Not All Patient Data Is PHI. Here's Where the Line Actually Falls
PII vs PHI
HIPAA compliance

Not All Patient Data Is PHI. Here's Where the Line Actually Falls

PII and PHI trigger different legal obligations. See how telehealth businesses tell the two apart and how Bask Health protects both by default.

Bask Health Team
Bask Health Team
09/22/2026

PII and PHI are often used interchangeably, but they do not mean the same thing. A telehealth business may collect an email address through a newsletter form, receive symptoms through an intake questionnaire, and store appointment details in a patient record. All three involve information about a person, but the legal and operational questions are different.

Understanding PII vs. PHI helps telehealth operators decide how to collect, use, share, and protect information. It also helps them evaluate the systems involved. Bask's security infrastructure, for example, describes encryption, access controls, monitoring, and logging—important safeguards for sensitive information, but not substitutes for determining which privacy requirements apply to a particular data flow.

The distinction is more precise than “PII becomes PHI when someone becomes a patient.” Information collected before a consultation can already be PHI, while some personal information held by a healthcare organization may not be PHI in its particular context. The important questions are what the information reveals, whether someone can be identified, and who holds or transmits it.

What Is PII?

PII stands for personally identifiable information. It is information that can distinguish or trace an individual's identity, either on its own or in combination with other information.

The National Institute of Standards and Technology explains this broad concept in its Guide to Protecting the Confidentiality of Personally Identifiable Information (PII). Its approach considers both direct identifiers and information that can be combined with other data to identify someone.

PII can include:

  • A person's full name
  • An email address or telephone number
  • A home address
  • A government-issued identification number
  • An account identifier
  • Certain device or online identifiers
  • Other information that can identify someone when combined with available data

PII is not specific to healthcare. Retailers, employers, financial services companies, online publishers, and many other businesses collect it. No single U.S. law treats every instance of PII the same way. Applicable obligations depend on the organization, information, jurisdiction, activity, and relevant privacy or security laws. PII is a broad category of identifiable information, not a promise that the same legal rule applies to every record containing it.

What Is PHI?

PHI stands for protected health information. Under HIPAA, it generally refers to individually identifiable health information a covered entity or its business associate holds or transmits, subject to specific exclusions.

The U.S. Department of Health and Human Services explains in its Summary of the HIPAA Privacy Rule that individually identifiable health information includes information relating to a person's past, present, or future health or condition; the provision of healthcare; or payment for healthcare, when the information identifies the person or could reasonably be used to identify them.

That definition is broader than a diagnosis or a clinical note. An identifiable appointment record can reveal that someone received healthcare. A prescription record can reveal treatment information, while a bill can connect someone to payment for care.

PHI can exist in electronic, paper, or oral form. Electronic PHI, commonly shortened to ePHI, is PHI held or transmitted electronically and is subject to the HIPAA Security Rule's applicable requirements.

PHI Is Not Simply “PII Plus a Diagnosis”

A patient does not need a recorded diagnosis for information to qualify as PHI. Information about seeking, receiving, or paying for healthcare may be enough when it meets the other parts of HIPAA's definition.

Conversely, a health-related fact is not automatically PHI, no matter where it appears. The organization's HIPAA status and its relationship to the information also matter.

For example, a person might voluntarily share their running goals with a general fitness newsletter. Those details may be identifiable and sensitive, but that alone does not make the newsletter operator a HIPAA-covered entity or business associate.

PII vs PHI: The Difference at a Glance

QuestionPIIPHI
What does it describe?Information that can identify a personIndividually identifiable information related to health, healthcare, or payment for care
Is it limited to healthcare?NoIts HIPAA definition concerns information held or transmitted in a regulated healthcare context
Does a name alone qualify?Generally, yesNot necessarily; context matters
Can it include an email address?YesYes, when it forms part of identifiable health information in the relevant context
Which rules apply?Depends on applicable privacy, consumer-protection, security, and other lawsApplicable HIPAA requirements when the information falls within HIPAA's scope; other laws may apply too
Can the same record be both?YesYes

The distinction is not a choice between protecting a record and leaving it unprotected. Information outside HIPAA may still be sensitive and regulated under other laws.

