Key Points
- PHI is the intersection of health information and identifiers that tie it to a person - session notes, assessments, graphs, schedules, claims, even appointment reminders.
- The Privacy Rule sets when PHI may be used and limits each use to the minimum necessary; the Security Rule adds safeguards for it in electronic form.
- Any vendor handling it needs a business associate agreement, which makes whether a tool will sign one a procurement question rather than an afterthought.
Protected Health Information (PHI) Explained
PHI is the intersection of two things: information about health, healthcare, or payment for healthcare, and identifiers that tie it to a person. In an ABA practice that intersection is everywhere - session notes, assessment reports, graphs labeled with a client's name, schedules, claims, even appointment reminders.
The identifier list is broader than intuition suggests: beyond names and birthdates it includes addresses, phone numbers, email addresses, account numbers, photographs, and other data that could identify the individual. A progress graph with no name but a birthdate and initials can still be PHI; de-identification has a formal bar to clear, not a vibe.
HIPAA governs PHI through its rules: the Privacy Rule sets when PHI may be used and disclosed - treatment, payment, and operations being the everyday permitted purposes - and the minimum necessary standard limits each use to what the purpose requires. The Security Rule adds safeguards for PHI in electronic form: access controls, audit trails, encryption, and the administrative practices around them.
When PHI flows to vendors - a practice-management platform, a billing service, a clearinghouse - HIPAA requires a business associate agreement obligating the vendor to protect it. Vetting whether a tool will sign a BAA and how it secures data is therefore part of procurement in ABA, not an afterthought; free consumer tools that won't sign are how well-meaning teams create violations.
Day-to-day compliance is mostly unglamorous discipline: role-based access instead of shared logins, communication channels approved for PHI instead of personal texting, screens and documents shielded in shared spaces, and training that keeps all of it habitual. The practices that handle PHI well have made the secure path the convenient one.