Protected Health Information (HIPAA)

Protected Health Information (PHI) is any health information that can be linked to an identifiable individual, such as a patient receiving treatment at the U-M Health System. PHI is regulated by the Health Insurance Portability and Accountability Act (HIPAA). Researchers should be aware that health and medical information about research subjects may also be regulated by HIPAA. Researchers can contact the UMHS Compliance Office with questions.

Frequently Used by: 

Faculty
Staff
Researchers

Category: 

Sensitive

Examples: 

The following individually identifiable data elements, when combined with health information about that person, make such information protected health information (PHI):

  • Names
  • Telephone numbers
  • Fax numbers
  • Email addresses
  • Social Security Numbers
  • Medical record numbers
  • Health plan beneficiary numbers
  • License plate numbers
  • URLs
  • Full-face photographic images
  • Any other unique identifying number, characteristic, code, or combination that allows identification of an individual
     

M+Box Core Apps: 

Not Permitted

M+Google Mail and Calendar: 

Not Permitted

M+Google Drive (Docs): 

Not Permitted

M+Google Sites, Talk, Groups, Tasks: 

Not Permitted

M+Google Additional Services (Non-Core): 

Not Permitted

M+Box Additional Apps (Non-Core): 

Not Permitted

Personal Device (phone, tablet, laptop, etc.): 

Not Permitted

Personal Account (Dropbox, Evernote, etc.): 

Not Permitted

UMHS Exchange Email and Calendar: 

Permitted

CTools: 

Not Permitted

Wolverine Access: 

Permitted

MiDatabase: 

Permitted

MiServer: 

Permitted

Desktop Virtualization (VDI): 

Permitted

TSM Backup: 

Permitted

MiWorkspace: 

Permitted

Sitemaker: 

Not Permitted

Virtualization as a Service (VaaS): 

Permitted

Value Storage: 

Not Permitted

Mainstream Storage: 

Permitted

Data Warehouse: 

Not Permitted

ITS Exchange Email and Calendar: 

Not Permitted

Desktop Backup (Powered by CrashPlan): 

Permitted

Flux: 

Not Permitted