Protected Health Information (PHI)
Protected health information (PHI) is individually identifiable health data safeguarded under HIPAA — and one of the most valuable targets attackers can steal.
Protected health information (PHI) is individually identifiable health information created, received, stored, or transmitted by a HIPAA-covered entity or its business associates. It spans the obvious — diagnoses, lab results, prescriptions, treatment notes — and the eighteen identifiers that can tie health data to a person, including names, dates, addresses, Social Security numbers, medical record numbers, and biometric data. In electronic form it is called ePHI, and it is the asset the HIPAA Privacy and Security Rules exist to protect.
Why attackers want it
A stolen payment card can be cancelled in minutes; a medical record cannot. PHI bundles identity, insurance, financial, and clinical details in one place, which makes it raw material for medical identity theft, fraudulent insurance claims, prescription fraud, and convincing spear-phishing pretexts — an attacker who knows your insurer, your clinic, and your last appointment writes a very believable email. That durability and versatility keep healthcare among the most-breached sectors: in 2025 alone, 710 large breaches were reported to the US Office for Civil Rights, exposing PHI of nearly 62 million people, and close to one in four involved email compromise. Most of that data left through people — a phished mailbox, a mis-sent attachment, a help desk talked into a password reset — not through broken cryptography.
How to defend it
Start by knowing where PHI actually lives, including the unofficial copies in inboxes, spreadsheets, and messaging apps, and apply least-privilege access so a single compromised account exposes the minimum. Encrypt ePHI at rest and in transit, require multi-factor authentication in front of it, and monitor for unusual access patterns such as bulk record views. Then address the channel most breaches actually use: train every workforce member — clinicians, billing, front desk, and management alike — to recognize phishing and pretext calls, and rehearse with realistic simulations. HIPAA's Security Rule explicitly requires a security awareness and training program for the entire workforce; our guide to human risk in healthcare covers how to turn that obligation into measurable behavior change rather than a completion report.
Related terms
NOUSEC simulates attacks across 8 channels and turns the results into one number your board can read.
Book a demo