Table of Contents

Related Content

Virtual Private Skyflow

Watch our webinars
No items found.

PHI vs. PII vs. PCI: What Does Each Require for AI?

September 3, 2026

Protected health information (PHI) is individually identifiable health information that a Health Insurance Portability and Accountability Act (HIPAA) covered entity or its business associate creates, receives, maintains, or transmits. Personally identifiable information (PII) is any information that can distinguish or trace an individual's identity, alone or combined with other data.

Payment card data under the Payment Card Industry Data Security Standard (PCI DSS) is a separate classification. Card brands and acquiring banks primarily enforce this industry standard through contracts, although some state laws incorporate PCI DSS or related requirements.

This guide covers scope, obligations, de-identification, and the runtime controls that let applications and AI systems use PHI, PII, and PCI data under one consistent policy.

What Is PHI vs. PII?

PHI is identifiable health data inside HIPAA's covered-entity scope. PII is any information that can identify a person, alone or combined with other data; a broader category that spans every sector, not just healthcare, and isn't defined by one federal law.

PHI status depends on who holds the data:

  • The HIPAA Privacy Rule protects individually identifiable health information that covered entities and their business associates hold or transmit and governs its use and disclosure.
  • The Security Rule mandates administrative, physical, and technical safeguards for electronic PHI.
  • The Breach Notification Rule sets reporting deadlines. The covered-entity test sets the scope, so an organization outside HIPAA's reach may hold identical health data without that data becoming PHI.

The 18 HIPAA Identifiers That Turn Health Data Into PHI

Under 45 CFR §164.514, these 18 identifiers make health information PHI when a covered entity holds it, and Safe Harbor de-identification must remove all of them:

  1. Names
  2. Geographic subdivisions smaller than a state, including street address, city, county, and ZIP code (a limited three-digit ZIP exception applies)
  3. All date elements except year that relate to an individual, plus all ages over 89
  4. Telephone numbers
  5. Fax numbers
  6. Email addresses
  7. Social Security numbers
  8. Medical record numbers
  9. Health plan beneficiary numbers
  10. Account numbers
  11. Certificate and license numbers
  12. Vehicle identifiers and serial numbers, including license plates
  13. Device identifiers and serial numbers
  14. Web URLs
  15. IP addresses
  16. Biometric identifiers, including finger and voice prints
  17. Full-face photographs and comparable images
  18. Any other unique identifying number, characteristic, or code

These categories define the Safe Harbor removal test, while PII uses a broader linked-or-linkable standard.

PHI vs. PII vs. PCI: Core Differences and Where They Overlap

The PHI vs PII relationship is one-directional: every PHI record contains PII, since identifiability is part of PHI's definition, but PII becomes PHI only when it links to health information inside a covered entity. 

PCI DSS account data breaks into two categories: 

  1. Cardholder data (the primary account number, plus the cardholder name, expiration date, or service code when present) 
  2. Sensitive authentication data (full track data, verification codes, and PINs), which PCI DSS prohibits merchants from retaining after authorization. 

The PCI Security Standards Council (PCI SSC) publishes the standard; card brands and acquiring banks enforce it through merchant contracts.

Dimension PHI PII Cardholder data (PCI)
Governing authority HIPAA (federal law) No single law; NIST definition plus state and sector statutes PCI DSS v4.0.1, an industry standard
Scope Health data plus identifiers that covered entities and business associates hold Any data identifying an individual, in any industry PAN and, when present, cardholder name, expiration date, service code
Enforcement HHS OCR (civil); DOJ (criminal) Varies by statute. Authorities include state attorneys general and sector regulators, as well as non-U.S. authorities Card brands and acquirers, through merchant contracts
Breach obligations Federal deadlines govern notice to affected individuals and HHS. Large breaches can also require media notice Varies by state and statute Contractual consequences via acquirers, including assessments and fee increases. Processing may also be suspended
Penalties Tiered civil fines plus criminal exposure Varies by statute Acquirers pass through non-compliance assessments

A single patient billing record can carry PII through a name and address. A diagnosis code adds PHI, while a card number adds PCI data, each with separate obligations.

When Does PII Become PHI?

All PHI is PII, but not all PII is PHI: the same name or IP address is PHI only when it connects to health information that a HIPAA-regulated organization holds. A data holder's role and use of the information determine PHI status. OCR's de-identification guidance states that a name or phone number in a phone book is not PHI, but the same name listed with a health condition or treatment record is.

