We value your privacy

We use cookies to enhance your browsing experience, serve personalised ads or content, and analyse our traffic. By clicking "Accept All", you consent to our use of cookies.

Powered by
    BisGentech logo
    AI & Technology Assessment
    AI & Technology Assessment
    Back to Insights

    Cybersecurity & Resilience

    What Growing Businesses Should Know About PII, PHI, and Sensitive Data

    Learn the difference between PII, PHI, and ePHI, where sensitive data commonly appears, and practical steps growing businesses can take to manage privacy and security risk.

    Benjamin IsidoreOctober 1, 20268 min read

    Growing businesses collect more sensitive information than they often realize. Customer records, employee information, financial data, health-related information, login credentials, documents, emails, cloud applications, intake forms, and AI tools can all create privacy, security, and operational obligations.

    The first challenge is understanding that not all sensitive information is regulated in the same way. PII, PHI, ePHI, financial information, credentials, and confidential business data overlap in important ways, but they are not interchangeable terms.

    A practical data-protection program begins by knowing what information the business has, where it is stored, who can access it, which vendors can receive it, and what rules apply to its use.

    What is PII?

    Personally identifiable information, or PII, is information that can identify, distinguish, or be linked to a specific individual. As defined in guidance from the National Institute of Standards and Technology (NIST), PII encompasses any representation of information that permits the identity of an individual to whom the information applies to be reasonably inferred by either direct or indirect means.

    Common examples of PII include:

    • full legal name and aliases
    • Social Security number (SSN)
    • driver's license or state identification number
    • biometric information such as facial geometry or fingerprints
    • date of birth or place of birth when combined with other identifiers
    • personal contact details including phone number, home address, and personal email
    • financial account numbers, payment card details, and credit information
    • employee personnel records, performance reviews, and payroll records
    • customer account identifiers, customer numbers, and unique digital profiles

    An important nuance is that not every data element is sensitive in isolation. A first name or a general job title alone rarely creates acute exposure. However, risk increases significantly when individual data elements can be linked or combined with other information to identify an individual, access accounts, or cause financial, operational, or reputational harm if exposed.

    What is PHI?

    Protected Health Information, or PHI, is a specific legal and regulatory category created under the Health Insurance Portability and Accountability Act (HIPAA). PHI generally involves individually identifiable health information that is created, received, maintained, or transmitted by a HIPAA-covered entity or its business associates in connection with covered healthcare operations, payment, or treatment.

    Several critical distinctions are often misunderstood by growing organizations:

    • not all health information is automatically PHI under federal law
    • whether HIPAA applies depends on the nature of the organization, its relationships, and the operational context in which the data is handled
    • a business should never assume that every health-related record it handles is subject to HIPAA, nor assume it is exempt simply because healthcare is not its primary industry
    • health information that falls outside HIPAA may still be subject to state privacy statutes, FTC enforcement, contractual requirements, or employment laws

    Whether your organization is classified as a covered entity, a business associate, or neither is a question that requires appropriate compliance and legal review. For technology and operations leaders, the practical lesson is that health-related data carries heightened expectations of confidentiality regardless of the regulatory label.

    What is ePHI?

    Electronic Protected Health Information, or ePHI, is simply PHI that is created, received, maintained, or transmitted electronically. In modern businesses and healthcare-adjacent workflows, almost all health information exists in electronic form at some stage.

    Common examples of ePHI in business workflows include:

    • electronic health records (EHR) and clinical software systems
    • cloud-stored patient or participant profiles and appointment records
    • emails, attachments, and customer support messages containing identifiable health details
    • digital intake forms, web portals, and telehealth scheduling tools
    • electronic billing, insurance claims, and payment records
    • files, spreadsheets, or exports exchanged with third-party vendors and partners
    • data viewed, cached, or processed through mobile applications and browser-based software

    Because electronic handling moves data across networks, storage drives, laptops, and cloud providers, ePHI introduces core technical and operational safeguards under the HIPAA Security Rule. Organizations must address authentication, role-based access, encryption in transit and at rest, audit logging, data backups, transmission security, vendor permissions, and data retention schedules.

    Health Information Outside HIPAA Still Matters

    A company may collect or process health-related information without being a HIPAA-covered entity or a HIPAA business associate. For example, wellness apps, workplace symptom questionnaires, fitness tracking tools, or direct-to-consumer software platforms may handle sensitive health data without ever touching HIPAA.

