What is PHI (protected health information)?
Protected health information is individually identifiable health information held or transmitted by a covered entity or its business associates - the data HIPAA's privacy and security rules exist to protect.
PHI is the intersection of two things: information about health, healthcare, or payment for healthcare, and identifiers that tie it to a person. In an ABA practice that intersection is everywhere - session notes, assessment reports, graphs labeled with a client's name, schedules, claims, even appointment reminders.
The identifier list is broader than intuition suggests: beyond names and birthdates it includes addresses, phone numbers, email addresses, account numbers, photographs, and other data that could identify the individual. A progress graph with no name but a birthdate and initials can still be PHI; de-identification has a formal bar to clear, not a vibe.
HIPAA governs PHI through its rules: the Privacy Rule sets when PHI may be used and disclosed - treatment, payment, and operations being the everyday permitted purposes - and the minimum necessary standard limits each use to what the purpose requires. The Security Rule adds safeguards for PHI in electronic form: access controls, audit trails, encryption, and the administrative practices around them.
When PHI flows to vendors - a practice-management platform, a billing service, a clearinghouse - HIPAA requires a business associate agreement obligating the vendor to protect it. Vetting whether a tool will sign a BAA and how it secures data is therefore part of procurement in ABA, not an afterthought; free consumer tools that won't sign are how well-meaning teams create violations.
Day-to-day compliance is mostly unglamorous discipline: role-based access instead of shared logins, communication channels approved for PHI instead of personal texting, screens and documents shielded in shared spaces, and training that keeps all of it habitual. The practices that handle PHI well have made the secure path the convenient one.