[nonimo]
EN
Download

PHI vs PII in HR files: what is sensitive before it goes to AI

· Updated · Written and maintained by Joaquín Trapero, Nonimo

An FMLA certification sitting in an HR file is not PHI. That surprises people, because it names a diagnosis and was written by a doctor, but HIPAA’s definition of protected health information leaves employment records out. The PHI vs PII question only settles which federal label applies.

The certification is still a confidential medical record under federal employment law, and in California it is also sensitive personal information. Before any of it goes into an AI tool, what has to come out is what ties it to the employee.

This guide is for the people who handle that paper every week: the HR manager at a company of fifty, the office manager who also runs payroll, the employment lawyer holding a client’s personnel file, the CPA firm that processes a client’s payroll. It covers who owns which label, where the sensitive categories hide in ordinary paperwork, and what a real run through Nonimo does to a leave memo.

PHI vs PII: the question HIPAA answers, and the one it leaves to others

PII is the generic term: anything that identifies a person, from a name to an employee ID. PHI is a legal term with an owner. HIPAA defines protected health information in 45 CFR 160.103 as individually identifiable health information, and the Privacy Rule only binds health plans, clearinghouses and providers who bill electronically, plus the business associates working for them.

So in the PHI vs PII debate, the deciding fact is rarely the content of the document. It is who holds it, and in what role. The same diabetes diagnosis is PHI in the clinic’s chart and something else in the employer’s leave file. Our guide to masking before AI covers the other half of the vocabulary, the words for what you do to the text afterward.

Who holds the paper decides the label

The regulation’s own wording shows it. Individually identifiable health information is information created or received by “a health care provider, health plan, employer, or health care clearinghouse” that relates to someone’s health and identifies them. Employers are named in the first clause. Then the definition of PHI takes a large part of it back.

Who holds the document? A provider, a health plan, or their business associate The employer, in its role as employer PHI: HIPAA applies Not PHI. Still covered by: ADA, FMLA and GINA: confidential medical record, in a separate file California: sensitive personal information
The same medical note, two holders. Sources: 45 CFR 160.103, 29 CFR 1630.14(c) and Cal. Civ. Code 1798.140(ae)

The exclusion reads, in paragraph (2)(iii) of the definition, “employment records held by a covered entity in its role as employer”. HHS repeats it in plain English on its page about employers, reviewed in November 2020: the Privacy Rule does not protect employment records, even when what they contain is about health.

Where HIPAA does reach an employer

There is one door back in, and it matters for midsize companies. A group health plan is itself a covered entity, even when the employer sponsors it. If your company funds its own plan and HR sees claims data, that data is PHI held for the plan, and 45 CFR 164.504(f) makes the sponsor promise not to use it for employment decisions.

The practical test is the source of the paper. A certification the employee handed to HR is an employment record. A claims report from the plan administrator is plan PHI, and it belongs in a different drawer and under a different set of rules, set out in the guide on HIPAA, BAAs and AI.

Sensitive personal information in California and Virginia

Outside HIPAA, the United States has no single list of sensitive data. The states that passed consumer privacy laws each wrote their own, and two of them, California’s and Virginia’s, disagree on the point that matters most to an HR department: whether employees count at all.

California calls it sensitive personal information, in Civil Code 1798.140(ae). Virginia calls it sensitive data. The categories overlap heavily, and the note on whether ChatGPT shares or sells your data shows why the vendor’s own terms decide less than people expect.

California counts your employees since 2023

California’s list is the longer one. It covers Social Security, driver’s license, state ID and passport numbers; account logins and card numbers with their access codes; precise geolocation; racial or ethnic origin, citizenship or immigration status, religious or philosophical beliefs and union membership; the contents of mail, email and texts not addressed to the business; genetic data and neural data; biometrics used to identify someone; and information about health, sex life or sexual orientation.