    That does not mean the information is unregulated or low risk. Guidance and enforcement from the Federal Trade Commission (FTC) make clear that health data outside HIPAA remains subject to federal oversight:

    • the FTC Health Breach Notification Rule applies to vendors of personal health records (PHRs), health-related apps, connected devices, and related service providers that handle identifiable health information not covered by HIPAA
    • under Section 5 of the FTC Act, privacy and data-sharing promises made to consumers in privacy policies, marketing copy, or user agreements must be accurate and truthful
    • businesses must maintain administrative, technical, and physical security practices appropriate to the sensitivity of the information they collect and store

    Treating health data casually because an organization is 'not in healthcare' is one of the quickest ways to create unexpected regulatory exposure, contractual defaults, or customer backlash.

    Where Sensitive Data Hides in a Growing Business

    When business leaders think about sensitive data, they tend to think of production databases or core line-of-business applications. In practice, sensitive data disperses rapidly across everyday tools and communication channels as an organization grows.

    Common places where sensitive data accumulates without clear tracking include:

    • CRM systems containing detailed customer notes, identities, and financial details
    • HR platforms, applicant tracking tools, and onboarding repositories with SSNs and banking info
    • email inboxes, archives, and forwarded threads containing sensitive attachments
    • shared cloud drives (such as Google Drive, OneDrive, or SharePoint) with broad internal permissions
    • spreadsheets downloaded for ad hoc reporting, reconciliations, or operational lists
    • accounting systems, payment processors, and billing software
    • website intake forms, contact endpoints, and customer support ticketing systems
    • messaging platforms such as Slack or Microsoft Teams where files and credentials get pasted
    • SaaS tools and connected third-party productivity integrations
    • generative AI tools and assistants used by employees without organizational oversight
    • local downloads, desktops, screenshots, and unencrypted employee laptops or mobile devices
    • routine backup snapshots, staging environments, and database dumps

    Businesses often maintain rigorous controls around their primary production systems while overlooking the dozens of secondary copies, exports, and shared documents that exist across the organization.

    Why Vendors Matter

    A business can have excellent internal password standards and device encryption, yet lose control of sensitive information the moment that data is shared with third-party vendors. When you send sensitive records to an outside platform, your security posture becomes directly tied to theirs.

    Before transmitting sensitive customer, employee, or health information to any vendor, organizations should establish clear answers to fundamental questions:

    • what specific data elements will the vendor receive or have access to?
    • why does the vendor need this information to fulfill its operational purpose?
    • where and how will the vendor store, process, and encrypt the data?
    • does the vendor rely on secondary subcontractors or subprocessors that will also receive the data?
    • what are the vendor's data retention, deletion, and export policies when the contract ends?
    • what security controls and certifications does the vendor maintain to protect customer information?
    • what are the vendor's contractual breach-notification timelines if an incident occurs?
    • are appropriate contractual safeguards—such as data processing agreements or business associate agreements—in place?

    Vendor oversight is not a one-time check during onboarding. As vendors update their features, alter subprocessor relationships, or change terms of service, regular reviews ensure sensitive data remains protected throughout the relationship.

    AI Creates a New Data-Handling Question

    The rapid adoption of generative AI and automated assistants introduces novel data-handling considerations for growing businesses. When employees paste documents, customer records, or internal notes into AI tools, they may unintentionally transmit sensitive information outside organizational boundaries.

    Before allowing or encouraging sensitive data to enter an AI tool, businesses should evaluate:

    • what data is being submitted in user prompts, uploaded files, or API payloads
    • whether the AI vendor stores prompt inputs, uploaded attachments, or system outputs
    • whether submitted information may be used to train, retrain, or improve public or foundation models
    • whether enterprise-grade administrative and organizational controls are active for company accounts
    • who within the vendor organization or third-party reviewers can inspect logged queries
    • whether sensitive elements could inadvertently reappear in generated summaries or logs
    • whether the specific workflow warrants human review and approval before automated processing

    Not all AI providers train on user data, and many enterprise tiers provide explicit data-retention and confidentiality commitments. The key is knowing the actual terms, configuring tenant settings correctly, and establishing clear internal policies for staff.

    Identify What Your Business Actually Handles

    Before applying any of the steps below, it helps to see where sensitive information may already exist across your business. The interactive checklist below takes about three minutes and gives you a practical snapshot of the categories and systems to think through. It is educational only — not a compliance audit or risk score — and you do not enter any actual sensitive values.

    Free Discovery Tool

    Sensitive Data Discovery Checklist

    Identify where your business may collect, store, process, transmit, or share sensitive information. This takes about three minutes and is for general educational and planning purposes only.

    Do not enter actual Social Security numbers, medical information, passwords, account numbers, patient data, or other sensitive values. Only identify the categories of information you handle. Your selections stay in your browser and are not stored unless you choose to submit them to BisGentech.

    Customer & Personal Data

    Select any personal or customer information your business may collect, store, or process.

    Health & Benefits Data

    Select any health- or benefits-related information your business may handle.

