Any information, including genetic information, whether oral or recorded in any form or medium, that: (1) Is created or received by a healthcare provider, health plan, public health authority, employer, life insurer, school or university, or healthcare clearinghouse; and (2) Relates to the past, present, or future physical or mental health or condition of an individual; the provision of healthcare to an individual; or the past, present, or future payment for the provision of healthcare to an individual.
Sources:
NIST SP 800-66r2
under health information
from
HIPAA Security Rule - §160.103
Sources:
NIST SP 800-66r2
under health information