PII and PHI are often used interchangeably, but they aren't the same thing, and mixing them up can lead to compliance mistakes. TechTarget's article makes the same point, noting that, “Using the terms interchangeably fails to recognize the intricacies of each and can lead to compliance issues for healthcare organizations.”

 

What is PII?

Personally identifiable information (PII) is any information that can identify a specific person, either on its own or when combined with other data. TechTarget, drawing on NIST's definition, describes it as anything directly or indirectly linked to an individual's identity. In homeless services, common examples include:

  • Full name and aliases
  • Date of birth
  • Social Security number
  • Photo ID or driver's license number
  • Phone number, email address, or last known address
  • Biometric data such as fingerprints
  • Household composition and family members' names

PII is broad. Even details that seem harmless, like a first name plus the shelter where someone sleeps, can identify a person when put together. In small communities, a few data points can be enough to single someone out.

HUD's HMIS rules use a closely related term, "protected personal information" (PPI). Under HUD's Data and Technical Standards Final Notice, PPI covers information about a living homeless individual that "identifies, either directly or indirectly, a specific individual." It also covers information that can be manipulated or linked with other data to identify someone.

 

What Is PHI?

Protected health information (PHI) is a more specific category. Under HIPAA's definitions, it is individually identifiable health information, meaning information that relates to a person's "past, present, or future physical or mental health or condition," to the provision of health care, or to payment for care. It must be held by a HIPAA-covered entity, such as a healthcare provider, health plan, or clearinghouse, or by their business associates. Examples include:

  • Diagnoses and treatment records
  • Medication lists
  • Mental health notes
  • Appointment details
  • Insurance and billing information

The difference is that all PHI contains PII, but not all PII is PHI. TechTarget offers an illustration, an address or phone number alone is not PHI, but once it's paired with a health condition or treatment plan, it becomes PHI. According to TechTarget, identifiable health information isn't PHI unless the organization holding it is a HIPAA-covered entity, and not everything a covered entity holds qualifies either. It cites an HHS example of a health plan report that only states the average age of its members, which identifies no one and so isn't PHI.

HIPAA also includes a list of 18 identifiers. It is the "Safe Harbor" method for de-identifying health data. Health information is treated as de-identified only if these identifiers are removed for the individual and for their relatives, employers, and household members, and the covered entity has no actual knowledge that what remains could identify someone. The list includes names, most dates, and "a]ll geographic subdivisions smaller than a State," including street address, city, and county, along with biometric identifiers.

Learn more: Examples of protected health information (PHI) in healthcare

 

Why the distinction matters in homeless services

Homeless services may include street outreach teams, emergency shelters, housing navigators, and healthcare programs like Health Care for the Homeless clinics. Each may fall under different rules. Many homeless service providers are not HIPAA-covered entities. HUD said as much when it issued its HMIS standards, stating its understanding that "very few homeless service providers are 'covered entities' under HIPAA". A shelter or housing nonprofit that doesn't bill insurance or provide clinical care usually isn't bound by HIPAA.

The Homeless Management Information System (HMIS) is the main data system for most providers funded by HUD. HMIS follows the privacy and security standards in HUD's 2004 Final Notice, which set baseline requirements for data collection, consent, access, and storage. HUD's own guidance says communities are still expected to adhere to Sections 4 (Privacy and Security) and 5 (Technical Standards) of that notice alongside the newer HMIS Data Standards (HUD Exchange).

HUD designed those standards with HIPAA in mind. The Final Notice explains that the HIPAA Privacy Rule served as a guide, that in several instances the HMIS requirements exceed HIPAA's, and that a provider which is a HIPAA covered entity follows HIPAA instead. That exemption avoids conflicts between the two sets of rules. A provider that is not a covered entity follows the HMIS standards plus applicable state and local privacy law. So even when health information such as disability status or HIV/AIDS status is entered into HMIS, it falls under HUD's rules rather than HIPAA, unless the organization is also a covered entity.

HUD also built health-data caution into the collection process. Under the Final Notice, staff may not collect health-related information (physical disability, developmental disability, HIV/AIDS, mental health, substance use) at intake unless it's a statutory or regulatory eligibility requirement. Providers also cannot deny services to an otherwise eligible person because of disability or health status. However, if an organization runs a clinic, employs licensed clinicians who bill electronically, or partners with healthcare providers, HIPAA may apply to that part of the work. Some organizations are "hybrid entities," with HIPAA applying to some programs and not others.

 

Other rules to consider

Besides HIPAA and HUD, other laws can apply:

  • VAWA (Violence Against Women Act): Victim service providers are prohibited from entering client data into HMIS and must use a comparable database instead. Survivors' safety depends on their location and identity staying confidential.
  • 42 CFR Part 2: Substance use disorder treatment records receive extra federal protection, often stricter than HIPAA, with tight limits on redisclosure.
  • State laws: Many states have stronger privacy rules around mental health, HIV status, minors' records, or data breaches. For instance, California’s Confidentiality of Medical Information Act (CMIA), covers "medical information," defined as identifiable information about a patient's "medical history, mental or physical condition, or treatment". Providers generally need the patient's authorization before disclosing that information, and patients can bring a civil action over improper disclosure. Since CMIA's scope comes from California law rather than HIPAA's covered entity rules, a clinic or health program in California can be subject to it even where HIPAA doesn't apply.

 

Best practices

When an organization isn't sure which information counts as PII or PHI, or which rules apply, these practices can bring clarity and protect clients.

1. Map the data. Organizations should know what they collect, where it lives, who can see it, and which laws apply. As NIST's guide to protecting PII puts it, "An organization cannot properly protect PII it does not know about".

2. Collect only what is needed. If a piece of information isn't required to deliver services or meet a funder's requirements, it shouldn't be collected, because data that isn't held can't be breached. NIST recommends rating PII as low, moderate, or high impact based on the harm if it were exposed. HUD's HMIS standards point the same way, data must be collected by lawful and fair means, and a client can't be denied service for lacking or refusing an SSN unless a statute requires it for the program.

3. Obtain consent. Clients should be told in simple terms what is being collected, why, and who will see it. HMIS providers must post a sign at intake explaining why information is collected and maintain a privacy notice.

4. Limit access by role. Staff and volunteers should see only what their roles require.

5. Secure the basics.HUD's HMIS baseline already expects password protection, firewalls, and auto-locking screens. A clear plan for lost devices or exposed data should be in place before an incident.

6. Put data sharing in writing. Every exchange across housing, healthcare, and social services should be governed by a written agreement covering purpose, limits, and responsibilities. HIPAA sets the model, a covered entity may share PHI with a business associate only after obtaining "satisfactory assurance that the business associate will appropriately safeguard the information," documented in a written contract meeting.

 

FAQs

What counts as a data breach?

A data breach is any incident in which personal information is accessed, used, or disclosed without authorization, including hacking, a lost device, or an email sent to the wrong person.

 

Do privacy protections apply to paper records?

Yes, because sign-in sheets, printed notes, and intake forms hold the same sensitive details as electronic files and need locked storage and controlled access.

 

Can clients see their own records?

Yes, both HIPAA and HUD's HMIS standards give individuals a right to access their own information.

 

What is a privacy notice?

A privacy notice is a plain-language statement of what information an organization collects, why it collects it, how it is used, and who it may be shared with.