HIPAA & PHI in Clinical Charting: A Practical Guide
What Counts as PHI
Protected Health Information includes any individually identifiable health information. The HIPAA Safe Harbor method defines 18 specific identifiers: names, geographic data smaller than a state, dates (except year), phone/fax numbers, email addresses, SSNs, medical record numbers, health plan numbers, account numbers, certificate/license numbers, vehicle identifiers, device identifiers, URLs, IP addresses, biometric identifiers, photos, and any other unique identifier.
PHI in Clinical Documentation Tools
When using any digital tool for documentation, including AI assistants, voice-to-text apps, or note-taking apps, you must ensure PHI is not transmitted to or stored by unauthorized systems. The key question is: does this tool store, process, or transmit any of the 18 HIPAA identifiers? If yes, it must be HIPAA compliant with a signed BAA.
De-Identification Best Practices
When using pre-charting tools, replace patient names with 'patient' or initials, omit dates of birth, remove addresses, and never include medical record numbers in external tools. Your final documentation in the EMR will have full PHI, but intermediate tools should only see de-identified clinical content.
What Nurses Can Do
Know your agency's policies on mobile devices and external apps. Never text PHI, never photograph patient documents with personal phones, and always log out of clinical apps between patients. Use tools that have built-in PHI detection, and when in doubt, leave identifying information out of any tool that isn't your official EMR.