Until the end of 2022, employee data sat outside most of the law under an exemption in section 1798.145(m). That subdivision says of itself that it became inoperative on January 1, 2023. Since then a California employee is a consumer like any other, and a leave file, an I-9 and a payroll register are all within reach of the law.

January 1, 2023employee exemption in 1798.145(m) ends
$26,625,000revenue test for a CCPA business
January 1, 2026risk assessment rules take effect
Cal. Civ. Code 1798.145(m)(4); California Privacy Protection Agency, CPI adjustment and OAL approval of September 22, 2025

The size test comes first. The law applies to a business run for profit that does business in California and passes one of three thresholds; the revenue one, adjusted by the California Privacy Protection Agency effective January 1, 2025, is $26,625,000. The others turn on buying, selling or sharing the data of 100,000 consumers or earning half your revenue from it. An employer of fifty with modest revenue can be under all three.

Virginia leaves the workplace out

Virginia’s Consumer Data Protection Act defines a consumer as a resident acting in an individual or household context, and says in the same sentence that it does not include someone acting in an employment context. Section 59.1-576 then exempts data held about applicants and employees within that role.

Its list of sensitive data is also shorter: racial or ethnic origin, religious beliefs, a mental or physical health diagnosis, sexual orientation, citizenship or immigration status, genetic or biometric data used to identify someone, a known child’s data and precise geolocation. Union membership is not on it. Where the law does apply, processing sensitive data needs the consumer’s consent.

What the two lists mean for a company with staff in both

For an HR team the difference is practical. The same union dues deduction is sensitive personal information about a California employee and nothing special under Virginia’s consumer law. If you employ people in several states, the California list is the one to plan around, since, of the two, only California’s reaches employees, and then check your own state’s statute rather than assuming it copied either.

California Virginia Union membership SSN, license, passport Account logins Mail and text contents Neural data Health Racial or ethnic origin Religious beliefs Sexual orientation Citizenship, immigration Genetic, biometric, geolocation A known child's data Reaches employees Leaves employees out
Categories named in each list, shortened. Cal. Civ. Code 1798.140(ae); Va. Code 59.1-575 and 59.1-576

Much of the paperwork in the table below lands in the middle, where the lists agree: health, religion, immigration status. The trouble sits on the left edge, in the categories only California names. A payroll register belongs there because of its dues column, and it is the document an employer is least likely to think of as sensitive.

PHI vs PII in ordinary HR paperwork: where the categories sit

None of these documents is labeled sensitive. They are forms, memos and exports that pass through an HR inbox every week, and each carries at least one category a state law or a federal employment law treats as special. Here is where they sit.

DocumentCategory it revealsRule that follows it
FMLA certification, Form WH-380-EHealth, sometimes a diagnosisFMLA and ADA: confidential medical record
ADA accommodation requestHealth or disability29 CFR 1630.14(c): separate file, short list of who may know
Religious accommodation requestReligious beliefCalifornia SPI; on Virginia’s list, which skips staff
EEOC chargeThe protected basis claimedDiscrimination law; California SPI for several bases
Paystub or payroll registerUnion membership, through a dues lineCalifornia SPI
Form I-9Citizenship or immigration statusBoth lists; only California’s reaches staff
Leave to care for a relativeFamily medical historyGINA: genetic information

Sources: 29 CFR 825.500(g), 1630.14(c), 1635.3(c); Cal. Civ. Code 1798.140(ae); Va. Code 59.1-575.

The FMLA certification

The Department of Labor’s Form WH-380-E, revised in June 2020 and approved through August 31, 2029, is the paper most HR teams see. The provider “may, but are not required to” give symptoms or a diagnosis, and many do. The form also asks how often episodes of incapacity will occur over six months, which on its own describes a chronic condition.

The form carries its own instruction to the employer, printed on the first page: keep these records as confidential medical records in separate files from the usual personnel files. That is the rule in 29 CFR 825.500(g), and it points on to the ADA and GINA rules.