HIPAA excludes employment records a covered entity maintains in its capacity as an employer, so a hospital's HR file on a nurse is PII but not PHI. FERPA, not HIPAA, protects student health records a school nurse maintains under the school's direct control. Fitness tracker data is not PHI in a patient's own hands but becomes PHI once a covered entity holds it.

Health information a regulated entity collects through its website or app is generally PHI: OCR's online tracking guidance applies that treatment to IP addresses, device IDs, and geolocation. A physical therapy app that transmits a user's name, mobile number, or IP address to a tracking vendor discloses PHI, because app use relates to the individual's health condition.

Compliance Obligations and Penalties That Apply to PHI but Not General PII

HIPAA imposes duties no general PII statute carries. A covered entity must execute a business associate agreement (BAA) before a vendor acting as a business associate creates, receives, maintains, or transmits PHI, apply Security Rule safeguards to electronic PHI, limit disclosures to the minimum necessary, and publish a notice of privacy practices.

The Breach Notification Rule requires individual notice without unreasonable delay and no later than 60 calendar days after discovery. Breaches affecting 500 or more individuals require contemporaneous notice to HHS and, if they affect more than 500 residents of a state, media notice too; smaller breaches get reported to HHS annually. Business associates owe covered entities notice on the same 60-day clock.

Civil penalties reach up to $2.19 million per violation tier annually under the 2026 inflation adjustment, and criminal misuse of health information for commercial gain or malicious harm carries fines up to $250,000 and 10 years' imprisonment under 42 U.S.C. §1320d-6

General PII carries no equivalent federal penalty structure, so consequences depend on which state or foreign law applies. PCI DSS non-compliance instead produces contractual assessments; Visa's published amounts reach $100,000 per incident for Level 1 and 2 merchants, which acquirers pass through.

How to De-Identify PHI So HIPAA No Longer Applies

Safe Harbor, the first of two routes out of HIPAA scope under §164.514, requires removing all 18 identifier categories, then confirming the organization has no actual knowledge that the remaining information could identify someone. OCR defines actual knowledge as clear and direct knowledge, so a dataset with an unusual combination of remaining fields still fails if staff can recognize the person.

Under Expert Determination, a person with appropriate statistical and scientific expertise determines that the anticipated recipient faces a very small risk of re-identifying someone, and documents the methods and results. 

OCR requires no specific credential and sets no universal numeric risk threshold, but the organization must make the documentation available to OCR on request. OCR permits keyed cryptographic hashes provided the entity does not disclose the keys, and notes that properly de-identified data still carries a small, nonzero re-identification risk.

A Limited Data Set supports research, public health, and health care operations that need dates or geography. It strips 16 direct identifiers but may retain city, state, ZIP code, and dates like birth and admission. It remains PHI and requires a written data use agreement that limits use, requires safeguards, and prohibits re-identification.

PII Beyond HIPAA: State Laws, GDPR, and Other Frameworks

Data outside HIPAA still carries statutory duties, and for a healthcare organization, they often cover the records HIPAA exempts. Four frameworks matter most:

  • California Consumer Privacy Act (CCPA) / California Privacy Rights Act (CPRA): California grants record-management rights covering deletion, correction, and opt-out. The HIPAA exemption applies at the data level, so a hospital's analytics, marketing, and employee data all stay covered.
  • State breach-notification laws: Most U.S. states impose notification duties, with triggers and clocks that vary by statute.
  • General Data Protection Regulation (GDPR): Health data is an Article 9 special category. Article 33 requires regulator breach notification within 72 hours, and Article 83 authorizes fines up to 4 percent of worldwide annual turnover.
  • India's Digital Personal Data Protection (DPDP) Act: The DPDP Act sets steep penalties for security failures, with obligations mandatory from 2027.

The EU AI Act classifies healthcare-eligibility, health-insurance pricing, and emergency triage systems as high-risk, with those obligations phasing in from late 2027.

