Health information is not included in PHI when it fails any part of HIPAA’s three-part test or falls into one of four explicit regulatory exclusions. To count as protected health information, data must relate to someone’s health or care, be individually identifiable, and be held or transmitted by a HIPAA-covered entity or its business associate. Strip out any one of those elements and HIPAA no longer applies, even when the information looks unmistakably medical. On top of that, 45 CFR 160.103 carves out four categories by name: education records under FERPA, certain student treatment records, employment records held by a covered entity in its role as an employer, and information about a person who has been deceased for more than 50 years.1eCFR. 45 CFR 160.103 Definitions
The Three-Part Test That Defines PHI
Under the HIPAA Privacy Rule, PHI is individually identifiable health information that a covered entity or business associate creates, receives, maintains, or transmits in any form.2HHS.gov. Summary of the HIPAA Privacy Rule Three elements must all be present at the same time:
- The information relates to someone’s past, present, or future physical or mental health, the care they received, or payment for that care.
- It identifies the person directly or could reasonably be used to identify them.
- A health plan, health care clearinghouse, health care provider that transmits information electronically, or one of their business associates holds or transmits the data.
Everything covered below either fails one of those three tests or is excluded by name in the regulation.
De-Identified Health Information
Once health data has been properly stripped of identifying details, it is no longer PHI and the Privacy Rule no longer restricts its use or disclosure.3HHS.gov. Guidance Regarding Methods for De-identification of Protected Health Information HIPAA recognizes two paths.
Safe Harbor
The concrete method requires removing 18 categories of identifiers: names; geographic information smaller than a state; dates directly tied to the person (except year); phone and fax numbers; email addresses; Social Security numbers; medical record numbers; health plan beneficiary numbers; account numbers; certificate and license numbers; vehicle identifiers; device serial numbers; web URLs; IP addresses; biometric identifiers such as fingerprints; full-face photographs; and any other unique identifying number or code. After the stripping is done, the entity must also have no actual knowledge that the remaining information could identify someone.3HHS.gov. Guidance Regarding Methods for De-identification of Protected Health Information
Expert Determination
The alternative relies on a qualified statistician who uses accepted scientific methods to determine that the risk of re-identifying any individual is “very small,” and who documents the analysis. This route can leave more information intact if the expert can show the re-identification risk is negligible given the likely recipients and available outside data.3HHS.gov. Guidance Regarding Methods for De-identification of Protected Health Information
De-identification is not risk-free in the real world; researchers have shown that combining anonymized datasets with outside information can sometimes re-identify individuals. But as a legal matter, data processed through either method sits outside the PHI definition.
Employment Records
Health information in your personnel file is explicitly excluded from PHI, even when your employer is also a HIPAA-covered entity such as a hospital.1eCFR. 45 CFR 160.103 Definitions A hospital that employs nurses collects medical data on those nurses for FMLA leave, workers’ compensation claims, pre-employment physicals, drug testing, disability accommodations, and return-to-work evaluations. None of it becomes PHI just because the employer also delivers health care. The regulation draws a clean line: employment records held by a covered entity in its role as an employer are not PHI.
That does not leave the information unprotected. The Americans with Disabilities Act requires employers to keep medical records in files separate from general personnel records and to limit access. FMLA regulations impose similar confidentiality duties. Drug test results that reveal lawfully prescribed medications are treated as confidential medical records under EEOC guidance. The protections just come from employment and disability law rather than HIPAA.4HHS.gov. Your Rights Under HIPAA
Education and Student Treatment Records
Health information kept as part of a student’s education record is governed by the Family Educational Rights and Privacy Act, not HIPAA. School nurse visit logs, immunization records, counseling notes, and health evaluations for special education services all fall under FERPA when a federally funded school or district maintains them. The PHI definition at 45 CFR 160.103 carves out both education records covered by FERPA and student treatment records described at 20 U.S.C. 1232g(a)(4)(B)(iv).1eCFR. 45 CFR 160.103 Definitions
The overlap gets trickier at colleges. A university health clinic that bills insurance electronically could technically qualify as a covered entity. Even so, student health records that are part of education records stay under FERPA. Treatment records maintained by a university counseling center solely for the treating professionals sit in a separate FERPA category: not “education records” available to others at the institution, but still not PHI.5Institute of Education Sciences. Forum Guide to the Privacy of Student Information — Health Records: FERPA and HIPAA If a school-based clinic runs HIPAA electronic transactions such as insurance claims, those specific transactions may trigger HIPAA’s transaction rules, but the underlying student records still follow FERPA.
Health Data Held by Companies That Are Not Covered Entities
HIPAA only reaches covered entities and their business associates.2HHS.gov. Summary of the HIPAA Privacy Rule A growing universe of companies collects intimate health data without ever falling inside that definition.
Health and Fitness Apps
Period trackers, mental health apps, sleep monitors, fitness wearables, and calorie counters gather data that is deeply personal and clearly health-related. Unless the developer is a covered entity or a business associate of one, the data is not PHI. Fitbit step counts, meditation app mood logs, and fertility tracker cycle data all sit in a regulatory space where HIPAA does not apply. The same is true for connected devices like smart scales and blood pressure monitors that sync to a phone app rather than a provider’s electronic health record.
