A medical receptionist forwards a patient's appointment reminder to her personal email so she can "finish up at home." That email contains the patient's name, date of birth, and diagnosis code. She doesn't think twice about it. Three months later, her laptop is stolen from a coffee shop, and an OCR investigation reveals a breach affecting 1,200 patients. This is exactly the kind of scenario that plays out when staff can't answer a basic question: which of the following are examples of PHI?

If your workforce can't spot protected health information in the wild, your organization is exposed. Not theoretically — financially, legally, and reputationally. Let's break down exactly what counts as PHI, what doesn't, and where the line gets dangerously blurry.

Which of the Following Are Examples of PHI? The Direct Answer

Protected health information (PHI) is any individually identifiable health information that a covered entity or business associate creates, receives, maintains, or transmits. It includes information about a patient's past, present, or future health condition, the provision of healthcare, or payment for healthcare — when linked to a specific individual.

Here are common examples that qualify as PHI:

  • A patient's name combined with a diagnosis
  • A medical record number
  • A health insurance claim with a Social Security number
  • An X-ray image stored in an electronic health record
  • A billing record that includes a patient's address and treatment codes
  • An email containing a patient's lab results and date of birth

And here's what does not qualify as PHI: de-identified data stripped of all 18 identifiers, aggregate statistical data with no link to an individual, and employment records held in a personnel file (even if they contain health info, they fall under different regulations).

The 18 Identifiers That Turn Data Into PHI

HHS defines 18 specific identifiers under the HIPAA Privacy Rule. When any one of these is combined with health information, you've got PHI on your hands. I've seen organizations get tripped up by identifiers they never considered sensitive.

The Full List

  • Names
  • Geographic data smaller than a state (street address, city, ZIP code)
  • Dates directly related to an individual (birth date, admission date, discharge date, date of death)
  • Phone numbers
  • Fax numbers
  • Email addresses
  • Social Security numbers
  • Medical record numbers
  • Health plan beneficiary numbers
  • Account numbers
  • Certificate/license numbers
  • Vehicle identifiers and serial numbers (including license plates)
  • Device identifiers and serial numbers
  • Web URLs
  • IP addresses
  • Biometric identifiers (fingerprints, voiceprints)
  • Full-face photographs and comparable images
  • Any other unique identifying number, characteristic, or code

That last one is the catch-all, and it's broader than most people realize. I've worked with organizations that assigned internal patient codes thinking they were safe, only to learn those codes still qualify as identifiers under HIPAA.

The Difference Between PHI and ePHI — and Why It Matters

PHI exists in any format: paper charts, verbal conversations, faxes, printed lab results. Electronic protected health information (ePHI) is simply PHI that's created, stored, or transmitted electronically. The distinction matters because ePHI triggers the HIPAA Security Rule, which imposes specific technical, physical, and administrative safeguards.

A patient's name scrawled on a sticky note attached to a paper chart? That's PHI, governed by the Privacy Rule. That same patient's name in your EHR system? That's ePHI, and now the Security Rule applies too. Your IT infrastructure, access controls, encryption standards, and audit logs all come into play.

In my experience, organizations that treat PHI and ePHI as a single concept end up with gaps in their compliance programs. The safeguard requirements are different, and OCR knows the difference when they come knocking.

The $3 Million Mistake: Real PHI Violations From OCR

Let me show you what happens when staff mishandle examples of PHI.

In 2018, Fresenius Medical Care North America agreed to a $3.5 million settlement with OCR after five separate breach incidents. The breaches involved stolen laptops, a stolen USB drive, and a missing hard drive — all containing ePHI. The root cause? Fresenius failed to conduct adequate risk analyses and didn't implement proper device-level protections for hardware containing patient identifiers.

Every one of those devices held data that someone should have recognized as PHI: patient names, treatment records, Social Security numbers. The staff handling those devices either didn't know what they were carrying or didn't treat it with the seriousness HIPAA demands.

