The difference between PII and PHI comes down to scope and rules: personally identifiable information is any data that can identify a specific person, while protected health information is the narrower slice of that data which relates to health and is held by an organization covered by HIPAA. Every piece of PHI is also PII. Most PII has nothing to do with healthcare. The distinction matters because PHI sits under one strict federal regime with defined penalties, and PII sits under a patchwork of federal and state laws with no unified standard.
What Counts as PII
The federal government defines PII as any information an agency maintains about a person that can distinguish or trace that person’s identity, plus any other information linked or linkable to that person.1NIST. Guide to Protecting the Confidentiality of Personally Identifiable Information (PII) That definition splits in two.
Linked information identifies someone on its own. A full name, Social Security number, driver’s license number, passport number, or biometric data like a fingerprint falls in this group. Linkable information doesn’t identify someone alone but can when combined with other available data. A date of birth, ZIP code, gender, IP address, or employment history is linkable rather than linked.
This is why PII is harder to pin down than people expect. A ZIP code by itself seems harmless. Pair it with a birth date and gender and researchers have shown the combination can uniquely identify a large percentage of the U.S. population. Organizations collecting seemingly innocent data points can end up holding PII without realizing it.
What Counts as PHI
PHI is individually identifiable health information that a HIPAA-covered entity or its business associate creates, receives, stores, or transmits in any form, whether electronic, paper, or spoken aloud.2U.S. Department of Health & Human Services. Summary of the HIPAA Privacy Rule Two conditions must both be true. The data relates to a person’s past, present, or future health condition, healthcare services, or payment for those services. And it identifies the person or could reasonably be used to do so.
Common examples include medical records, lab results, prescription histories, health insurance policy numbers, billing records from a doctor’s office, and notes about a diagnosis or treatment plan. Even demographic details like a name, address, or birth date become PHI when they sit in a healthcare context alongside health information.2U.S. Department of Health & Human Services. Summary of the HIPAA Privacy Rule
Here’s the point that trips people up: your health information on its own is not automatically PHI. If you tell a coworker about your knee surgery, that conversation isn’t regulated by HIPAA. PHI only exists in the hands of entities HIPAA covers.
How the Two Relate
The relationship is hierarchical. All PHI is PII, but only a small fraction of PII is PHI. Your Social Security number is PII in every context. It becomes PHI only when a covered entity holds it alongside your health information. The same number on a tax return or a job application is just PII, and different rules apply.
What flips one into the other isn’t the data itself. It’s who is holding it and why. Identical fields on identical spreadsheets can be PHI in one office and ordinary PII in another.
The Rules That Apply to Each
The regulatory gap is where the practical difference lives.
PHI is governed by a single federal law, HIPAA, with detailed rules about use, disclosure, storage, and breach notification. Covered entities must limit PHI use and disclosure to the minimum amount necessary for the intended purpose.3U.S. Department of Health & Human Services. Minimum Necessary Requirement They must designate a privacy officer, train their workforce on PHI handling policies, and maintain written procedures.4eCFR. 45 CFR 164.530 – Administrative Requirements The Security Rule adds administrative, physical, and technical safeguards specifically for electronic PHI.5U.S. Department of Health & Human Services. The Security Rule
PII has no equivalent single law at the federal level. Different types of PII are protected by different statutes depending on context. Financial data falls under the Gramm-Leach-Bliley Act. Children’s online data falls under COPPA. Credit reporting data falls under the Fair Credit Reporting Act. Federal agency records fall under the Privacy Act of 1974.6U.S. Department of Justice. Privacy Act of 1974 Most of these laws lack an equivalent minimum-necessary standard, and none of them cover PII across the board.
Who HIPAA Actually Covers
HIPAA doesn’t apply to everyone who touches health data. Its rules bind three categories of covered entities and any business associate working on their behalf.7U.S. Department of Health & Human Services. Covered Entities and Business Associates
- Healthcare providers, including doctors, hospitals, clinics, pharmacies, dentists, psychologists, and nursing homes, but only if they transmit health information electronically for transactions like billing or insurance claims.
- Health plans, including health insurance companies, HMOs, employer-sponsored group health plans, and government programs like Medicare and Medicaid.
- Healthcare clearinghouses, which convert nonstandard health data into standardized electronic formats.