The ADA accommodation request

An accommodation request usually holds more than the certification, because the employee explains what they cannot do and why. Under the ADA the medical part goes in a separate medical file, and the list of who may be told is short. The section on filing versus AI takes that list apart, because it is where an AI tool fits worst.

The EEOC charge

A charge of discrimination is, by design, a statement about a protected characteristic. The EEOC’s own page lists the bases: race, color, religion, sex, national origin, age from 40, disability and genetic information. A draft position statement answering the charge repeats that basis on every page, with the employee named and the charge number printed at the top. If the charge later becomes a lawsuit, telling the court about AI use is a separate question with its own rules.

Four entries that do not look sensitive and are

The categories above are easy to spot on a medical form. The harder cases are ordinary lines in ordinary documents, which a manager forwards without a second look. Four come up constantly, and each belongs to a list in the table.

  1. A dues line on a paystub. A deduction labeled union dues says the employee is a union member, which California lists by name. The payroll export a CPA firm cleans up every month carries it for everyone who pays dues.
  2. A Friday schedule change. A request to start later on Fridays for prayer is a religious accommodation, and it reveals a religious belief as clearly as a form would.
  3. A status box on the I-9. The Form I-9 records whether someone is a citizen, a permanent resident or authorized to work another way. Both state lists name citizenship or immigration status.
  4. A leave to care for a parent. When an employee asks for leave to care for a mother with breast cancer, the file now holds her diagnosis, and GINA treats that as information about the employee.

Why family medical history is genetic information

The fourth one is the least intuitive, and it has the strictest rule. 29 CFR 1635.3(c) defines genetic information to include “the manifestation of disease or disorder in family members”, the regulation’s name for family medical history. A caregiver leave request fits that definition, even though no test was ever run.

  1. Does the text describe a disease in one of the employee's family members?

    YesIt is genetic information about the employee, even if no test was run.

    NoGINA's family history rule does not reach it; the FMLA and ADA rules on medical records still may.

  2. Is the disclosure one of the six cases GINA lists?

    YesIt may be disclosed in that case.

    NoIt stays in the separate medical file. A software tool is not among the six.

A caregiver leave request under GINA. 29 CFR 1635.3(c) and 1635.9(b)

GINA’s confidentiality rule then applies to it. The information goes in a medical file separate from personnel records, and section 1635.9 lists the only six situations in which it may be disclosed. The FMLA rule sends the reader to that same section for exactly this case.

Filing a medical note and putting it into a chatbot are different acts

Every rule above is written about files and people. Keep it separate, keep it confidential, tell only these people. None of them mentions software, and none was written with a chatbot in mind. That does not leave the question open; it means the question has to be answered with the lists the rules already contain.

The ADA list of who may be told

Under 29 CFR 1630.14(c)(1), medical information about an employee is kept on separate forms and in separate files and treated as a confidential medical record. The exceptions are three: supervisors and managers, about restrictions and accommodations; first aid and safety staff, when emergency treatment may be needed; and government officials investigating compliance.

An AI vendor is none of the three. Whether sending text to a tool that processes it for you counts as disclosure is not something the regulation addresses. What it does settle is the direction: the fewer people and systems that learn which employee has which condition, the closer you are to what the rule describes. For a city or county employer the paste also creates a public record that someone may later request.

6
situations in which GINA allows genetic information to be disclosed. 29 CFR 1635.9(b)

The GINA list is stricter still: the employee on written request, a health researcher under federal research rules, a court order, government investigators, FMLA certification, and a public health agency about a contagious disease. A software tool is not among the six. The policy template has a section for writing down which categories staff may not put into any AI tool at all.

California adds a risk assessment for AI on sensitive data

California’s newer rules go further, because they are about processing rather than filing. The regulations the California Privacy Protection Agency adopted, approved on September 22, 2025 and in force since January 1, 2026, say in section 7150 that processing sensitive personal information presents significant risk and requires a risk assessment before it starts.

