Two ingredients: health content and identifiability, in the hands of a regulated party. A diagnosis, prescription, lab result, appointment record, or an invoice for treatment becomes PHI when it can be tied to a person and it’s held by a covered entity or a business associate working for one. The same blood-pressure reading in a consumer wellness app sold directly to individuals generally isn’t PHI — context, not content, decides.
HIPAA’s de-identification safe harbor lists eighteen identifiers — names, address elements, dates tied to a person, phone and email, medical record and account numbers, device identifiers, IP addresses, photos, and a catch-all for any other unique identifying characteristic. In engineering terms the list is brutal: timestamps, user IDs, and IPs are everywhere in logs and analytics, so “we only store a little health data” rarely survives a real data-flow review. Strip or generalize all eighteen and data can fall out of PHI status; until then, treat it as in scope.