What is Protected health information (PHI)?
Protected health information is any individually identifiable health information a covered entity creates or holds: names tied to treatments, chart notes, consent forms, clinical photos, appointment types, even an email address in a clinical context. HIPAA's Privacy and Security Rules govern how PHI is stored, accessed, shared, and disclosed.
How it works in an aesthetic clinic
A before-and-after photo with a recognizable face is PHI. So is a calendar entry reading 'Jane D., Botox, 3pm.' The clinic maps where PHI lives (platform, phones, inboxes), restricts access by role, encrypts it, and treats marketing use as a separate written authorization. A staff member's personal phone gallery is where PHI turns up in audits.
Protected health information (PHI) vs PII
| Protected health information (PHI) | Identifiable health information held by a covered entity, governed by HIPAA |
|---|---|
| PII | Any identifying personal data, governed by general privacy and consumer-protection law |
Why it matters for clinic operators
Nearly everything an aesthetic clinic stores about clients qualifies as PHI, so compliance is less about classification and more about habits: role-based access, clinic-controlled devices, BAAs with every vendor, and marketing authorizations captured before a photo is ever posted.
On the platform: HIPAA & security at Gracero · Go deeper: HIPAA compliance checklist for clinics
See Gracero run your clinic.
A 15-minute demo: booking, payments, memberships, and the aesthetic layer, all in one platform.
Book a demo