{"id":974,"date":"2021-06-06T17:00:00","date_gmt":"2021-06-06T17:00:00","guid":{"rendered":"https:\/\/dataprivacyparty.com\/?p=974"},"modified":"2021-06-23T14:18:24","modified_gmt":"2021-06-23T14:18:24","slug":"hipaa-what-exactly-is-personal-health-information","status":"publish","type":"post","link":"https:\/\/dataprivacyparty.com\/?p=974","title":{"rendered":"HIPAA: What Exactly is Personal Health Information?"},"content":{"rendered":"\n<div class=\"wp-block-image is-style-default\"><figure class=\"aligncenter size-large is-resized\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/dataprivacyparty.com\/wp-content\/uploads\/2021\/05\/PHI-Ven-Diagram.png?resize=544%2C303&#038;ssl=1\" alt=\"\" class=\"wp-image-977\" width=\"544\" height=\"303\" srcset=\"https:\/\/i0.wp.com\/dataprivacyparty.com\/wp-content\/uploads\/2021\/05\/PHI-Ven-Diagram.png?resize=1024%2C573&amp;ssl=1 1024w, https:\/\/i0.wp.com\/dataprivacyparty.com\/wp-content\/uploads\/2021\/05\/PHI-Ven-Diagram.png?resize=300%2C168&amp;ssl=1 300w, https:\/\/i0.wp.com\/dataprivacyparty.com\/wp-content\/uploads\/2021\/05\/PHI-Ven-Diagram.png?w=1340&amp;ssl=1 1340w\" sizes=\"auto, (max-width: 544px) 100vw, 544px\" \/><\/figure><\/div>\n\n\n\n<p>Personal health information, or PHI for short, is the broad term used to encompass all health-related information that can be used to accurately identify an individual. You can use your imagination, but Table 1 below shows several different instances of what PHI can be.<\/p>\n\n\n\n<figure class=\"wp-block-table is-style-stripes\"><table><tbody><tr><td>Names (First, Middle, Last)<\/td><td>SSN<\/td><td>Email Address<\/td><td>Physical Address<\/td><td>Health Insurance Account Numbers\/Details<\/td><\/tr><tr><td>Medical History<\/td><td>Pictures of the Individual<\/td><td>Health Plan Numbers<\/td><td>Lab Tests<\/td><td>Drivers License Numbers<\/td><\/tr><tr><td>Birth Dates (except when only the year is present)<\/td><td>IP Addresses<\/td><td>Biometric Identifiers (voice, fingerprints, retinal)<\/td><td>Telephone Numbers<\/td><td>Vehicle IDs (License Plates)<\/td><\/tr><tr><td>Any other unique code<\/td><td>FAX numbers<\/td><td>Website URLs<\/td><td>Certificate number(s)<\/td><td>Device identifiers and serial numbers<\/td><\/tr><\/tbody><\/table><figcaption>TABLE 1<\/figcaption><\/figure>\n\n\n\n<p>As you can see, these aren&#8217;t lumped into any specific category. That&#8217;s because once they&#8217;re all connected, they can uniquely identify an individual. However, not all of these categories need to have a value in order to identify the individual. In some cases, we may only need their name and physical address to uniquely identify them. But sometimes, we may only have their IP address and lab test results. The latter would be much more difficult to use to identify an individual, but this is still considered PHI by the HIPAA Rule because of the potential, when combined, to identify an individual if it fell into the wrong hands.<\/p>\n\n\n\n<p>Essentially, anything related to your personal information and health can be lumped into a category we see above. However, revealing these instances wouldn&#8217;t be a violation if done by a non-CE, or anything not considered a covered entity. An example of personal health information would be my resting heart rate (RHR) or heart rate variance (HRV). My favorite fitness tracker is the WHOOP band, which tells you both of these numbers daily. My RHR is the rate at which my heart beats while my body is in a state of &#8220;rest,&#8221; or when I am asleep and in a comfortable state. My HRV is the variance of my heart rate. If I told you these numbers, this would not be a HIPAA violation. If WHOOP told you these numbers, it would not be a violation. If my hospital told you these numbers, it would be a violation of HIPAA.<\/p>\n\n\n\n<p>Based on the example above, it&#8217;s important to know that an employer asking for proof of your COVID-19 vaccination is NOT a HIPAA violation. This is no different than a university requiring proof of vaccines for measles, mumps, or COVID-19. Your employer asking if you received a vaccine is not a violation. They do not intend to share that information with others and must properly secure it to adhere to the HIPAA Security Rule. I can&#8217;t stress enough, THIS IS NOT A VIOLATION!<\/p>\n\n\n\n<p class=\"has-text-align-center\"><strong><em>RECENT REPORTED PHI BREACHES<\/em><\/strong><\/p>\n\n\n\n<p><strong>5\/26\/2021<\/strong> &#8211;  LogicGate identified a security incident that potentially exposed the PHI of 47,035 individuals. This was caused by an unauthorized individual gaining stolen credentials for the AWS cloud storage servers. The files were decrypted by the attacker was able to view the customer data.<\/p>\n\n\n\n<p><strong>6\/2\/2021 &#8211; <\/strong>Temple University Hospital, Inc. experienced a breach of unauthorized access and information disclosure. This affected the PHI of 16,356 individuals.<\/p>\n\n\n\n<p><strong>5\/28\/2021 &#8211; <\/strong>Lafourche Medical Group experienced a breach, via email, where the PHI of 34,862 individuals was exposed. This incident was the result of a hacking incident in which no business associate was present and the company was the victim of a hack.