PII vs PHI: what is the difference, and what can a healthcare company license?
PII is any information that identifies a person or can be linked to one, defined differently across US laws; PHI is HIPAA's term for individually identifiable health information held or transmitted by a covered entity or business associate. PHI is a regulated subset of PII. Records that are mainly PHI are a licensing red flag unless authorized or de-identified.
The short answer: PHI is health information tied to who holds it
Personally identifiable information (PII) is a general term for information that identifies a person or can reasonably be linked to one: a name, an email address, a phone number, an account number or a combination of details. There is no single US definition; federal and state laws each define personal information in their own way.
Protected health information (PHI) is a defined HIPAA term. As the HHS Office for Civil Rights explains in its de-identification guidance, the HIPAA Privacy Rule protects individually identifiable health information held or transmitted by a covered entity or its business associate, in any form or medium, and calls it PHI. Two conditions make information PHI: it relates to a person's health, care or payment for care, and it sits with a covered entity or a business associate.
So the same email address can be ordinary PII in a software vendor's sales CRM and part of PHI in a clinic's patient portal.
PII vs PHI, side by side
| Factor | PII | PHI |
|---|---|---|
| What it is | Information that identifies or can be linked to a person | Individually identifiable health information |
| Legal source | Many laws, each with its own definition | The HIPAA Privacy Rule |
| Who it applies to | Depends on the law: businesses, financial institutions, government agencies | Covered entities and their business associates |
| Typical examples | Name, email, phone, address, account number | Diagnosis, treatment dates, claim details linked to a patient identifier |
| Health content required | No | Yes: health status, care or payment for care |
| How it stops being regulated | Varies by law | De-identification under HIPAA's standard |
| Licensing screen | Check notices, contracts and the privacy laws that apply | A red flag if records are mainly PHI without HIPAA authorization or de-identification |
Is an email address PHI?
On its own, no: an email address is PII. It becomes part of PHI when a covered entity or business associate holds it together with health information about the person, such as a patient's address in an appointment reminder system. Email addresses are one of the 18 identifiers that HIPAA's Safe Harbor de-identification method requires removing, along with items such as names, phone numbers, Social Security numbers, medical record numbers and full-face photographs.
| Data item | PII? | PHI? | Why |
|---|---|---|---|
| Customer contact in a SaaS vendor's CRM | Yes | No | No health content, and the vendor is not acting for a covered entity |
| Patient name and appointment date at a clinic | Yes | Yes | Identifiable and about care, held by a provider |
| Claim number and denial reason at a billing company serving providers | Yes | Usually yes | Health payment data held as a business associate |
| A staff member's sick-leave note at a logistics firm | Yes | Generally no | Health content, but the employer is not acting as a covered entity |
| Denial rates by payer, with no patient-level data | No | No | Aggregated, with no individual identifiers |
| An internal procedure for appealing denials, with no patient details | No | No | Process knowledge, not about an individual |
How PHI stops being PHI: de-identification
HHS recognizes two methods. Under Expert Determination, a qualified expert determines and documents that the risk of re-identification is very small. Under Safe Harbor, the 18 specified identifiers are removed and the organization has no actual knowledge that the remaining information could identify an individual. Health information de-identified by either method is no longer PHI under the Privacy Rule.
De-identification is not the only route; HIPAA also permits some uses with an individual's authorization. For licensing, whichever route applies has to be settled before any work on PHI begins, and SourceX agrees de-identification and redaction requirements with the company first.
The screen for healthcare administration companies
Billing, revenue cycle, credentialing, scheduling and practice-management businesses frequently work as business associates for provider clients. Two consequences follow. Much of the PHI they hold belongs to their clients, which makes it a whose-data-is-it problem as well as a HIPAA one. And their own operating records, which carry little or no PHI, can still qualify.
| Record type | Typical PHI exposure | Screen outcome |
|---|---|---|
| Patient claims, charts and remittances | High | Red flag unless authorized or de-identified, and usually the client's data |
| Denial-management playbooks and appeal templates | Low, if examples are scrubbed | Candidate |
| Internal SOPs, training decks and QA rubrics | Low | Candidate |
| Staff chat about workflow that mentions patients | Mixed | Candidate only with redaction rules agreed |
| Project, finance and vendor-management records | Low | Candidate |
| Coding guidance and payer policy notes the company wrote | Low | Candidate if the company owns them |
The explainer on what a HIPAA business associate is covers the contract side, and data controller vs data processor explains the same ownership question in general privacy terms.
