A hospital marketing director once asked me if the number of flu shots administered last October counted as protected health information. She wanted to use the stat in a press release. Her compliance officer had locked it down, convinced any health data was PHI. The press release sat in limbo for three weeks.

She didn't need to wait. That aggregate number — with no names, no dates of birth, no way to trace it back to any individual — was never PHI in the first place.

Understanding what is not considered PHI under HIPAA is just as critical as knowing what is. Get it wrong in one direction, and you expose patient data. Get it wrong in the other, and you paralyze your own operations with unnecessary restrictions. I've watched both failures unfold at organizations of every size.

What Actually Makes Data PHI? The Two-Part Test

Before you can identify what falls outside PHI, you need the definition nailed down. Under the HIPAA Privacy Rule, protected health information has two requirements that must both be true simultaneously.

First, the information must relate to an individual's past, present, or future physical or mental health condition, the provision of healthcare, or payment for healthcare. Second, it must identify the individual — or there must be a reasonable basis to believe it could identify the individual.

Strip away either leg and the data is not PHI. That's the key insight most workforce members never fully absorb during training.

Six Categories That Are Not Considered PHI Under HIPAA

1. De-Identified Data

HIPAA spells out two methods for de-identification under 45 CFR §164.514. The Expert Determination method requires a qualified statistician to certify the risk of re-identification is "very small." The Safe Harbor method requires removing all 18 specific identifiers — names, dates, phone numbers, Social Security numbers, geographic data smaller than a state, and so on.

Once data is properly de-identified through either method, it is no longer PHI. Researchers, analysts, and marketing teams can use it without triggering HIPAA obligations. I've helped three health systems build de-identification pipelines specifically so their data science teams could work without Business Associate Agreements for every project.

2. Employment Records Held by a Covered Entity as an Employer

This one catches people off guard. If your hospital maintains employee health records for occupational health, workers' compensation, or workplace drug testing — and those records are held in the employer's role rather than the provider's role — they are not PHI under HIPAA.

That doesn't mean those records have no legal protection. State labor laws and the ADA still apply. But HIPAA's Privacy Rule doesn't govern them. The distinction matters when your HR department asks whether they need to follow the minimum necessary standard for a workers' comp claim. In their employer capacity, they don't.

3. Education Records Covered by FERPA

Student health records maintained by a school or university that receives Department of Education funding fall under the Family Educational Rights and Privacy Act, not HIPAA. The campus counseling center's therapy notes, the health clinic's immunization records — FERPA is the governing framework.

The HHS guidance on FERPA and HIPAA makes this boundary explicit. I've seen university compliance teams spend months trying to apply HIPAA breach notification rules to student clinic records when FERPA was the correct standard all along.

4. Health Data Held by Non-Covered Entities

HIPAA only applies to covered entities (health plans, healthcare clearinghouses, and healthcare providers who transmit data electronically) and their business associates. Health data sitting on a fitness app, a consumer wearable, or a wellness blog's user database is not PHI — because the entity holding it isn't covered by HIPAA.

Your Fitbit heart rate data? Not PHI. The blood pressure readings you log into a consumer app that has no relationship with a covered entity? Not PHI. This is exactly why Congress and the FTC have pushed separate regulatory frameworks for consumer health data, including state laws like Washington's My Health My Data Act.

5. Aggregate or Statistical Data With No Individual Identifiers

This brings us back to the flu shot press release. Aggregate data — "Our clinic treated 4,200 patients for respiratory illness in Q1" — contains no individually identifiable health information. It's a population-level statistic.

Covered entities use aggregate data for public reporting, quality improvement, and operational planning constantly. As long as the data can't reasonably be used to identify any single person, it sits outside HIPAA's definition of PHI.

6. Information About a Deceased Individual (After 50 Years)

HIPAA protections for a deceased person's PHI expire 50 years after death. After that window, the information is no longer PHI. Before that 50-year mark, the data of deceased individuals still carries full HIPAA protection — something I've seen funeral homes and genealogy researchers stumble over.

What About ePHI That Gets Stripped of Context?

Here's a scenario I encounter in almost every training session. A medical coder copies a diagnosis code — say, E11.9 for Type 2 diabetes — into a personal spreadsheet to study for a certification exam. No patient name, no medical record number, no encounter date. Just a code.

Is that ePHI? No. A diagnosis code standing alone, disconnected from any individual, has no identifying link. It becomes PHI only when it's attached to — or can be reasonably connected to — a specific person.

The same logic applies to blank medical forms, template prescriptions, and clinical reference materials. They describe health information in the abstract. They don't identify anyone.

The Mistake That Leads to OCR Enforcement Actions

In my experience, the organizations that get into trouble aren't usually confused about what falls outside PHI. They're confused about what falls inside it. They assume that removing a patient's name is enough. It's not.

OCR has repeatedly emphasized that any combination of data elements that could allow re-identification qualifies as PHI. A date of birth plus a zip code plus a diagnosis can be enough. The 2011 UCLA Health System settlement — $865,500 — involved unauthorized access to celebrity patient records, reinforcing that even internal curiosity about identifiable patient data triggers enforcement.

Your workforce needs to understand both sides of this line. Every member of your staff who touches health data should know what is not considered PHI under HIPAA — and, more importantly, what still is.

How This Applies to Your Training Program

Most off-the-shelf HIPAA training spends 90% of its time on what PHI is and barely addresses the boundaries. That's a gap. When your staff can't distinguish between PHI and non-PHI, two things happen: they either over-restrict data that could be used productively, or they under-protect data they wrongly assume is safe.

Our HIPAA training for physicians and clinical environments covers this distinction with scenario-based exercises. Clinicians work through real examples — de-identified datasets, employer health records, consumer app data — and practice drawing the line. It's the kind of applied training that sticks.

For organizations with mixed roles — front desk, billing, IT, clinical — the full training catalog offers role-specific modules that address these nuances for every part of the workforce.

Quick Reference: Is It PHI?

  • Patient name + diagnosis in a medical record at a hospital: Yes, PHI.
  • Aggregate surgery counts with no patient identifiers: Not PHI.
  • Employee drug test result held by HR (employer role): Not PHI under HIPAA.
  • Student immunization record at a FERPA-covered university: Not PHI under HIPAA.
  • Heart rate data on a consumer fitness app (no covered entity involved): Not PHI.
  • A diagnosis code copied into a study guide with no patient link: Not PHI.
  • A deceased patient's chart from 2024: Still PHI (within 50 years).

The Bottom Line for Your Organization

HIPAA's reach is broad, but it isn't infinite. Data must be individually identifiable and relate to health, healthcare, or payment — and be held or transmitted by a covered entity or business associate — to qualify as PHI. Remove any one of those elements, and the data sits outside HIPAA's jurisdiction.

Knowing where the boundary falls lets your organization use data confidently for research, marketing, quality improvement, and workforce management — without exposing actual patient information. That knowledge starts with training that goes beyond definitions and into application.

Get your team trained on the full picture. The line between PHI and not-PHI isn't a technicality — it's the foundation every compliance decision rests on.