PHI vs PII: Key Differences Explained

Kyle Morris

GRC Consultant

Linkedin

TL;DR: PHI vs PII

  • PHI and PII both identify individuals, but PHI applies only when health information is linked to a person in a healthcare context.
  • PII covers a broader set of personal data used across industries, business functions, and customer records.
  • HIPAA governs PHI, while PII obligations depend on laws such as GDPR, CCPA, and sector-specific rules.
  • Clear data classification helps teams apply the correct access controls, disclosures, and retention rules to each record type.
  • Scytale’s AI GRC platform maps sensitive-data obligations across frameworks and keeps protection efforts aligned.

Healthcare, SaaS, and service organizations often store names, email addresses, account records, and medical details within the same systems. That overlap creates classification problems quickly, particularly when one dataset triggers HIPAA obligations and another falls under broader privacy laws with different requirements.

The distinction between PHI and PII determines how organizations classify data, restrict access, respond to incidents, and manage disclosures, and a clear model reduces policy gaps between legal, security, and compliance teams. In this article, we explain what PHI and PII are, how they differ, which frameworks govern each, how common examples apply in practice, and how your organization can protect both.

What is protected health information (PHI)

Protected health information (PHI) is any health-related information that can identify an individual and is created, received, stored, or transmitted by a covered entity or business associate in connection with healthcare services.

Under the HIPAA Privacy Rule, protected health information includes medical histories, treatment details, lab results, insurance information, and billing records when they connect to an identifiable person. HIPAA defines 18 identifiers, including names, dates, Social Security numbers, medical record numbers, and IP addresses, that turn health information into PHI when the two are linked.

In practice, the PHI meaning in HIPAA comes down to three factors: context, identity, and custody. A diagnosis alone does not create PHI in every setting, but a diagnosis linked to a patient record held by a covered entity does, so organizations that store identifiable health data in systems supporting treatment, payment, or operations should treat it under HIPAA requirements from the point of collection.

What is personally identifiable information (PII)

Personally identifiable information (PII) covers any data that can identify, contact, or locate a specific person, either on its own or when combined with other data points.

Common examples include names, email addresses, phone numbers, government ID numbers, and account numbers across business, consumer, and employee records. Unlike PHI, PII does not require a healthcare relationship. A customer email address in a SaaS platform, an employee tax form, and a shipping address in an ecommerce system all count as personally identifiable information when they identify a specific individual.

Some PII carries limited risk on its own, while combined records, such as a name paired with a date of birth and a government ID, significantly raise exposure to fraud, identity theft, and privacy violations. For this reason, organizations generally define internal sensitivity tiers for PII rather than applying a single standard to every data point.

What’s the difference between PHI and PII?

PHI and PII can appear in the same systems, but they differ in scope, legal requirements, and how organizations need to protect them. Understanding these differences is an important part of data privacy and compliance, helping teams identify which requirements apply and put the right safeguards in place for each type of personal information.

Here are the key differences between PHI and PII:

  • Scope: PII applies across industries, while PHI is identifiable health information protected under HIPAA.
  • Legal requirements: PHI is subject to HIPAA, while PII may be covered by different privacy and security laws.
  • Operational impact: PHI has specific requirements around access, use, disclosure, and protection.

Scope and context

The main distinction in the HIPAA PHI vs PII comparison is context. PII is information that can identify an individual across any industry and can appear across HR, finance, sales, support, and product systems. PHI is identifiable health information handled by a HIPAA-covered entity or business associate and can include patient records, treatment information, billing details, and health insurance information.

Regulatory requirements

PHI is specifically protected under HIPAA, which sets requirements for how covered entities and business associates use, disclose, store, and safeguard health information, including rules around access, security, and breach notification. PII does not fall under one single U.S. federal law in the same way, so requirements depend on factors such as the type of information, location, industry, and applicable privacy laws or contractual obligations.