A business associate is any outside person or company that performs work for a covered entity involving access to PHI. Billing services, IT contractors, cloud storage providers, law firms, and accounting firms handling health-related records all qualify. Business associates must sign a formal agreement with the covered entity and follow HIPAA’s privacy and security requirements themselves.8eCFR. 45 CFR 160.103 – Definitions Their subcontractors are bound too.
This is where confusion sets in. A fitness app tracking your heart rate is probably not a covered entity. Your employer’s HR department is not a covered entity. A school nurse’s records might be governed by FERPA rather than HIPAA. The data involved might look identical to PHI, but without the covered-entity connection, HIPAA’s protections don’t apply. Whatever protects that data is coming from PII laws instead.
How Breach Notification Differs
When data is exposed in a breach, PII and PHI trigger different notification rules. This is the sharpest practical difference between the two.
PHI Breach Notification Under HIPAA
A covered entity that discovers a breach of unsecured PHI must notify every affected individual within 60 calendar days of discovering the breach.9eCFR. 45 CFR 164.404 – Notification to Individuals If the breach affects 500 or more people, the entity must also notify the Secretary of Health and Human Services within that same 60-day window. Smaller breaches affecting fewer than 500 individuals can be logged and reported to HHS within 60 days after the end of the calendar year in which the breach was discovered.10eCFR. 45 CFR Part 164 Subpart D – Notification in the Case of Breach of Unsecured Protected Health Information Breaches involving 500 or more residents of a single state also trigger a requirement to notify prominent local media.
PII Breach Notification
No single federal law sets a universal breach notification timeline for PII. Federal agencies follow OMB Memorandum M-17-12, which requires notifying affected individuals “as expeditiously as practicable and without unreasonable delay,” primarily by first-class mail, with major incidents reported to Congress within seven days.11Obama White House Archives. Preparing for and Responding to a Breach of Personally Identifiable Information Those rules apply only to federal agencies.
For private companies, PII breach notification is governed almost entirely by state law. Every state has its own breach notification statute, and timelines range from 30 to 90 days depending on the jurisdiction. Some states require notification to the state attorney general alongside individual notice. Companies operating in multiple states have to track each state’s requirements separately.
How Penalties Differ
HIPAA sets tiered civil penalties based on culpability. The base statutory amounts run from $100 per violation with a $25,000 annual cap for a violator who did not know, up to $50,000 per violation with a $1,500,000 annual cap for willful neglect that wasn’t corrected.12Office of the Law Revision Counsel. 42 USC 1320d-5 – General Penalty for Failure to Comply With Requirements and Standards HHS adjusts these amounts upward for inflation each year.
Criminal prosecution is reserved for people who knowingly obtain or disclose PHI in violation of HIPAA. Basic wrongful disclosure carries up to $50,000 in fines and one year in prison. Disclosure under false pretenses carries up to $100,000 and five years. Disclosure with intent to sell or use for personal gain or malicious harm carries up to $250,000 and ten years.13Office of the Law Revision Counsel. 42 USC 1320d-6 – Wrongful Disclosure of Individually Identifiable Health Information
PII enforcement comes from whichever authority has jurisdiction, because no single law covers it. The FTC is the most active federal enforcer for private companies, bringing cases under its authority to prohibit unfair or deceptive trade practices. Companies that receive an FTC Notice of Penalty Offenses and continue violating can face civil penalties of up to $50,120 per violation.14Federal Trade Commission. Notices of Penalty Offenses State attorneys general also bring enforcement actions under their own data breach and consumer protection statutes, with penalties that vary widely.
Why the Distinction Matters to You
Stolen credit card numbers are a headache. Stolen medical records are a different kind of problem. When someone uses your financial identity, the fraud is usually caught through transaction monitoring, and federal law caps your liability. When someone uses your medical identity, their diagnoses, allergies, and blood type can end up merged with yours in a medical record. That contamination can lead to wrong medications or inappropriate treatment decisions.
Financial identity theft has mature recovery processes. Banks have dedicated fraud departments, and disputing unauthorized charges follows well-established procedures. Medical identity theft recovery is messier. Getting false information removed from medical records means navigating healthcare providers individually, and there’s no equivalent of a credit freeze for your health data. Victims often don’t discover the theft until they receive an unexpected bill or a claim denial from their insurer, sometimes months or years after the breach.
That difference in consequences is a large part of why HIPAA imposes stricter controls on PHI than most PII laws require. The exposure is harder to reverse, and the person affected may not find out until real harm has already occurred.