HIPAA protects ALL personal health information of a patient, including physical and mental health information, payment information, and demographic information. It applies to all oral, written, and electronic forms. Collectively, the information is referred to as protected health information, or PHI.
PHI can be used and disclosed by covered entities and business associates as long as they remain compliant with HIPAA.