Direct-to-Consumer Genetic Testing
Companies such as 23andMe and AncestryDNA are not providers, health plans, or clearinghouses. The genetic data they collect is not PHI under HIPAA, even though it can reveal health risks and biological traits. The Genetic Information Nondiscrimination Act (GINA) bars health insurers and employers from using genetic information in coverage or employment decisions, but GINA does not regulate how the testing company itself handles your data. Some states have added genetic privacy laws requiring express consent before these companies share or sell genetic data.
Life, Disability, and Long-Term Care Insurance
Life insurers, disability insurers, and long-term care insurers collect detailed medical information during underwriting. They are generally not HIPAA-covered entities, because they are not health plans in the HIPAA sense (which covers medical, dental, vision, and similar health coverage). Health data they gather through applications, medical exams, or pharmacy databases falls under state insurance regulation and, for consumer reports, the Fair Credit Reporting Act.6eCFR. Part 1022 Fair Credit Reporting (Regulation V)
Information About People Deceased More Than 50 Years
HIPAA protections do not run forever. A covered entity must comply with the Privacy Rule regarding a deceased person’s health information for 50 years after the date of death; after that, the information is no longer PHI.7eCFR. 45 CFR 164.502 — Uses and Disclosures of Protected Health Information The regulation at 45 CFR 160.103 lists information “regarding a person who has been deceased for more than 50 years” as excluded from the PHI definition.1eCFR. 45 CFR 160.103 Definitions During those 50 years, baseline protections remain intact, though authorized disclosures to family members, personal representatives, and others involved in the decedent’s care or payment may still be permitted under HIPAA’s standard exceptions.
Health Information You Share Yourself
HIPAA regulates what covered entities and business associates do with your health information. It does not regulate what you do with it. Posting about a diagnosis on social media, discussing medications with a coworker, or sharing lab results in a support-group forum is not governed by HIPAA. The law imposes obligations on the entities holding your data in a professional capacity, not on you as its subject.
The same logic runs in reverse for other private individuals. If a neighbor tells someone about your surgery, or a friend shares your health news without permission, that may be a breach of trust, but it is not a HIPAA violation. HIPAA does not create a general right to medical secrecy. It creates specific obligations for specific organizations.
A Permitted Disclosure Is Not the Same as Non-PHI
One common confusion is worth correcting directly. When a hospital reports a gunshot wound to police, shares disease surveillance data with a public health agency, or produces records under a court order, the information disclosed is still PHI. HIPAA permits these disclosures without patient authorization under specific exceptions for public health activities, law enforcement, judicial proceedings, and other enumerated purposes, but the data does not stop being PHI simply because the disclosure is allowed.8HHS.gov. Disclosures for Public Health Activities
When the covered entity discloses PHI to a public health authority for disease reporting or vital statistics, the receiving agency may not itself be a covered entity. At that point the data sits in the hands of an organization outside HIPAA’s reach, but the original disclosure still had to comply with the Privacy Rule. “HIPAA allows this disclosure” and “this is not PHI” are very different statements.
What Protects Health Data That Falls Outside HIPAA
Data being outside PHI does not mean it is unregulated. Several other frameworks fill parts of the gap.
The FTC’s Health Breach Notification Rule applies to vendors of personal health records, related entities, and their service providers, meaning the health apps, wearable device companies, and connected health platforms that fall outside HIPAA. The rule explicitly does not apply to HIPAA-covered entities or their business associates, and it requires notice to affected individuals within 60 calendar days of discovering a breach of unsecured health data.9eCFR. Part 318 Health Breach Notification Rule10FTC. Complying with FTC’s Health Breach Notification Rule
Several states go further. Washington’s My Health My Data Act covers any entity that does business in Washington and collects consumer health data, regardless of HIPAA status. It defines consumer health data broadly to include conditions, diagnoses, medications, bodily functions, reproductive health, gender-affirming care, biometric data, genetic data, and precise location data that could reveal an attempt to access health services. It requires consent before collecting or sharing this data and gives consumers a right to deletion.11Washington State Legislature. Chapter 19.373 RCW My Health My Data Act California, Colorado, Connecticut, and Virginia treat health data as “sensitive” under their comprehensive privacy laws and impose heightened consent and handling rules. Which protections apply to you depends heavily on where you live and where the company operates.
The Fair Credit Reporting Act also plays a role when medical information ends up in a consumer report, typically during insurance underwriting or an employment background check. Entities that receive medical information from a consumer reporting agency generally cannot redisclose it beyond the original purpose, and the FCRA defines medical information broadly to include data created by or derived from a health care provider or the consumer that relates to health, health care, or payment for health care.6eCFR. Part 1022 Fair Credit Reporting (Regulation V)
Finally, GINA, the ADA, FMLA, and state workers’ compensation laws all impose confidentiality obligations on health data that HIPAA does not reach. None of them are HIPAA, but together they cover much of the ground that the PHI definition leaves open.