  1. Is it sensitive personal information about a California employee, at a CCPA business?

    YesGo to the next question.

    NoNot this rule. The federal employment rules above still apply.

  2. Is it processed solely for compensation, work authorization, benefits, a required accommodation or wage reporting?

    YesNo risk assessment is needed.

    NoA risk assessment comes before the processing starts.

When HR processing needs a California risk assessment. CPPA regulations, section 7150, in force since January 1, 2026

There is an exception written for HR. Processing employees’ sensitive data solely for compensation, work authorization, benefits, legally required accommodation or wage reporting needs no assessment. Everything else does. An AI summary of an accommodation file may or may not stay inside “solely”; that is a question for counsel, and a good reason to keep the employee’s identity out of the tool in the first place.

What to take out so the memo is no longer about someone

The category usually has to stay. An AI tool asked to draft an accommodation plan needs to know the condition; one asked to tighten a position statement needs to know the basis of the charge. What does not need to reach it is who the employee is. The job, then, is to remove the identity and keep the substance, in this order:

  1. Names, all of them. The employee, relatives named in a caregiver request, the treating provider, the supervisor. A provider’s name narrows the field more than people think.
  2. Every number that points to a record. Social Security number, employee ID, the EEOC charge number, a claim or case number. An internal ID is a name to anyone with access to the HRIS.
  3. Contact details. Address, phone, personal email.
  4. Exact dates. A date of birth, and the specific dates of a leave, which anyone with the schedule can match.
  5. The one detail that gives it away. The only night shift supervisor, the rare condition in a team of six. Read the text as a coworker would.

What a masked memo still is

Taking all of that out does not change what the text is under the law. It is still information about an identifiable employee, because your company can match it back, and our data breach guide explains why a mistake with it is still judged as one. The outside tool, though, receives far less.

Software does most of the first four steps. Someone who knows the workplace has to do the fifth, and check what the software left. Our guide on whether redacting protects privilege reaches the same conclusion for legal files: software narrows the problem, and a person closes it.

Nonimo on the HR desk: the name goes, the diagnosis stays

Nonimo is an app for Mac and PC. You select the text and press the key, and the identifiers are replaced by labels before it goes to ChatGPT, Claude or another tool. When the answer comes back, the real values return on your computer. Here is a leave memo HR might draft before asking for a summary, run through version 0.2.8 on September 25, 2026.

Typed                                   What reached the AI tool
Employee: Darnell Okafor                Employee: [PERSON_1]
Employee ID: 40718                      Employee ID: 40718
SSN: 000-45-6789                        SSN: [REFERENCE_1]
Date of birth: 02/30/1981               Date of birth: [RECORD_FIELD_1]
Phone: (614) 555-0187                   Phone: [RECORD_FIELD_2]
Email: d.okafor@example.com             Email: [EMAIL_1]
Address: 1400 Example Avenue,           Address: [ADDRESS_1]
  Columbus, OH 43215

Nothing in the memo belongs to a real person. Social Security has never issued a number in area 000, no calendar has a February 30, the 555-0100 block is set aside for fiction, and example.com exists for documentation.

What Nonimo takes out is who the employee is, not what the memo says about them. A diagnosis, a religious practice or a union deduction stays in the text, because the task needs it, and on your side the memo is still sensitive information about someone your organization can identify.

On your computer it keeps the correspondence between labels and values, encrypted, and our server receives a daily count with no text in it. Our security page has the detail, and the page for organizations covers a rollout to a whole HR team.

Employment lawyers and CPA firms holding someone else’s HR file

The same paper travels. An employment lawyer defending a company receives the personnel file, the accommodation correspondence and the charge. A plaintiff’s lawyer receives the employee’s own copies, often with medical records attached. A CPA firm running payroll for clients sees every dues deduction and every garnishment. Law and CPA firms alike can tell the client how that file will meet an AI tool before it arrives, in the AI clause of the engagement letter.