    Business-Sensitive Data

    Select any confidential or business-sensitive information your business may hold.

    Where Data Exists

    Select all the places or systems where this information may live.

    Third-Party Access

    Do vendors, contractors, partners, or service providers have access to any of this information?

    You haven't identified any sensitive information yet.

    Your Discovery Summary

    You haven't identified any sensitive information yet.

    This checklist is provided for general educational and planning purposes. It is not a legal, regulatory, compliance, privacy, or security assessment and does not determine whether your organization complies with any specific requirement.

    A Practical Sensitive-Data Baseline

    Managing sensitive data responsibly does not require an enterprise compliance department on day one. A grounded, step-by-step foundation provides substantial protection for growing businesses:

    • 1. Know what sensitive data you have: conduct a straightforward inventory of personal, financial, health, and confidential records.
    • 2. Identify where it is stored: map primary applications, cloud drives, file shares, spreadsheets, and backup locations.
    • 3. Identify who can access it: review user accounts and restrict access to individuals with a legitimate operational need.
    • 4. Identify which vendors receive it: document third-party services that store, process, or transmit your sensitive information.
    • 5. Limit collection to what is needed: avoid collecting unnecessary identifiers, SSNs, or sensitive details if they do not serve an immediate business function.
    • 6. Use role-based access: prevent broad employee access to HR folders, customer billing databases, or sensitive client files.
    • 7. Require MFA everywhere: enforce multi-factor authentication on every email account, cloud platform, CRM, and vendor portal.
    • 8. Review retention and deletion practices: establish practical schedules for archiving or securely deleting records when no longer needed.
    • 9. Protect data in transit and at rest: verify standard encryption protocols across devices, web traffic, and cloud storage.
    • 10. Maintain reliable backups and recovery procedures: test backups periodically to ensure critical information can be restored during an outage or incident.
    • 11. Review vendor security responsibilities: ensure contracts, data agreements, and access permissions match the sensitivity of the data shared.
    • 12. Establish incident-reporting and escalation procedures: make sure staff know how to report lost devices, suspicious emails, or potential disclosures immediately.
    • 13. Train employees on handling sensitive information: educate staff on phishing, safe file sharing, credential hygiene, and prompt guidelines.
    • 14. Review how AI tools interact with sensitive data: define acceptable-use guidelines for generative AI tools and configure enterprise data controls.

    The Question Is Not Only "Is This Regulated?"

    A mature data-protection approach does not begin and end with whether a specific statute explicitly names a data element. Focusing solely on legal minimums can lead businesses to ignore real operational vulnerabilities that sit just outside formal compliance definitions.

    When evaluating how data should be handled, business owners and technology leaders should also weigh:

    • the inherent sensitivity and vulnerability of the individual whose data is held
    • the direct financial and operational impact on your business if the information were exposed or deleted
    • customer trust and explicit contractual commitments made to enterprise clients or partners
    • vendor exposure and third-party supply-chain dependencies
    • the risk of identity theft, account takeover, or fraud against employees or customers
    • reputational impact and long-term brand credibility in your market

    By treating sensitive data protection as a core business practice rather than a compliance checklist, growing organizations build resilience, protect customer relationships, and prepare smoothly for future growth and regulatory milestones.

    Key Takeaways

    • PII is a broad category of information linked or linkable to an individual.
    • PHI is a HIPAA-specific category and should not be used as a synonym for all health information.
    • ePHI is PHI handled electronically.
    • Health information outside HIPAA may still carry significant privacy and security obligations.
    • Sensitive data often exists in SaaS tools, spreadsheets, email, vendors, backups, and AI workflows.
    • Businesses should understand what sensitive data they collect, where it moves, who can access it, and how long it is retained.
    • Vendor and AI data handling should be part of the same broader data-governance discussion.

    Sources and References

    1. NIST — Personally Identifiable Information (PII) Glossary (source)
    2. U.S. Department of Health & Human Services — HIPAA for Professionals / The HIPAA Privacy Rule (source)
    3. U.S. Department of Health & Human Services — The HIPAA Security Rule (Electronic Protected Health Information) (source)
    4. Federal Trade Commission — Collecting, Using, or Sharing Consumer Health Information? Look to HIPAA, the FTC Act, and the Health Breach Notification Rule (source)
    5. Federal Trade Commission — Health Breach Notification Rule: The Basics for Business (source)

    About the Author

    Benjamin Isidore

    Founder & CEO, BisGentech

    Benjamin Isidore is the Founder and CEO of BisGentech. He helps growing small and medium-sized businesses clarify technology decisions, improve operations, and strengthen security with practical, business-first guidance built on more than 24 years of technology leadership.