Is an Email Address Considered PHI?
An email address is considered PHI when it is maintained in a designated record set by a HIPAA covered entity or business associate, and the designated record set contains health, treatment, or payment information about an individual who could be identified by the email address. In all other circumstances, email addresses are not protected by HIPAA – although state privacy and security regulations may apply.
In order to answer the question is an email address considered PHI, it is best to start by discussing what is considered PHI under HIPAA. PHI is “individually identifiable health information” that relates to an individual’s health condition, treatment for the condition, or payment for the treatment, that could identify the individual or could be used along with other information maintained in the same designated record set to identify the individual.
For the purpose of clarity, a “designated record set” is a group of medical, enrollment, payment, and/or billing records maintained by a HIPAA covered entity or business associate used to make health, treatment, or payment decisions about an individual. A HIPAA regulated entity might maintain one designated record set per individual, or might maintain dozens of designated record sets per individual to manage access controls in different departments.
When is an Email Address PHI?
With regards to when is an email address PHI, an email address is considered PHI when it is maintained in the same designated record set as individually identifiable health information AND the email address could be used independently or with other information in the same designated record set to identify the subject of the information. However, it is not always the case that an email address maintained in a designated record set qualifies as PHI. For example:
A designated record set maintained by a dental office contains an x-ray of a patient’s teeth and the email address of the lab that is constructing a crown to fit over one of the teeth. The x-ray does not identify the patient, nor does the email address. Therefore, in this scenario, the email address is not considered PHI as it could not be used to identify the patient, or their health, treatment, or payment information.
However, if details of the health plan that will pay for the construction of the crown are added to the designated record set, and the details include a plan membership number that identifies the patient, the email address acquires the same protected status as the x-ray and details of the health plan and is considered PHI – even though by itself it could still not be used to identify the patient, or their health, treatment, or payment information.
When Else is an Email Address Considered PHI?
An email address does not necessarily have to belong to the subject of the PHI or be associated with their health, treatment, or payment to be considered PHI. An email address of a family member, friend, or employer could be used to identify the subject of the PHI if it is maintained in the same designated record set as the individual’s PHI – although the same email addresses would not be considered PHI if they were maintained separately.
In some cases, the same email address could be considered both PHI and not PHI. For example, if a copy of the individual’s email address is maintained in a designated record set along with health information AND a further copy of the individual’s email address is maintained in a separate database (i.e., for authorized marketing purposes) that does not contain any health, treatment, or payment information.
However, in circumstances in which email addresses are not protected by HIPAA, it is often the case that state privacy and security regulations apply and, if an unprotected database of email addresses is viewed or acquired without authorization, the event is notifiable to state attorneys general. Covered entities and business associates unsure about when is an email address considered PHI are advised to speak with an independent HIPAA compliance professional.
