The HIPAA Privacy Rule protects all individually identifiable health information that is held or transmitted by covered entities and their business associates. The information may be in any form (e.g., paper, electronic, oral). The Privacy Rule calls this information protected health information (PHI) . A covered entity may not use or disclose PHI except as permitted or required by the Privacy Rule.