Three Questions That Help Locate the PII-to-PHI Line

A practical starting point is to examine the information and the organization handling it together.

1. Does the information identify someone?

A name or email address may identify a person directly. Other details can identify someone when combined with information already available to the organization or a recipient.

Removing a name does not necessarily make a record anonymous. An account ID, contact detail, or combination of less obvious data points may still identify the person.

2. Does it relate to health, healthcare, or payment for care?

An email address in a general business mailing list does not, by itself, describe someone's healthcare. That same address, when linked to a specific person's consultation, prescription, or healthcare bill, may form part of identifiable health information.

The context can exist outside the visible text of a single database field. A contact record may appear to contain only a name and email address, but its presence in a patient scheduling system could connect that person to the provision of healthcare.

3. Who is holding or transmitting the information?

HIPAA does not regulate every business that collects health-related information. Its Privacy Rule applies to covered entities and, in relevant ways, their business associates.

HHS's Business Associates guidance explains that a business associate generally performs specified functions or services involving PHI on behalf of a covered entity. The organization’s role and the purpose for which it handles the information are therefore essential to the analysis.

You cannot reliably classify a data field as PHI or non-PHI from its column name alone. You need to understand what the record reveals, where it came from, and the role of the organization handling it.

Six Telehealth Examples Where the Distinction Matters

The examples below illustrate how the same type of information can be treated differently depending on context. They are not automatic classifications for every business model.

Information or activityWhat to consider
Email address submitted for a general company newsletterIdentifiable information, but not automatically PHI merely because the company operates in healthcare
Identifiable symptoms submitted through a covered provider's intake formCan be PHI even if the person never completes the consultation or becomes a paying patient
Appointment confirmation maintained by a covered providerCan be PHI because it connects an identifiable person to the provision of healthcare
Anonymous webpage visit to a general health articleThe visit alone does not necessarily establish that the visitor's information is PHI
Identifiable prescription or laboratory result in a covered provider's systemGenerally PHI because it connects a person to healthcare or treatment
Identifiable health information held by an independent consumer fitness appMay fall outside HIPAA, but other privacy and consumer-protection rules can still apply

A particularly important operational lesson is that “not yet a patient” is not a reliable privacy classification. If an identifiable person submits health information to a HIPAA-regulated provider through an intake form, the information does not have to wait for a completed appointment to receive appropriate protection.

That is why patient intake software design matters early in the telehealth journey. Information may become sensitive and potentially regulated at the point of collection, well before a clinician reviews it.

The Marketing-to-Intake Boundary Is Easy to Miss

Telehealth brands often build a journey that starts with an advertisement or educational webpage and continues through a questionnaire, registration form, clinical review, and payment.

From the patient's perspective, this may feel like one continuous experience. Operationally, however, several technologies might be involved: a website builder, analytics service, advertising platform, form provider, CRM, patient portal, and clinical record system.

The privacy question changes as information moves through those systems.

A general website visit does not automatically make all associated tracking data PHI. But identifiable information collected through a health-related form or patient workflow may raise different issues, especially when a HIPAA-regulated entity collects or discloses it.

HHS addresses this distinction in its guidance on online tracking technologies. The agency also notes that a federal court vacated the portion of its guidance that treated an IP address combined solely with a visit to an unauthenticated public webpage about a health condition or provider as sufficient to trigger HIPAA obligations. The remaining analysis depends on the actual information and circumstances—not a blanket rule that every visitor to a healthcare website generates PHI.

For telehealth operators, the practical approach is to map which fields each third-party service receives. A tracking tool should not receive identifiable intake responses or patient information simply because it was installed before the clinical workflow was built.

What If HIPAA does Not cover a Health App?

One of the most consequential misunderstandings in this area is assuming that information outside HIPAA has no legal protection.

An independent consumer health app may collect identifiable information about medications, symptoms, fitness, or other health topics without being a HIPAA-covered entity or business associate in that activity.

The Federal Trade Commission explains in its guidance on the Health Breach Notification Rule that certain non-HIPAA health apps and related businesses may be subject to that rule. The FTC also enforces consumer-protection requirements concerning deceptive or unfair practices involving personal information.