None of that turns the firm into a HIPAA covered entity. A law or accounting firm comes under HIPAA as a business associate when a covered entity engages it for legal or accounting work that involves PHI, and the HIPAA guide covers that case. For the rest, the governing duty is the professional one: confidentiality under the bar’s rules, or the CPA’s own confidentiality rule.

PHI vs PII in an employment case file: invented intake notes in which the client name, Social Security number and date of birth have become placeholders before they reach ChatGPT
Release 0.2.8 on a Mac, with the invented intake notes from our page for law firms

That capture shows the same pattern in an employment case, a retaliation claim after a wage complaint. It is a shorter note than the memo above, and the placeholders look the same. The version for litigation files is laid out for law firms, and the payroll version for CPA firms.

The client’s employees are not the firm’s clients

One point catches firms out. The confidentiality duty runs to the client, the company. The sensitive categories belong to its employees, who are strangers to the engagement, and California’s list protects them directly when the client is a CCPA business. A firm that puts a client’s accommodation file into an AI tool carries both loads at once, which is the reason to remove the employees’ identity while the text is still in the office.

Sources

Common questions

PHI vs PII: what is the difference?

PII is any information that identifies a person. PHI is the narrower HIPAA term: identifiable health information held by a health plan, a clearinghouse or a provider that bills electronically, or by their business associates. The definition in 45 CFR 160.103 leaves out employment records, so a medical note in an HR file is PII, and often sensitive, but not PHI. Nonimo replaces the identifiers in either kind before the text reaches an AI tool.

Is an FMLA certification in the HR file PHI?

No. Once it sits in the employer's file it is an employment record, which the HIPAA definition of PHI excludes, and HHS says the Privacy Rule does not protect employment records even when they are health related. It is still a confidential medical record under 29 CFR 825.500(g), kept apart from the personnel file. Nonimo can take the employee's name and numbers out before any of it goes to an AI tool.

Is union membership sensitive personal information?

In California, yes. Civil Code 1798.140(ae) lists union membership next to racial or ethnic origin, citizenship or immigration status and religious beliefs. Virginia's list leaves it out, and Virginia's law does not reach employees at all. A payroll line for union dues can reveal membership without saying so, and Nonimo does not judge that: it replaces the name and numbers around it.

Does the CCPA cover employee data?

Yes, since January 1, 2023, when the exemption for job applicants and employees in Civil Code 1798.145(m) became inoperative. It applies to a business that meets the statute's size tests, such as annual revenue above $26,625,000 as adjusted for 2025. A small firm under every threshold is outside the CCPA, though its duties under the ADA, the FMLA and GINA stay the same.

Can HR put an accommodation request into ChatGPT?

No rule names chatbots, but the ADA says medical information from an accommodation request is a confidential medical record, and 29 CFR 1630.14 lists who may be told: supervisors about restrictions, first aid staff and government investigators. A software vendor is not on that list. The prudent course is to send the tool the request without the employee's identity, which is the part Nonimo takes out.

Is family medical history genetic information under GINA?

Yes. 29 CFR 1635.3(c) defines genetic information to include the manifestation of a disease in an employee's family members. So a leave request to care for a mother with cancer puts genetic information about the employee in the file, and 1635.9 limits disclosure to six listed cases. Nonimo can replace the names in that request; the medical facts it leaves for the reader to judge.

Does taking out the name make an FMLA note safe for AI?

Not by itself. A rare condition, a small team and a date can still point to one person, and an employee ID or a charge number left in the text works like a name. Take out every identifier, then read what remains as a coworker would. Nonimo handles the labeled names, numbers and addresses; that last reading stays with a person.

Does Nonimo decide whether a text is sensitive?

No. Nonimo does not classify a document as PHI or sensitive personal information, and it leaves diagnoses, religious practice and union membership in place, since those are usually what the task needs. It replaces the identifiers that tie them to a person, on your own computer, and the result is still personal information about someone your organization can identify.