Which Labels Map to PHI Exactly?

In the Spirion Sensitive Data Platform, Protected Health Information (PHI) is not a single "Data Type" but rather a collection of specific identifiers that, when found, map to the PHI category.

To map labels to PHI exactly, you should focus on the following AnyFinds and Sensitive Data Definitions (SDDs):

1. Core AnyFinds that Map to PHI

These are the built-in detectors that identify the most common HIPAA-regulated identifiers:

  • Health Information: Specifically designed to find medical-related data.
  • Social Security Number: A primary identifier under HIPAA.
  • Date of Birth: Often used in combination with other data to establish PHI.
  • Drivers License / Passport Number: Government-issued identifiers that are part of the 18 HIPAA identifiers.
  • E-Mail Address / Personal Address / Telephone Number: Contact information that becomes PHI when linked to health data.

2. Healthcare-Specific Identifiers (Custom or SDD)

For a precise PHI mapping, you should also include these specific medical identifiers:

  • Medical Record Number (MRN)
  • Health Insurance Claim Number (HICN)
  • ICD-9 / ICD-10 Codes: International Classification of Diseases codes used for billing and diagnosis.
  • Insurance Numbers: Policy or group numbers.

3. The "Exact Mapping" Strategy: Using SDDs

HIPAA defines PHI as health information linked to an individual. To map this exactly in Spirion and avoid false positives (like a list of softball team members), you should use Sensitive Data Definitions (SDDs) to create "Contextual PHI" rules:

  • Rule Example: (Health Information OR ICD-10 Code) NEAR (Name OR SSN OR MRN)
  • Mapping: When this SDD is triggered, the playbook should apply the "PHI" or "Restricted - PHI" label.

Summary of Mapping:

Spirion Data Type

HIPAA Category

Recommended Label

Health Information

Medical Records / Diagnosis

PHI

SSN / MRN / HICN

Unique Identifiers

PHI - Restricted

ICD-9 / ICD-10

Clinical Codes

PHI

Name + DOB + Address

Demographic PHI

PHI - Confidential

Operational Tip

In your Governance Dashboard, you can create a specific view that aggregates all results from these specific Data Types and SDDs into a single "PHI Risk" trend. This enables you to trace exactly how much PHI is being discovered and labeled across your environment.