decoded/phi/
Decoded #7, part 1: PII vs PHI
PII says who you are. PHI is that same information once it becomes part of your care.
Most of us have spent years protecting PII like names, emails, addresses, etc. The stuff that says who someone is.
PHI sounds like a tougher, more regulated version of that. Protected health information. But it's not really a different kind of data. It's the same information after it becomes part of someone's care.
HIPAA is the law that draws that line, and it draws it in a place people don't expect. HIPAA doesn't protect health facts wherever they show up. It protects them once they're part of a healthcare service. Treatment, billing, or the medical record.
Same fact, different rules, depending on how it got there. Your heart rate in a fitness app is just personal data. That same heart rate in your doctor's chart is protected health information, because now it's part of treating you. The number didn't change. Where it lives did.
That used to be the whole story. But health data doesn't stay with the doctor anymore. It's in our apps, our search history, our shopping carts, and the law is still trying to catch up to all the health information that never touches a clinic at all.
So the useful frame: PII says who you are. PHI is that same information once it becomes part of your care. The harder question we're all circling now is what we owe the rest of it.