthcare company that also runs patient financing or collections should check both regimes.

This is general information, not legal, tax or financial advice. Confirm with your own healthcare privacy counsel before acting.

Next step

Owners can test their fit with the company fit checker, read who qualifies and apply at sourcex.si/apply. For what makes records usable once rights are clear, see what AI-ready data means. If you advise a healthcare administration business with deep, separable operating records, register as a partner to make the introduction.

Common questions

Is de-identified health data still personal information under other laws?

It can be. HIPAA de-identification takes data out of PHI status under the Privacy Rule, but state privacy laws and contracts use their own definitions and may still apply, especially if the data could be linked back to people. Treat de-identification as one requirement rather than a blanket clearance, and confirm the position under every law and agreement covering the records.

Does HIPAA apply to every company that holds health information?

No. HIPAA's Privacy Rule applies to covered entities, meaning health plans, health care clearinghouses and providers that conduct certain transactions electronically, and to their business associates. A company outside those categories can hold health information that is not PHI, though state laws, contracts and its own privacy notices may still restrict what it does with that information.

Can a medical billing company license its data for AI training?

Usually not its claims and patient records, which it typically holds for provider clients as a business associate. Its own operating records can be different: process documentation, training materials, workflow tickets, finance and vendor records with little or no PHI may qualify, subject to de-identification and redaction rules agreed with the company before any work begins.

Who decides whether a dataset is de-identified enough?

Under HIPAA's Expert Determination method, a qualified expert applies statistical or scientific principles and documents that the risk of re-identification is very small. Under Safe Harbor, the organization removes the 18 listed identifiers and must have no actual knowledge that what remains could identify someone. For a license, the method and redaction rules are agreed with the company before work starts.

Is an IP address PII or PHI?

An IP address is generally treated as PII because it can be linked to a person or household. It is also one of the 18 Safe Harbor identifiers, so when a covered entity or business associate holds it alongside health information, it forms part of PHI and must be removed for Safe Harbor de-identification.

Free resources

By SourceX Partnerships Team · Published 2026-10-09 · Updated 2026-10-09

Know a US company with valuable proprietary data?

Become a referral partner from anywhere we support, get your link and introduce an owner or authorized decision-maker.

Refer a company →

I own a business

Explore licensing your company's data to AI developers worldwide. Start a short assessment; no uploads needed.

Start an assessment