Protected health information
Also known as PHI, ePHI
Health information that can be tied to an individual, in any form, held by a covered entity or its business associates.
It is broader than medical records. Appointment schedules, billing data, insurance details, and even the fact that someone is a patient all qualify when linked to an identifiable person.
Electronic PHI is what the Security Rule addresses, and it lives in more places than the practice management system: email, scanned documents, imaging, backups, and increasingly cloud collaboration tools.
Where this comes up
Protected health information sits inside our compliance and frameworks work. If you are trying to work out what this means for your own environment rather than in the abstract, that is the page worth reading next, and a short call will get you a straight answer faster than either.