How Skyflow Protects PHI, PII, and PCI Across Systems

Skyflow is a Runtime AI Data Control Platform that isolates PHI, PII, and PCI data in a Data Privacy Vault and applies policy on each request from applications and AI systems. Downstream systems work with tokens instead of raw values, and Policy-Based Access Control evaluates identity, action, region, and consent per request, so a support agent sees a masked value while a sensitive application sees the full value. A custom schema builder maps the 18 HIPAA identifiers to vault fields, so the vault can apply field-level controls for records governed by HIPAA, PCI DSS, GDPR, and CCPA.

For health data specifically, Skyflow Detect de-identifies text, audio, images, and PDFs while preserving clinical context. A compromised application can expose tokens rather than usable PHI or card numbers, which contains the blast radius rather than preventing intrusion.

Control PHI, PII, and PCI at the Data Layer with Skyflow

Operational control starts with classifying each record by who holds it and how the organization uses it. Applying tokenization and access policy at the data layer creates audit evidence while helping applications and AI systems meet HIPAA, payment-card, and privacy requirements without distributing raw sensitive values across downstream systems.

Teams building AI systems that touch health, personal, or payment data can book a demo to see how Skyflow's vault architecture and deployment models keep that data usable without exposing it downstream.

Frequently Asked Questions about PHI, PII, and PCI

What Is the Difference Between PHI and PII?

PII is any information that identifies an individual. PHI is the subset that a HIPAA covered entity or business associate holds and that links identifiers to health information.

What Are the 18 HIPAA Identifiers?

They are the identifier categories in 45 CFR §164.514(b)(2) that make health data individually identifiable: names, geographic data below the state level, dates, contact details, Social Security numbers, medical record and account numbers, biometrics, and any other unique code. 

When Does PII Held by a Healthcare Organization Become PHI?

When the data relates to health status or care and the organization is a covered entity or business associate. Per OCR guidance, an IP address or device ID a regulated entity's app collects is generally PHI, while employment records held in the organization's capacity as an employer stay outside HIPAA.

What Are the Penalties for a PHI Breach Under HIPAA?

Civil penalties are tiered by culpability, reaching up to $2.19 million per violation tier annually under the 2026 inflation adjustment. Criminal misuse for commercial gain or malicious harm carries fines of up to $250,000 and up to 10 years' imprisonment.

Related Content

Data Privacy Vault
Data Governance
Data Privacy & Security
Compliance

How Can Global Capability Centers Securely Process Healthcare Data?

Related Content

How Can Global Capability Centers Securely Process Healthcare Data?

PHI vs. PII vs. PCI: What Does Each Require for AI?

September 3, 2026

Protected health information (PHI) is individually identifiable health information that a Health Insurance Portability and Accountability Act (HIPAA) covered entity or its business associate creates, receives, maintains, or transmits. Personally identifiable information (PII) is any information that can distinguish or trace an individual's identity, alone or combined with other data.

Payment card data under the Payment Card Industry Data Security Standard (PCI DSS) is a separate classification. Card brands and acquiring banks primarily enforce this industry standard through contracts, although some state laws incorporate PCI DSS or related requirements.

This guide covers scope, obligations, de-identification, and the runtime controls that let applications and AI systems use PHI, PII, and PCI data under one consistent policy.

What Is PHI vs. PII?

PHI is identifiable health data inside HIPAA's covered-entity scope. PII is any information that can identify a person, alone or combined with other data; a broader category that spans every sector, not just healthcare, and isn't defined by one federal law.

PHI status depends on who holds the data:

  • The HIPAA Privacy Rule protects individually identifiable health information that covered entities and their business associates hold or transmit and governs its use and disclosure.
  • The Security Rule mandates administrative, physical, and technical safeguards for electronic PHI.
  • The Breach Notification Rule sets reporting deadlines. The covered-entity test sets the scope, so an organization outside HIPAA's reach may hold identical health data without that data becoming PHI.

The 18 HIPAA Identifiers That Turn Health Data Into PHI

Under 45 CFR §164.514, these 18 identifiers make health information PHI when a covered entity holds it, and Safe Harbor de-identification must remove all of them:

  1. Names
  2. Geographic subdivisions smaller than a state, including street address, city, county, and ZIP code (a limited three-digit ZIP exception applies)
  3. All date elements except year that relate to an individual, plus all ages over 89
  4. Telephone numbers
  5. Fax numbers
  6. Email addresses
  7. Social Security numbers
  8. Medical record numbers
  9. Health plan beneficiary numbers
  10. Account numbers
  11. Certificate and license numbers
  12. Vehicle identifiers and serial numbers, including license plates
  13. Device identifiers and serial numbers
  14. Web URLs
  15. IP addresses
  16. Biometric identifiers, including finger and voice prints
  17. Full-face photographs and comparable images
  18. Any other unique identifying number, characteristic, or code

These categories define the Safe Harbor removal test, while PII uses a broader linked-or-linkable standard.

