US

HIPAA: Scope and Definitions

Scope and Definitions [45 CFR 160.103]

Rule: HIPAA applies to covered entities and their business associates when handling protected health information (PHI).

Covered Entities

Entity TypeExamples
Healthcare providersHospitals, doctors, clinics, pharmacies, dentists
Health plansHealth insurers, HMOs, Medicare, Medicaid
Healthcare clearinghousesBilling services, repricing companies

Business Associates

Organizations that perform services for covered entities involving access to PHI:

  • Cloud service providers storing PHI
  • Medical billing companies
  • EHR vendors
  • IT consultants with PHI access
  • Attorneys, accountants with PHI access

Protected Health Information (PHI)

PHI is individually identifiable health information that:

  1. Is created or received by a covered entity
  2. Relates to physical/mental health, healthcare provision, or payment
  3. Identifies or could identify the individual

The 18 HIPAA Identifiers

If ANY of these are present with health data, it’s PHI:

#Identifier
1Names
2Geographic data (smaller than state)
3Dates (except year) related to individual
4Phone numbers
5Fax numbers
6Email addresses
7Social Security numbers
8Medical record numbers
9Health plan beneficiary numbers
10Account numbers
11Certificate/license numbers
12Vehicle identifiers
13Device identifiers and serial numbers
14Web URLs
15IP addresses
16Biometric identifiers
17Full-face photos
18Any other unique identifying number

De-identification

PHI becomes non-PHI when de-identified using either:

  1. Expert Determination (§164.514(b)(1)) — Statistical expert certifies re-identification risk is very small
  2. Safe Harbor (§164.514(b)(2)) — All 18 identifiers removed, no actual knowledge re-identification possible

What’s NOT Covered

Data TypeHIPAA Status
Employment recordsNot PHI (even health data)
Student health recordsFERPA applies, not HIPAA
Consumer health apps (non-CE)Not HIPAA (FTC Act applies)
Research data (de-identified)Not PHI

Citation

45 CFR 160.103 — Definitions

Contains public sector information licensed under the Open Government Licence v3.0 where applicable. This is not legal advice. Always refer to official sources for authoritative text.

llms.txt