Where PII and PHI turn up in ordinary systems
Most companies hold PII in nearly every system, and healthcare-adjacent companies can hold PHI in places nobody mapped. A quick system-by-system pass shows where redaction effort would land.
| System | PII usually present | Where PHI can creep in |
|---|---|---|
| Names, signatures, phone numbers | Forwarded claim files, patient questions sent by clients | |
| Slack or Teams | Staff names and handles | Screenshots or pasted records during troubleshooting |
| CRM | Client contacts and deal notes | Rarely, unless patient-level work is logged there |
| Support or ticketing | Requester details | Ticket bodies quoting claims, eligibility or patient records |
| HR and benefits | Employee files | Benefits and leave records, which follow their own rules |
| Finance | Vendor and customer billing details | Patient statements at a provider or billing company |
The pattern matters more than the totals: PHI that sits in a few predictable fields can be separated or redacted, while PHI scattered through free text across every system makes a license far harder.
Owner checklist before raising a license
- Are we a covered entity, a business associate, both or neither?
- Which of our systems hold PHI, and which hold only operating records?
- Do our business associate agreements limit how we may use client data?
- Can operating records be separated from patient-level data at export?
- Who internally would own a de-identification plan, with outside expert help if needed?
- Did we reach 50+ full-time employees at peak (contractors excluded), with several years of records across many systems?
If the honest answer is that most valuable records are client PHI, the company is probably not a fit today. If its own operating history is deep and separable, it may be.
Financial PII has its own rules
Health data is not the only regulated category of PII. Under the Gramm-Leach-Bliley Act, financial institutions within the FTC's jurisdiction must give customers notices about information-sharing practices and, before sharing with certain nonaffiliated third parties, opt-out rights, as the FTC's GLBA business guidance sets out. A healthcare company that also runs patient financing or collections should check both regimes.
This is general information, not legal, tax or financial advice. Confirm with your own healthcare privacy counsel before acting.
Next step
Owners can test their fit with the company fit checker, read who qualifies and apply at sourcex.si/apply. For what makes records usable once rights are clear, see what AI-ready data means. If you advise a healthcare administration business with deep, separable operating records, register as a partner to make the introduction.
Common questions
Is de-identified health data still personal information under other laws?
It can be. HIPAA de-identification takes data out of PHI status under the Privacy Rule, but state privacy laws and contracts use their own definitions and may still apply, especially if the data could be linked back to people. Treat de-identification as one requirement rather than a blanket clearance, and confirm the position under every law and agreement covering the records.
Does HIPAA apply to every company that holds health information?
No. HIPAA's Privacy Rule applies to covered entities, meaning health plans, health care clearinghouses and providers that conduct certain transactions electronically, and to their business associates. A company outside those categories can hold health information that is not PHI, though state laws, contracts and its own privacy notices may still restrict what it does with that information.
Can a medical billing company license its data for AI training?
Usually not its claims and patient records, which it typically holds for provider clients as a business associate. Its own operating records can be different: process documentation, training materials, workflow tickets, finance and vendor records with little or no PHI may qualify, subject to de-identification and redaction rules agreed with the company before any work begins.
Who decides whether a dataset is de-identified enough?
Under HIPAA's Expert Determination method, a qualified expert applies statistical or scientific principles and documents that the risk of re-identification is very small. Under Safe Harbor, the organization removes the 18 listed identifiers and must have no actual knowledge that what remains could identify someone. For a license, the method and redaction rules are agreed with the company before work starts.
Is an IP address PII or PHI?
An IP address is generally treated as PII because it can be linked to a person or household. It is also one of the 18 Safe Harbor identifiers, so when a covered entity or business associate holds it alongside health information, it forms part of PHI and must be removed for Safe Harbor de-identification.
Related pages
- What is a HIPAA business associate, and can it license the data it holds?
- Data controller vs data processor: what is the difference for data licensing?
- Check Company Fit for Data Licensing
- Which US businesses are a fit for a SourceX data licensing introduction
- What is AI-ready data, and is it the same as data you can license?
Free resources
- Profit margin calculator — Profit and margin across three scenarios.
- Client opportunity brief generator — An editable intro email, summary and checklist.
- Days sales outstanding calculator — How many days customers take to pay.
- All free tools · MCP resource center
By SourceX Partnerships Team · Published 2026-10-09 · Updated 2026-10-09
Know a US company with valuable proprietary data?
Become a referral partner from anywhere we support, get your link and introduce an owner or authorized decision-maker.
Refer a company →I own a business
Explore licensing your company's data to AI developers worldwide. Start a short assessment; no uploads needed.
Start an assessment