<\/p>\n\n\n\n<p><strong>5\/26\/2021 &#8211; <\/strong>Aetna ACE experienced a breach in which 562 individuals were affected. Unauthorized access to hard copies of information allowed for the information to be inappropriately disclosed, in violation of HIPAA.<\/p>\n\n\n\n<p>The above breaches show that no matter how large your company or how small the loss of information is, if you&#8217;re a covered entity or a business associate, you&#8217;re on the hook for anything that happens in your company.<\/p>\n\n\n\n<p class=\"has-text-align-center\"><strong><em>SHORT RECAP<\/em><\/strong><\/p>\n\n\n\n<p>Any information that can uniquely identify you from other people would fall into the umbrella of PHI. Anything listed in the table above is a category of PHI. And occasionally, the definitions will be updated to stay current. So don&#8217;t fall behind! One of the best sources of information would be to read the HIPAA Journal if you want to know more!<\/p>\n\n\n\n<p>We will go over the details around Covered Entities, Business Associates, and Hybrid Entities in another letter!<\/p>\n\n\n\n<hr class=\"wp-block-separator is-style-default\"\/>\n\n\n<div class=\"wp-block-jetpack-contact-form is-layout-flex wp-container-jetpack-contact-form-is-layout-faa3ad1c wp-block-jetpack-contact-form-is-layout-flex\"><a href=\"https:\/\/dataprivacyparty.com\/?p=974\" target=\"_blank\" rel=\"noopener noreferrer\">Submit a form.<\/a><\/div>\n\n\n<p>See the <a href=\"https:\/\/dataprivacyparty.com\/newsletter\/\">Newsletters<\/a> page for the latest content and to subscribe to the regular update, see the <a href=\"https:\/\/dataprivacyparty.com\/about\/\">About<\/a> page for information around who DPP is, and check out the <a href=\"https:\/\/dataprivacyparty.com\/contact\/\">Contact<\/a> page to reach out to DPP with any questions or concerns. These are my thoughts and should not be taken as professional advice simply because you are not paying me for my opinion.<\/p>\n\n\n\n<p>Once you understand how valuable your information is, then you can begin taking steps to keep it private.<\/p>\n\n\n<div class=\"wp-block-jetpack-contact-form is-layout-flex wp-container-jetpack-contact-form-is-layout-faa3ad1c wp-block-jetpack-contact-form-is-layout-flex\"><a href=\"https:\/\/dataprivacyparty.com\/?p=974\" target=\"_blank\" rel=\"noopener noreferrer\">Submit a form.<\/a><\/div>\n\n\n<p><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Personal health information, or PHI for short, is the broad term used to encompass all health-related information that can be used to accurately identify an individual. You can use your imagination, but Table 1 below shows several different instances of what PHI can be. Names (First, Middle, Last) SSN Email Address Physical Address Health Insurance [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"nf_dc_page":"","om_disable_all_campaigns":false,"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"episode_type":"","audio_file":"","podmotor_file_id":"","podmotor_episode_id":"","cover_image":"","cover_image_id":"","duration":"","filesize":"","filesize_raw":"","date_recorded":"","explicit":"","block":"","itunes_episode_number":"","itunes_title":"","itunes_season_number":"","itunes_episode_type":"","_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"HIPAA: What Exactly is Personal Health Information?\n#dataprivacy #dataprivacyparty","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":true,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2}},"categories":[21],"tags":[19],"class_list":["post-974","post","type-post","status-publish","format-standard","hentry","category-hipaa","tag-hipaa","has-post-thumbnail","fallback-thumbnail"],"aioseo_notices":[],"jetpack_publicize_connections":[],"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"jetpack_likes_enabled":true,"_links":{"self":[{"href":"https:\/\/dataprivacyparty.com\/index.php?rest_route=\/wp\/v2\/posts\/974","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/dataprivacyparty.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/dataprivacyparty.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/dataprivacyparty.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/dataprivacyparty.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=974"}],"version-history":[{"count":5,"href":"https:\/\/dataprivacyparty.com\/index.php?rest_route=\/wp\/v2\/posts\/974\/revisions"}],"predecessor-version":[{"id":1030,"href":"https:\/\/dataprivacyparty.com\/index.php?rest_route=\/wp\/v2\/posts\/974\/revisions\/1030"}],"wp:attachment":[{"href":"https:\/\/dataprivacyparty.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=974"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/dataprivacyparty.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=974"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/dataprivacyparty.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=974"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}