What Is PII, PHI, and Financial Data? A Plain-English Guide for Small Businesses
A tax preparer emailing a W-2 and a clinic emailing an intake form think they face different compliance problems. Legally, they do. In practice, the approach is the same: know what you are holding, know which rules apply, and handle it accordingly. So what exactly are PII, PHI, and financial data—and which ones is your business collecting right now?
TL;DR: If you are asking what is PII PHI, here is the short answer: most small businesses handle all three, and each carries its own penalties. PII means names, SSNs, and addresses. PHI covers health records. Financial data includes tax and payment details. Where categories overlap, follow the strictest rule.
Key Takeaways:
- PII identifies a person. Names, SSNs, and addresses are everyday examples.
- PHI is health information held by providers or vendors—diagnoses, prescriptions, and intake forms, for example.
- Financial data includes tax returns, W-2s, and payment details. It almost always overlaps with PII.
- State laws, HIPAA, and GLBA govern these categories. Expect mandatory encryption, access limits, and breach notifications.
- Classifying data determines which compliance rules, vendor contracts, and breach responses apply.
- One document often falls under multiple categories at once.
All three describe information about people that regulators actively enforce. The category decides who can see it, how to send it, how long to keep it, and what you owe people if it leaks. Below is each one in plain English, with examples you will recognize from your inbox. (This is educational, not legal advice.)
What Is PII, PHI, and Financial Data? Definitions First
PII: personally identifiable information
PII is anything that identifies someone—alone or combined with other details. Full names with Social Security numbers, driver's licenses, passports, birth dates, home addresses, personal emails, and phone numbers are obvious examples. IP addresses, device IDs, and combinations like job title plus employer plus city also count. You can hold PII without ever touching an SSN.
Use this simple test: Could a stranger use this to find, impersonate, or steal from a specific person? If yes, treat it as PII.
PHI: protected health information
PHI is health information that identifies a person and is created or held by a healthcare provider, health plan, or their vendor. Diagnoses, prescriptions, lab results, appointment notes, treatment plans, insurance member IDs, and completed intake forms all qualify.
Context matters. Your resting heart rate on a fitness watch is not PHI. The same number in a cardiology practice's chart is. The data has not changed. Who holds it has.
Financial data
Financial data is the trail of money-related information: bank and credit account numbers, card numbers, tax returns, W-2s, 1099s, pay stubs, credit reports, loan applications, and income or asset details. If you prepare taxes, sell insurance, broker mortgages, or manage money, this is your daily work.
A W-2 counts as both PII and financial data. A patient intake form is PII and PHI. Real-world documents often fall into multiple categories, and you inherit the rules for every category they touch.
Which Laws Apply to Each
You do not need a law degree. You need a map:
- PHI → HIPAA. Covers healthcare providers, health plans, clearinghouses, and their vendors. You need safeguards, minimum-necessary handling, business associate agreements, and breach notifications.
- Financial data → GLBA and the FTC Safeguards Rule. The Gramm-Leach-Bliley Act treats a wide range of businesses as "financial institutions," including tax preparers, and demands a written information security program. Payment card data also falls under PCI DSS, a contractual standard enforced by card brands.
- PII generally → state laws. Every U.S. state has a data breach notification law covering PII. A growing number, like California's CCPA/CPRA, grant consumers rights over their personal information. If you serve customers across state lines, you will likely face multiple rules at once.
The throughline: regulators do not care about your industry. They care about what data you hold.
If the overlap feels overwhelming, use the rule most small businesses follow: you almost certainly handle all three categories, so default to the strictest rules that apply. In practice, encrypt everything sensitive, restrict access by role, and use secure channels for transfers. Whether a document is technically PII, PHI, or financial data is a question for your attorney, not your daily workflow.
Why Classification Drives Your Handling Rules

The category determines what you actually do:
- Who may see it? PHI requires minimum-necessary access. Limit financial data to need-to-know roles.
- How may you send it? Send regulated data through encrypted channels, such as a secure portal, never as email attachments that replicate across devices.
- Which vendors may touch it? PHI needs a signed BAA. Financial data requires contracted safeguards and oversight. Vet any vendor handling PII before data flows.
- What happens after a breach? Who you must notify, how fast, and how much it costs all depend on the category and state.
Misclassifying data backfires fast. Under-protect it and you face breaches and liability. Over-restrict everything and your team invents shortcuts—personal email, thumb drives, screenshots—which can be worse. The fix is a quick classification exercise. List where client data enters your business, tag each flow by category, and assign handling rules. Most small businesses finish this in under an hour and immediately spot email attachments that need fixing.
What to Protect and How: A Quick Reference
| Data type | Everyday examples | Main rules that apply | Handling basics |
|---|---|---|---|
| PII | Names with SSNs, IDs, addresses, DOBs | State privacy and breach laws | Encrypt, limit access, never email raw |
| PHI | Intake forms, diagnoses, insurance details | HIPAA | Encrypted portal, minimum necessary, BAA with vendors |
| Financial/tax data | W-2s, 1099s, returns, bank statements | GLBA, FTC Safeguards Rule | Written security plan, MFA, encrypted transfer |
| Payment card data | Card numbers | PCI DSS (contractual) | Never store unless required; use a compliant processor |
Conclusion
Once you can answer "what is PII, PHI, and financial data?" for your business, the rest is habit. Inventory what you collect, tag it by category, gather only what you need, and move regulated documents through encrypted, access-controlled channels instead of email. This week, try the 15-minute version: list every place client information ends up in your business. Anything on that list—PII, PHI, or financial data sitting in an email inbox—is your first fix. Move that flow to a secure upload portal and you eliminate your most common leak in one step.
References
- HIPAA Privacy and Security Rules: Health Insurance Portability and Accountability Act (HIPAA) Privacy and Security Rules — U.S. Department of Health & Human Services.
- Gramm-Leach-Bliley Act: Gramm-Leach-Bliley Act and the FTC’s guidelines for protecting customer information (Safeguards Rule, 16 CFR Part 314) — Federal Trade Commission.
- State Data Breach Notification Statutes: State data breach notification statutes (enacted in all 50 U.S. states) — various state legislatures.
Frequently Asked Questions
Q: What is PII PHI?
A: PII, PHI, and financial data are information types that identify individuals. Each carries its own regulations and handling requirements.
Q: How do PII and PHI differ?
A: PII identifies individuals through personal details like names or addresses. PHI is health-related data—diagnoses, treatment plans, lab results—held by healthcare providers or their vendors.
Q: What are examples of personally identifiable information?
A: Examples include names, Social Security numbers, driver's licenses, and addresses. Even an IP address or a job title combined with city can count as PII.
Q: Which laws apply to PII, PHI, and financial data?
A: State laws regulate PII. HIPAA covers PHI. GLBA and the FTC Safeguards Rule apply to financial data. Each sets its own safeguards, vendor requirements, and breach notification rules.
Q: Why is classifying data important for small businesses?
A: If you do not classify data, you cannot know which handling rules apply. Encryption, secure transfers, and breach response all depend on getting the category right.