PHI vs. PII vs. PCI: Core Differences and Where They Overlap

The PHI vs PII relationship is one-directional: every PHI record contains PII, since identifiability is part of PHI's definition, but PII becomes PHI only when it links to health information inside a covered entity. 

PCI DSS account data breaks into two categories: 

  1. Cardholder data (the primary account number, plus the cardholder name, expiration date, or service code when present) 
  2. Sensitive authentication data (full track data, verification codes, and PINs), which PCI DSS prohibits merchants from retaining after authorization. 

The PCI Security Standards Council (PCI SSC) publishes the standard; card brands and acquiring banks enforce it through merchant contracts.

Dimension PHI PII Cardholder data (PCI)
Governing authority HIPAA (federal law) No single law; NIST definition plus state and sector statutes PCI DSS v4.0.1, an industry standard
Scope Health data plus identifiers that covered entities and business associates hold Any data identifying an individual, in any industry PAN and, when present, cardholder name, expiration date, service code
Enforcement HHS OCR (civil); DOJ (criminal) Varies by statute. Authorities include state attorneys general and sector regulators, as well as non-U.S. authorities Card brands and acquirers, through merchant contracts
Breach obligations Federal deadlines govern notice to affected individuals and HHS. Large breaches can also require media notice Varies by state and statute Contractual consequences via acquirers, including assessments and fee increases. Processing may also be suspended
Penalties Tiered civil fines plus criminal exposure Varies by statute Acquirers pass through non-compliance assessments

A single patient billing record can carry PII through a name and address. A diagnosis code adds PHI, while a card number adds PCI data, each with separate obligations.

When Does PII Become PHI?

All PHI is PII, but not all PII is PHI: the same name or IP address is PHI only when it connects to health information that a HIPAA-regulated organization holds. A data holder's role and use of the information determine PHI status. OCR's de-identification guidance states that a name or phone number in a phone book is not PHI, but the same name listed with a health condition or treatment record is.

HIPAA excludes employment records a covered entity maintains in its capacity as an employer, so a hospital's HR file on a nurse is PII but not PHI. FERPA, not HIPAA, protects student health records a school nurse maintains under the school's direct control. Fitness tracker data is not PHI in a patient's own hands but becomes PHI once a covered entity holds it.

Health information a regulated entity collects through its website or app is generally PHI: OCR's online tracking guidance applies that treatment to IP addresses, device IDs, and geolocation. A physical therapy app that transmits a user's name, mobile number, or IP address to a tracking vendor discloses PHI, because app use relates to the individual's health condition.

Compliance Obligations and Penalties That Apply to PHI but Not General PII

HIPAA imposes duties no general PII statute carries. A covered entity must execute a business associate agreement (BAA) before a vendor acting as a business associate creates, receives, maintains, or transmits PHI, apply Security Rule safeguards to electronic PHI, limit disclosures to the minimum necessary, and publish a notice of privacy practices.

The Breach Notification Rule requires individual notice without unreasonable delay and no later than 60 calendar days after discovery. Breaches affecting 500 or more individuals require contemporaneous notice to HHS and, if they affect more than 500 residents of a state, media notice too; smaller breaches get reported to HHS annually. Business associates owe covered entities notice on the same 60-day clock.

Civil penalties reach up to $2.19 million per violation tier annually under the 2026 inflation adjustment, and criminal misuse of health information for commercial gain or malicious harm carries fines up to $250,000 and 10 years' imprisonment under 42 U.S.C. §1320d-6

General PII carries no equivalent federal penalty structure, so consequences depend on which state or foreign law applies. PCI DSS non-compliance instead produces contractual assessments; Visa's published amounts reach $100,000 per incident for Level 1 and 2 merchants, which acquirers pass through.

