PHI, PII, and PI are three different legal categories of information, each defined by a different body of law, and mixing them up leads organizations to apply the wrong safeguards. PHI (protected health information) is defined by HIPAA at 45 CFR 160.103. PII (personally identifiable information) is a broader security and privacy term defined most precisely by NIST Special Publication 800-122. PI (personal information) is the term used in most state privacy and breach notification statutes, and its scope varies by state. Knowing which category a piece of data falls into determines which rules apply to how you collect, store, transmit, and disclose it.
What Counts as PHI Under HIPAA
HIPAA defines protected health information at 45 CFR 160.103 as individually identifiable health information that is created or received by a covered entity or business associate, and that relates to a person's past, present, or future physical or mental health condition, the provision of health care, or payment for health care. The key qualifier is "individually identifiable." Health information stripped of identifiers, following the de-identification methods in 45 CFR 164.514(a) and (b), is no longer PHI.
PHI is not limited to medical charts. It includes appointment dates, billing records, insurance identifiers, and any communication, including text messages, that ties a health condition or health service to an identifiable person. A text that says "your appointment with Dr. Reyes is confirmed for Tuesday" is PHI the moment it is tied to a specific patient's phone number, because it reveals that person is receiving care from a specific provider.
PHI only exists within the HIPAA regulatory context, meaning it applies to covered entities (health plans, health care clearinghouses, and most health care providers) and their business associates. The same health data held by an employer, a school, or a fitness app outside that chain is typically not PHI, though it may still be PII or state-defined PI.
What Counts as PII Under NIST Guidance
NIST Special Publication 800-122 defines PII as any information that can be used to distinguish or trace an individual's identity, either alone or when combined with other information that is linked or linkable to a specific individual. This is a functional, risk-based definition rather than a fixed list. NIST separates PII into direct identifiers, such as a name, Social Security number, or biometric record, and indirect identifiers, such as date of birth, gender, or race, that become identifying when combined with other data points.
PII is a security and privacy framework term, not a single statute's defined term. It is used across federal guidance, including OMB memoranda and agency privacy programs, to scope what data requires protection regardless of subject matter. Unlike PHI, PII is not limited to health information. A customer's email address, home address, or account number are all PII whether or not any health context is involved.
What Counts as PI Under State Law
Most state data breach notification and privacy statutes use the term "personal information" rather than PII or PHI, and each state defines it independently. The typical structure combines a first name or initial and last name with one or more of the following: Social Security number, driver's license or state ID number, financial account number combined with a security code, or, increasingly, medical or health insurance information and biometric data. States such as California, under the California Consumer Privacy Act, use an even broader definition that includes any information that identifies, relates to, or could reasonably be linked with a particular consumer or household.
Because PI definitions are set state by state, the same data set can trigger breach notification obligations in one state and not another. An organization operating nationally has to check its data against each state's PI definition, not assume a single national standard applies.
How PHI, PII, and PI Compare
| Category | Defined By | Scope | Example |
|---|---|---|---|
| PHI | 45 CFR 160.103 (HIPAA) | Health information tied to an identifiable person, held by a covered entity or business associate | A text confirming a lab result for a named patient |
| PII | NIST SP 800-122 | Any information that can identify or trace a specific individual, regardless of subject matter | A customer's name and email address in a CRM |
| PI | State statute (varies by state) | Name plus one or more sensitive data elements, as defined by each state's breach notification or privacy law | A name combined with a driver's license number |
Where the Categories Overlap
A single data element can be PHI, PII, and PI at the same time. A patient's name paired with a diagnosis is PHI under HIPAA because it is health information tied to an identifiable person and handled by a covered entity. That same pairing is also PII under NIST's framework because it identifies a specific individual. And in most states, it also meets the statutory definition of PI because it combines a name with medical information. The categories are not mutually exclusive; they are different lenses applied by different legal frameworks to overlapping data.
This matters operationally because compliance obligations stack rather than substitute for one another. Satisfying HIPAA does not automatically satisfy a state's PI-based breach notification law, and a general PII security program does not automatically meet HIPAA's specific requirements for PHI, such as the minimum necessary standard or breach notification timelines under 45 CFR 164.400-414.
Why the Distinction Matters for Text Messaging
Organizations that communicate with patients or clients by SMS need to know which category their messages fall into before deciding how to send them. A message from a covered entity that references a health condition, appointment, or treatment is PHI, which means it falls under HIPAA's technical, administrative, and physical safeguard requirements, as covered in is texting HIPAA compliant. A message from a substance use disorder treatment program carries additional restrictions under 42 CFR Part 2, which is stricter than HIPAA in several respects and is explained in 42 CFR Part 2 vs HIPAA.
Even organizations that are not covered entities should evaluate whether the data they text qualifies as PII or state-defined PI, because state breach notification laws can apply regardless of HIPAA status. Any platform used to send health-adjacent texts should be evaluated for how it handles this layered set of obligations; see HIPAA compliant text messaging for how the requirements translate into platform features.
This article is general information, not legal advice. Requirements vary by jurisdiction and change over time, so confirm your own obligations with qualified counsel or the relevant regulator.
Frequently Asked Questions
Is a phone number PHI?
A phone number alone is not PHI. It becomes PHI when it is tied to health information about an identifiable person by a covered entity or business associate, for example when it is used to send a text about an appointment, prescription, or diagnosis. The same phone number held by a marketing company with no health context is not PHI, though it may still be PII.
Is an email address PII?
Yes. Under NIST SP 800-122, an email address is a direct or indirect identifier that can be used to distinguish or trace a specific individual, which makes it PII. Whether it also counts as PI under a given state's breach notification law depends on that state's statutory definition and whether the email is paired with other data elements.
What is the difference between PHI and PII?
PHI is a subset concept defined specifically by HIPAA at 45 CFR 160.103 and applies only to health information handled by covered entities and business associates. PII is a broader term defined by NIST that covers any data capable of identifying a specific person, in any context, health-related or not. All PHI is PII, but not all PII is PHI.
Does HIPAA use the term PII?
No. HIPAA's regulatory text uses "individually identifiable health information" and "protected health information," not PII. PII is a term used in NIST guidance and broader federal and state privacy frameworks. The concepts overlap but come from separate bodies of law and guidance.
What is considered PI under state law?
Most states define personal information as a first name or initial and last name combined with a sensitive data element such as a Social Security number, driver's license number, or financial account number. Some states, including California, use a broader definition covering any information reasonably linkable to a specific consumer or household. Definitions vary by state.
Is a home address PHI, PII, or PI?
A home address can be all three depending on context. It is PII under NIST because it can help identify a person. It becomes PHI if a covered entity holds it alongside health information for that person. It may also meet a state's PI definition if paired with other identifying elements under that state's statute.
Does de-identified health data still count as PHI?
No. Under 45 CFR 164.514, health information that has been de-identified using either the Safe Harbor method or expert determination is no longer PHI and falls outside HIPAA's requirements. Once identifiers are removed to the standard set out in that section, the data can generally be used and disclosed without HIPAA restrictions.
Why does it matter which category my data falls into?
The category determines which law applies, and different laws set different rules for consent, storage, breach notification, and disclosure. Data can be PHI, PII, and state-defined PI simultaneously, and each classification carries its own obligations that stack rather than replace one another. Misclassifying data is a common root cause of compliance gaps.
Text health information the right way
Sending appointment reminders, billing notices, or care updates by text means handling data that likely qualifies as PHI, PII, and state-defined PI at once. FRANSiS supports compliance for healthcare texting, with a signed BAA included for covered entities and business associates. Contact us to talk through how your organization's messages should be classified and handled.