The distinction matters for businesses operating multiple products. A company could handle PHI as a business associate for a healthcare client while also offering a separate consumer product subject to different requirements.

Outside HIPAA does not mean outside privacy law. It means the operator must determine which requirements govern that particular information, activity, and business relationship.

Why Removing a Name Does Not Automatically Remove PHI Status

A telehealth business may want to use data for analytics, reporting, or operational planning without exposing individual patient information. That can be appropriate, but simply deleting the name field is not enough to conclude that the remaining information has been de-identified under HIPAA.

HHS describes two recognized methods for de-identifying PHI in its de-identification guidance: Expert Determination and Safe Harbor. Safe Harbor involves removing specified identifiers and meeting an additional knowledge condition; Expert Determination involves a qualified expert evaluating the risk of identification under the applicable standard.

Consider a hypothetical report containing a rare condition, an exact appointment date, and a small geographic area. Even without names, those details might make a particular person identifiable when combined with other information.

A useful distinction for operators is:

  • Masked data: Information is hidden from a particular view but may remain identifiable elsewhere.
  • Pseudonymized data: Direct identifiers are replaced, but a code or other available information may still connect the record to a person.
  • De-identified data under HIPAA: Information has met an applicable HIPAA de-identification method.

Do not treat those terms as interchangeable. Nor should a business assume that a dataset is safe for unrestricted use just because one obvious identifier has been removed.

What the PII vs PHI Distinction Changes Operationally

Once information is classified in context, that decision should influence how it moves through the business.

For PHI, a HIPAA-regulated organization needs to consider the permitted purposes for which information may be used or disclosed, applicable business associate arrangements, workforce access, and safeguards for electronic information.

HHS's Summary of the HIPAA Security Rule describes administrative, physical, and technical safeguards for ePHI, including requirements addressing access control, audit controls, integrity, authentication, and transmission security. These requirements apply in the context of the regulated organization's overall security program, not merely as settings inside one application.

For other identifiable information, the organization still needs to determine which applicable laws, contractual commitments, and internal privacy policies govern its collection and use.

The operational objective is to avoid two mistakes: treating PHI as ordinary marketing data and assuming that information classified as non-PHI may be shared without further review.

A Practical Data-Mapping Checklist for Telehealth Operators

Instead of asking staff to make an isolated PII-versus-PHI decision every time they see a field, build a data map around the workflows in which the information appears.

Data-mapping questionWhy it matters
Where was the information collected?A newsletter form, intake questionnaire, and clinical portal may have different purposes, and data flows
What does it reveal about the person?Identify whether it relates to health, healthcare, or payment
Can the person be identified?Consider direct identifiers and combinations of data
Which legal entity holds it?Determine whether that entity is a covered entity, business associate, or another type of organization
Which vendors receive it?Review analytics, messaging, forms, cloud services, and other integrations
Why is it being used or disclosed?Operational use, clinical care, advertising, and analytics may raise different questions
What safeguards and agreements apply?Match the workflow to the relevant requirements rather than relying on a platform-wide marketing claim

A useful test is to follow one person from an advertisement to an intake form and then into the patient portal. Record which systems receive their information at each stage, rather than assuming that every stage inherits the privacy treatment of the one before it.

If a data flow involves identifiable health information and its HIPAA status is uncertain, restrict unnecessary sharing while the organization reviews the context and applicable requirements. Precaution is a useful operating principle; it is not a substitute for a documented classification and compliance process.

How Bask Health Supports Patient Data Protection

Bask Health provides a telehealth platform that connects patient-facing and clinical workflows. Its plans describe a patient portal and experience builder, a doctor portal, e-prescribing and EMR capabilities, and a broader telehealth management environment.

Bask's security page describes encryption at rest and in transit, administrative access controls, system monitoring, logging and alerting, information governance, and two-factor authentication. These controls help protect information handled within the platform.

However, it would be misleading to say that using a secure platform automatically resolves every PII-versus-PHI question for a telehealth brand. An operator still needs to understand what information it collects, its legal role, how it uses the data, the agreements governing relevant vendors, and any outside marketing or analytics tools connected to the patient journey.