A Smaller Case, Same Lesson

In 2017, St. Luke's-Roosevelt Hospital Center paid $387,200 after a physician impermissibly disclosed PHI — including HIV status — to a patient's employer. The physician didn't realize that transmitting a patient's diagnosis alongside identifying information to an unauthorized third party was a clear HIPAA violation. That's a textbook example of failing to recognize what constitutes PHI and who's authorized to receive it.

Where Staff Get Confused: The Gray Areas of PHI

The exam-style question "which of the following are examples of PHI" seems straightforward. In practice, the gray areas trip people up constantly.

Scenario 1: The Unnamed Patient

A nurse posts on social media: "Had a 94-year-old patient today with the most amazing recovery from a triple bypass." No name mentioned. But if the hospital only has one 94-year-old triple bypass patient that week, and a small community could identify them? That's potentially identifiable health information. Context matters.

Scenario 2: The Voicemail

Your office leaves a voicemail: "This is Dr. Rivera's office calling about your test results. Please call us back." That's generally acceptable — it doesn't disclose specific health information. But if the voicemail says, "We're calling from the oncology department about your biopsy results," you've just disclosed PHI to whoever hears that message.

Scenario 3: The Work Email

An HR manager receives a doctor's note for an employee's absence. The note says the employee was treated for a condition and needs two weeks off. Is this PHI? Not under HIPAA — employment records held by an employer acting as an employer are not covered. But if that same employer is also a covered entity (like a hospital), and the information is in a patient record rather than an employment file, the analysis changes entirely.

These are the real-world situations that make workforce training essential. Your staff needs to recognize PHI not just on a multiple-choice test, but in the hallway, the parking lot, and the inbox.

How to Protect PHI Across Your Organization

Recognition is only step one. Once your workforce can identify examples of PHI, they need clear procedures for protecting it.

Administrative Safeguards

  • Conduct a thorough risk analysis annually — this is where OCR investigations almost always start
  • Implement role-based access so staff only see the PHI they need for their job function
  • Train every workforce member, not just clinical staff — billing, IT, front desk, volunteers, and contractors all handle PHI

Technical Safeguards for ePHI

  • Encrypt all ePHI at rest and in transit
  • Enable automatic logoff on workstations
  • Maintain audit controls that track who accessed what and when
  • Use unique user IDs — shared logins make breach investigations nearly impossible

Physical Safeguards

  • Lock filing cabinets containing paper records
  • Position monitors away from public view
  • Implement visitor access controls in areas where PHI is stored or discussed

If this list feels overwhelming, start with the risk analysis. Every enforcement action I've reviewed circles back to the same failure: the organization never properly assessed where PHI lived and what threatened it.

Training Is the Only Scalable Fix

You can buy the best encryption software on the market. You can hire a Chief Privacy Officer. But if your receptionist doesn't know that a patient's email address combined with an appointment date is PHI, none of it matters.

HIPAA requires workforce training under both the Privacy Rule (45 CFR §164.530) and the Security Rule (45 CFR §164.308). It's not optional, and it's not a one-time event. Every new hire needs training, and your entire workforce needs refreshers when policies change or new threats emerge.

I've seen organizations invest six figures in technology and then skip the $30-per-person training that would have prevented their breach. It's the most cost-effective compliance investment you can make. Explore our HIPAA training catalog to find role-specific courses that teach your staff to recognize and protect PHI in real-world situations.

The Bottom Line for Covered Entities

When someone searches "which of the following are examples of PHI," they're usually studying for a certification exam or trying to solve a real compliance problem. Either way, the answer has consequences.

PHI is any health information linked to an individual through one or more of the 18 HIPAA identifiers. It exists on paper, in conversation, and in every electronic system your organization touches. Mishandling it triggers breach notification requirements, OCR investigations, and penalties that can reach millions.

Your staff needs to identify PHI instinctively — not after a breach, but before one. Build that instinct through consistent, comprehensive HIPAA workforce training that goes beyond definitions and into the scenarios your team actually faces every day.

Because the next time your organization encounters a real-world version of "which of the following are examples of PHI," the answer won't be multiple choice. And the penalty for getting it wrong won't be a lost point on a quiz.