Glossary · Compliance & clinical governance

What is Protected health information (PHI)?

Protected health information is any individually identifiable health information a covered entity creates or holds: names tied to treatments, chart notes, consent forms, clinical photos, appointment types, even an email address in a clinical context. HIPAA's Privacy and Security Rules govern how PHI is stored, accessed, shared, and disclosed.

How it works in an aesthetic clinic

A before-and-after photo with a recognizable face is PHI. So is a calendar entry reading 'Jane D., Botox, 3pm.' The clinic maps where PHI lives (platform, phones, inboxes), restricts access by role, encrypts it, and treats marketing use as a separate written authorization. A staff member's personal phone gallery is where PHI turns up in audits.

Protected health information (PHI) vs PII

Protected health information (PHI)Identifiable health information held by a covered entity, governed by HIPAA
PIIAny identifying personal data, governed by general privacy and consumer-protection law

Why it matters for clinic operators

Nearly everything an aesthetic clinic stores about clients qualifies as PHI, so compliance is less about classification and more about habits: role-based access, clinic-controlled devices, BAAs with every vendor, and marketing authorizations captured before a photo is ever posted.

Related terms

Run your whole clinic in one place

See Gracero run your clinic.

A 15-minute demo: booking, payments, memberships, and the aesthetic layer, all in one platform.

Book a demo
15-minute walkthroughEasy migrationNo commitment
Book a demo