For broader HIPAA requirements around clinical information, Bask's guide to HIPAA compliance in telehealth provides a related starting point. The specific task here is to identify the information and data flows those requirements apply to.

FAQs

What is the difference between PII and PHI?

PII is information that can identify a person. PHI is individually identifiable health information held or transmitted in a context covered by HIPAA, subject to the law's definitions and exclusions. The same record can contain both.

Is an email address PII or PHI?

An email address is generally PII. It can also form part of PHI when associated with identifiable health information, such as a patient's healthcare appointment, and held or transmitted in the relevant HIPAA-regulated context.

Does someone have to become a patient before their information is PHI?

No. Identifiable health information submitted to a HIPAA-regulated provider through an intake workflow can qualify as PHI even if the person never schedules or completes an appointment.

Is every visit to a telehealth website PHI?

No. A visit to a public webpage does not automatically make every related identifier PHI. The information collected, the visitor's interaction, the site's use of tracking technologies, and the organization's HIPAA status all matter.

Is health information held by a fitness app always PHI?

No. A consumer fitness app may operate outside HIPAA for a particular service, although identifiable health information it collects may still be subject to other laws, including applicable FTC requirements.

Is data no longer PHI once the patient's name is removed?

Not necessarily. Other details may still identify the person. HIPAA provides specific de-identification methods; removing a name alone does not mean those standards have been met.

How does Bask Health protect patient information?

Bask describes security measures including encryption, access controls, monitoring, logging, and two-factor authentication. Telehealth brands using Bask should also assess their own data collection, vendor integrations, access configurations, and applicable privacy obligations.

Conclusion

The line between PII and PHI cannot be drawn by looking at a name, email address, or form field in isolation. The information's relationship to health or healthcare, its ability to identify someone, and the role of the organization handling it all matter.

For telehealth businesses, the difficult cases often arise before the virtual visit: a health questionnaire connected to marketing software, an abandoned intake form, or information passing between a website and a patient portal. Those workflows deserve attention because a person's information can require appropriate protection before any clinical encounter is completed.

Bask Health's plans provide connected patient and clinical infrastructure, supported by the safeguards described on its security page. Operators should use that foundation alongside a clear understanding of their own data flows, vendor relationships, and legal responsibilities. The goal is not to label every piece of information as PHI automatically; it is to recognize when the label applies and protect other sensitive information appropriately, too.

References

  1. National Institute of Standards and Technology (NIST). (2010). Guide to protecting the confidentiality of personally identifiable information (PII). https://www.nist.gov/publications/guide-protecting-confidentiality-personally-identifiable-information-pii
  2. U.S. Department of Health & Human Services. (n.d.). HIPAA Privacy Rule: Laws and regulations. https://www.hhs.gov/hipaa/for-professionals/privacy/laws-regulations/index.html
  3. U.S. Department of Health & Human Services. (n.d.). Business associates. https://www.hhs.gov/hipaa/for-professionals/privacy/guidance/business-associates/index.html
  4. U.S. Department of Health & Human Services. (n.d.). Use of online tracking technologies by HIPAA covered entities and business associates. https://www.hhs.gov/hipaa/for-professionals/privacy/guidance/hipaa-online-tracking/index.html
  5. U.S. Federal Trade Commission (FTC). (n.d.). Complying with the FTC’s Health Breach Notification Rule. https://www.ftc.gov/business-guidance/resources/complying-ftcs-health-breach-notification-rule-0
  6. U.S. Department of Health & Human Services. (n.d.). Guidance regarding methods for de-identification of protected health information in accordance with the HIPAA Privacy Rule. https://www.hhs.gov/hipaa/for-professionals/special-topics/de-identification/index.html
  7. U.S. Department of Health & Human Services. (n.d.). HIPAA Security Rule: Laws and regulations. https://www.hhs.gov/hipaa/for-professionals/security/laws-regulations/index.html
Schedule a Demo

Talk to an expert about your data security needs. Discuss your requirements, learn about custom pricing, or request a product demo.

Sales

Speak to our sales team about plans, pricing, enterprise contracts, and more.