Who must comply with the HIPAA privacy standards?
3. What is “protected health information” under HIPAA? Protected health information (PHI) means individually identifiable health information maintained or transmitted in any form, whether electronically, on paper or orally. However, PHI excludes individually identifiable health information in employment records kept by a covered entity in its role as an employer (such as OSHA 300 logs or First Report of Injury forms completed by an employer for reporting purposes). [45 CFR 164.501] 4.