PII, SPII, and PHI… Oh My!

Christian Guilbert • March 11, 2025
What schools and businesses need to know about PII, SPII, and PHI.

Why Every Industry Needs to Pay Attention

It's been a while since my last blog post, so let’s have a quick heart-to-heart about data. No, not the “how fast is your internet” kind, but the stuff that can blow up in your face if you’re not careful: Personally Identifiable Information (PII), Sensitive PII (SPII), and Protected Health Information (PHI).


Most people think of HIPAA when they hear “data protection” and a mental picture of a nurse whispering behind a clipboard. But the truth is, this goes way beyond hospitals and insurance companies. If you're storing student records, managing financial data, or even a name + email combo in your system, you're part of the data protection party whether you like it or not.

Decoding the Acronyms (Without Putting You to Sleep)

  • PII is your baseline: names, addresses, phone numbers, etc. Anything that can identify someone.
  • Sensitive PII (SPII) takes it up a bit, think Social Security numbers, financial info, or a combo of data points that, if leaked, could hurt someone.
  • PHI is a special kind of sensitive data, tied to health information and regulated by HIPAA. It only counts if it’s collected by or on behalf of a healthcare provider or related entity.

But here's the kicker: this kind of data shows up everywhere.

Hey Educators, It's Not Just Doctors and Bankers

You might not run a hospital, but if you're in the education sector, you're sitting on a gold mine of student data that could qualify as PII or SPII, and sometimes even PHI (think student IEPs, mental health services, or health clinic visits).

  • Have a student database with names, addresses, and dates of birth? That’s PII.
  • Store scanned copies of student IDs or transcripts? Likely SPII.
  • Offer onsite counseling or track immunization records? You just entered PHI territory.

Basically, you don’t have to be a healthcare provider or financial institution to have serious compliance responsibilities. Oh yeah, even Europe's GDPR has a say in it if you’re collecting info from someone in the EU. Fun...

What Happens When It All Goes Sideways

If this info gets compromised, it’s not just a bad day at the office, it could lead to:

  • Identity theft
  • Financial fraud
  • Breach notification requirements
  • Loss of trust
  • Fines (we’re talking six or seven digits depending on the industry)

And no, some generic "we care about your privacy" footer on your website or emails isn’t going to cut it.

So What Can You Do?

I'm glad you asked. Here's a quick list to stay on top of your data protection game:

  • Encrypt data at rest (on your devices and servers) and in motion (during transfer)
  • Lock down access. Only those who need the data should be able to see it
  • Use MFA and VPNs for remote access
  • Educate your staff. Phishing is still the #1 way bad actors sneak in
  • Audit your systems regularly. Don’t wait for a breach to find the holes
  • Know your data. Map out what you’re collecting and whether it qualifies as PII, SPII, or PHI

If that list made your head spin a little? You’re not alone.

Ready to Lock It Down?

Whether you're a school, a business, a clinic, or something in between, the responsibility to protect your users' data is real. The risks are higher than ever, but so are the tools available to help you stay ahead of the game.


Need help sorting out what data you have and how to protect it? CGuilbert Technologies is here for that.  Shoot us a message before your next “security update” comes with a lawsuit attached. We promise we encrypt our emails… and our jokes.

Image of Christian Guilbert, President and Chief Technology Simplifier of CGuilbert Technologies LLC.

Christian Guilbert

Chief Technology Simplifier

#TechTuesday

A nurse stares at a red error message on her computer.
By Christian Guilbert June 17, 2025
Windows 10 hits end-of-life on October 14, 2025. Learn what this means, why ESU isn't the answer, and how to upgrade before time runs out.
Illustration of a teacher using cloud-based tools in a tech-enabled classroom
By Christian Guilbert May 6, 2025
Discover the latest IT trends transforming Midwest K–12 schools: cloud tools, cybersecurity, AI, and why managed IT support matters more than ever.
Healthcare workers managing digital records
By Christian Guilbert April 8, 2025
Cyberattacks are rising in healthcare. Learn 2025 trends in cybersecurity, HIPAA compliance, and how MSPs like us help protect small medical practices.
Treasure chest of digital gold
By Christian Guilbert April 23, 2024
Explore our guide on must-have essential tech tools for small businesses with CGuilbert Technologies. Navigate the digital age with confidence and grow your business with our expert insights and IT solutions. Visit us now to unlock your business's potential. #TechTuesday
Uncover essential data backup strategies and best practices to protectyour business's digital assets
By Christian Guilbert April 16, 2024
Uncover essential data backup strategies and best practices to ensure your business's digital assets are secure. Learn how to protect your data effectively with CGuilbert Technologies. #TechTuesday
exhausted computer
By Christian Guilbert April 9, 2024
Boost your PC's performance with expert tips on decluttering, updating software, and upgrading hardware. #TechTuesday
By Christian Guilbert April 2, 2024
Uncover the transformative role of AI in business with CGuilbert Technologies. Explore how artificial intelligence optimizes decision-making, customer service, marketing, and more to drive growth and innovation. Let's navigate the AI landscape together. #TechTuesday
key unlocking a digital door
March 26, 2024
Discover the key to securing your digital world. Explore tips on creating strong passwords, the critical role of password managers, and enhancing security with two-factor authentication. Elevate your digital safety today. #TechTuesday
futuristic home office
By Christian Guilbert March 19, 2024
Discover essential tips for setting up an efficient home office in 2024. Learn how to integrate technology, prioritize ergonomics, and personalize your workspace for maximum productivity and comfort. #TechTuesday
By Christian Guilbert March 12, 2024
Become a leading Education Technology leader and mentor with our latest Tech Tuesday post. Guiding you through the essential traits, strategies, and continuous learning paths needed to light the way in educational technology. Transform tech intimidation into enlightenment today. #TechTuesday
More Posts