Operational and compliance impact

The distinction between PHI and PII affects access controls, vendor management, incident response, and data sharing. A 2026 IBM report found that healthcare continued to have the highest average data breach cost of any industry, highlighting the importance of strong controls around sensitive health information. Context also matters: a patient’s name linked to an appointment or medical record and held by a healthcare provider may be PHI, while the same person’s name and email in an unrelated marketing database would generally be PII rather than PHI.

PHI vs PII comparison

Data typeWhat it coversCommon examplesPrimary regulation
PHIIdentifiable health information protected under HIPAADiagnosis, lab result, treatment note, insurance informationHIPAA
PIIInformation that can identify an individualName, email, phone number, employee ID, mailing addressVaries by applicable law
PII and PHI overlapIdentifying information linked to protected health informationPatient name with medical records, billing information, or appointment historyHIPAA and potentially other privacy laws
PHI vs PII differences

Which frameworks cover PHI and PII?

The requirements that apply to PHI and PII depend on the type of data, where it is handled, and the organization’s role. PHI is primarily regulated by HIPAA in the U.S., while PII may fall under multiple privacy laws and security frameworks. Organizations handling both often need to manage overlapping requirements across the same systems and data.

HIPAA

HIPAA governs PHI handled by covered entities and business associates, setting requirements for administrative, technical, and physical safeguards, as well as how PHI can be used, disclosed, and protected. Its PHI disclosure rules affect how patient information is shared in everyday operations, while Business Associate Agreements (BAAs) are generally required when covered entities share PHI with business associates. HIPAA also includes breach notification requirements, with affected individuals generally required to be notified within 60 days of discovering a breach.

GDPR and CCPA

GDPR and CCPA regulate personal data and consumer privacy rights, placing many forms of PII within scope and setting requirements around areas such as transparency, access, deletion, retention, and third-party data handling. GDPR also classifies health data as a special category of personal data, meaning organizations subject to both GDPR and HIPAA may need to meet requirements under both for the same health information.

PCI DSS and security frameworks

PCI DSS protects payment card data rather than PII as a whole, although payment and personal information often exist in the same systems. Frameworks such as SOC 2 and ISO 27001 can also help strengthen access controls, encryption, monitoring, and other safeguards around sensitive data. Managing multiple frameworks through shared controls can reduce duplicate work, especially in healthcare where organizations may manage HIPAA alongside other security frameworks.

For example, TrialX, a clinical research technology company, turned to Scytale after manually documenting only 50% of its SOC 2 and HIPAA requirements.

Examples of PHI and PII

Examples make the difference between PHI and PII easier to understand. The same information can be classified differently depending on what it is linked to, who handles it, and how it is used. Here are some common PHI vs PII examples:

  • PHI example: A hospital billing record containing a patient’s name, diagnosis code, and insurance information is PHI.
  • PII example: An HR record containing an employee’s name, home address, and Social Security number is PII.
  • Overlap example: A telehealth platform storing a user’s name alongside treatment notes handles information that may qualify as both PII and PHI.
  • Non-PHI health data: Health statistics that cannot be linked to an individual generally do not qualify as PHI.

The distinction can become less clear when health information appears in general business systems. For example, support teams may handle insurance forms, wellness information, or medical intake records through CRM or ticketing platforms. Clear data classification and tagging help support HIPAA compliance by ensuring sensitive information receives the right protections wherever it is stored or shared.

Health information that has been properly de-identified under HIPAA is no longer considered PHI. De-identification can therefore reduce the amount of regulated data organizations need to manage when using health information for purposes such as analytics and research that do not require individuals to be identified.

How should your organization protect PII and PHI?

