**Protected Health Information (PHI)** is individually identifiable health information that is transmitted or maintained in any form.
18 HIPAA Identifiers:
1. Names
2. Geographic data (smaller than state)
3. Dates (except year) related to an individual
4. Phone numbers
5. Fax numbers
6. Email addresses
7. Social Security numbers
8. Medical record numbers
9. Health plan beneficiary numbers
10. Account numbers
11. Certificate/license numbers
12. Vehicle identifiers and serial numbers
13. Device identifiers and serial numbers
14. Web URLs
15. IP addresses
16. Biometric identifiers
17. Full-face photos
18. Any other unique identifying number or code
ePHI (Electronic PHI):
PHI that is created, received, maintained, or transmitted electronically. This includes:
Electronic health recordsEmail containing patient informationPatient portalsDigital imagesBilling recordsLab resultsDe-Identified Data:
Health information with all 18 identifiers removed (Safe Harbor) or certified by an expert (Expert Determination) is not considered PHI and is not protected by HIPAA.