How to De-Identify PHI So HIPAA No Longer Applies

Safe Harbor, the first of two routes out of HIPAA scope under §164.514, requires removing all 18 identifier categories, then confirming the organization has no actual knowledge that the remaining information could identify someone. OCR defines actual knowledge as clear and direct knowledge, so a dataset with an unusual combination of remaining fields still fails if staff can recognize the person.

Under Expert Determination, a person with appropriate statistical and scientific expertise determines that the anticipated recipient faces a very small risk of re-identifying someone, and documents the methods and results. 

OCR requires no specific credential and sets no universal numeric risk threshold, but the organization must make the documentation available to OCR on request. OCR permits keyed cryptographic hashes provided the entity does not disclose the keys, and notes that properly de-identified data still carries a small, nonzero re-identification risk.

A Limited Data Set supports research, public health, and health care operations that need dates or geography. It strips 16 direct identifiers but may retain city, state, ZIP code, and dates like birth and admission. It remains PHI and requires a written data use agreement that limits use, requires safeguards, and prohibits re-identification.

PII Beyond HIPAA: State Laws, GDPR, and Other Frameworks

Data outside HIPAA still carries statutory duties, and for a healthcare organization, they often cover the records HIPAA exempts. Four frameworks matter most:

  • California Consumer Privacy Act (CCPA) / California Privacy Rights Act (CPRA): California grants record-management rights covering deletion, correction, and opt-out. The HIPAA exemption applies at the data level, so a hospital's analytics, marketing, and employee data all stay covered.
  • State breach-notification laws: Most U.S. states impose notification duties, with triggers and clocks that vary by statute.
  • General Data Protection Regulation (GDPR): Health data is an Article 9 special category. Article 33 requires regulator breach notification within 72 hours, and Article 83 authorizes fines up to 4 percent of worldwide annual turnover.
  • India's Digital Personal Data Protection (DPDP) Act: The DPDP Act sets steep penalties for security failures, with obligations mandatory from 2027.

The EU AI Act classifies healthcare-eligibility, health-insurance pricing, and emergency triage systems as high-risk, with those obligations phasing in from late 2027.

How Skyflow Protects PHI, PII, and PCI Across Systems

Skyflow is a Runtime AI Data Control Platform that isolates PHI, PII, and PCI data in a Data Privacy Vault and applies policy on each request from applications and AI systems. Downstream systems work with tokens instead of raw values, and Policy-Based Access Control evaluates identity, action, region, and consent per request, so a support agent sees a masked value while a sensitive application sees the full value. A custom schema builder maps the 18 HIPAA identifiers to vault fields, so the vault can apply field-level controls for records governed by HIPAA, PCI DSS, GDPR, and CCPA.

For health data specifically, Skyflow Detect de-identifies text, audio, images, and PDFs while preserving clinical context. A compromised application can expose tokens rather than usable PHI or card numbers, which contains the blast radius rather than preventing intrusion.

Control PHI, PII, and PCI at the Data Layer with Skyflow

Operational control starts with classifying each record by who holds it and how the organization uses it. Applying tokenization and access policy at the data layer creates audit evidence while helping applications and AI systems meet HIPAA, payment-card, and privacy requirements without distributing raw sensitive values across downstream systems.

Teams building AI systems that touch health, personal, or payment data can book a demo to see how Skyflow's vault architecture and deployment models keep that data usable without exposing it downstream.

Frequently Asked Questions about PHI, PII, and PCI

What Is the Difference Between PHI and PII?

PII is any information that identifies an individual. PHI is the subset that a HIPAA covered entity or business associate holds and that links identifiers to health information.

What Are the 18 HIPAA Identifiers?

They are the identifier categories in 45 CFR §164.514(b)(2) that make health data individually identifiable: names, geographic data below the state level, dates, contact details, Social Security numbers, medical record and account numbers, biometrics, and any other unique code. 

When Does PII Held by a Healthcare Organization Become PHI?

When the data relates to health status or care and the organization is a covered entity or business associate. Per OCR guidance, an IP address or device ID a regulated entity's app collects is generally PHI, while employment records held in the organization's capacity as an employer stay outside HIPAA.

What Are the Penalties for a PHI Breach Under HIPAA?

Civil penalties are tiered by culpability, reaching up to $2.19 million per violation tier annually under the 2026 inflation adjustment. Criminal misuse for commercial gain or malicious harm carries fines of up to $250,000 and up to 10 years' imprisonment.