Protected Health Information (PHI)
Individually identifiable health information held or transmitted by a HIPAA covered entity or business associate in any form — electronic PHI (ePHI) is PHI in electronic form. PHI triggers HIPAA Privacy, Security, and Breach Notification Rule duties that SOC 2 attestation does not replace.
In practice
In a SaaS product, PHI shows up anywhere health context meets an identifier — a patient name next to a diagnosis code, a support ticket quoting a lab result, or a database column storing a treatment date tied to a member ID. If the data is created, received, maintained, or transmitted electronically, it's ePHI, and §164.312(a)(1) access control along with related Security Rule technical safeguards apply to the systems that hold it.
Common confusion
Teams sometimes assume de-identifying a few obvious fields — name, Social Security number — is enough to take data out of PHI scope. HHS's de-identification standard under §164.514 requires removing 18 specific identifier categories, or a formal expert determination; a data set with dates, ZIP codes, or a rare diagnosis combination can still be re-identifiable and therefore still PHI.