Protecting PII and PHI starts with knowing what sensitive data your organization holds, where it is stored, and who can access it. Effective data protection practices combine clear classification, role-based access, disclosure logging, vendor oversight, retention rules, and incident response processes based on the type and sensitivity of the data. Here are the core practices for protecting both PII and PHI:

PII and PHI data protection

Classify data before you protect it

Organizations should map every system, field, and workflow that stores PHI PII data, including where it enters the business, who accesses it, and which records move to vendors, archives, or analytics tools. Data classification at this level gives teams the foundation to apply the right data security controls to each record type rather than one blanket standard.

Apply least-privilege access

Restrict access to the smallest group of users needed for each task, and review those permissions on a regular cadence. PHI usually requires tighter segmentation, stronger approval paths, and more detailed audit trails than general business PII, so access controls should reflect that difference.

Monitor disclosures and vendors

Review disclosures, third-party access, and data-sharing paths on a set schedule. Vendors handling healthcare or identity records should meet your contractual, security, and reporting standards before any data transfer begins, and an automated vendor risk assessment process helps teams verify this consistently.

Encrypt and minimize sensitive data

Encrypt PHI and sensitive PII at rest and in transit by default, and collect and retain only the data each process requires. Minimization and de-identification reduce the volume of regulated data in scope, which lowers breach exposure and the effort required to demonstrate compliance.

Align controls across frameworks

A single environment often supports HIPAA, privacy laws, and customer security reviews at the same time. Mapping those obligations to shared controls reduces duplicate work, keeps evidence organized, and supports continuous compliance as requirements and systems change.

Simplify PHI and PII compliance with Scytale

Scytale‘s AI GRC platform helps organizations manage PHI and PII obligations within one operating model, combining automated evidence collection, continuous monitoring, and cross-framework control mapping. Teams can track HIPAA, privacy, and security requirements in one place, identify gaps earlier, and keep sensitive-data protections aligned as systems and vendors change.

Scytale also supports multi-framework compliance across HIPAA, SOC 2, ISO 27001, GDPR, and PCI DSS, mapping a single control to multiple requirements to eliminate duplicate work. Combined with a customizable Trust Center and dedicated GRC experts, Scytale helps organizations maintain audit readiness, reduce manual effort, and protect both health and personal data with confidence.ves faster on audits, reviews, and remediation without losing sight of sensitive-data risk.

FAQs about PHI vs PII

  1. What does PHI mean?

    PHI means protected health information, which is identifiable health data handled in connection with treatment, payment, or healthcare operations. It includes medical details linked to a person, and HIPAA sets the main rules for how covered entities and business associates store, share, and protect it.

  2. What does PII mean?

    PII means personally identifiable information, which is any data that identifies a person directly or indirectly, such as a name, email address, phone number, or government ID. Unlike PHI, PII applies across all industries, so the governing rules depend on the laws and frameworks that affect your organization.

  3. What is the difference between PII and PHI?

    The main difference is scope: PII identifies a person in any setting, while PHI identifies a person through health information in a healthcare-related context. PHI and PII can overlap, but not all PII is PHI, and Scytale’s AI GRC platform helps teams map those distinctions to the right controls when systems hold both data types.

  4. What are examples of PII and PHI?

    Examples of PII include names, email addresses, phone numbers, and employee IDs, while examples of PHI include treatment records, lab results, insurance details, and appointment histories linked to a person. The same identifier can shift category when it appears inside a healthcare record tied to care or billing.

  5. What are the key regulations that govern PHI and PII?

    HIPAA is the key regulation governing PHI in the United States, while PII falls under a wider mix of obligations such as GDPR, CCPA, and sector-specific rules. Leading AI GRC platforms like Scytale help organizations connect those overlapping requirements to shared controls and evidence workflows.

Kyle Morris

Kyle Morris

Kyle Morris is a highly experienced Governance, Risk, and Compliance (GRC) professional with over 12 years of expertise in information security, IT auditing, and regulatory compliance. He is a Certified Information Systems Auditor (CISA) and an ISO 27001 Certified Lead Implementer, with a Bachelor of Science degree in Computer Science.  Kyle began his career as a Senior Analyst... Read more