A therapist in a small group practice mentioned a patient's diagnosis during a casual hallway conversation with the front desk staff. No chart was opened. No email was sent. But that one sentence — overheard by another patient sitting in the waiting room — triggered a complaint to the Office for Civil Rights. The practice had no verbal disclosure policy and no documentation of workforce training. What followed was a corrective action plan that consumed months of time and thousands in legal fees.
That story illustrates a truth many organizations learn the hard way: HIPAA protects a category of information that goes far beyond electronic records. It covers spoken words, paper charts, billing records, even images on a phone screen. If you don't understand the boundaries of that category, you're exposed in ways you probably haven't considered.
What Exactly Does "Protected Health Information" Mean?
HIPAA protects a category of information known as Protected Health Information, or PHI. The formal definition comes from 45 CFR §160.103, and it's broader than most people assume. PHI is any individually identifiable health information that is created, received, maintained, or transmitted by a covered entity or business associate.
That definition has three load-bearing elements. First, the information must relate to a person's health condition, healthcare provision, or payment for healthcare. Second, it must identify the individual — or provide a reasonable basis for identification. Third, a covered entity or business associate must hold or handle it.
Strip away any one of those three elements, and the information falls outside HIPAA's scope. A dataset with diagnoses but no names, dates of birth, or zip codes? Not PHI — assuming it's been properly de-identified under the HHS de-identification standard. Your personal Fitbit data sitting on your phone? Not PHI — because Fitbit isn't a covered entity.
The 18 Identifiers That Make Health Data PHI
HHS specifies 18 types of identifiers that, when linked to health information, create PHI. I've seen organizations get tripped up on identifiers they never considered. Here's the full list:
- Names
- Geographic data smaller than a state
- Dates (except year) related to an individual — birth date, admission date, discharge date, date of death
- Phone numbers
- Fax numbers
- Email addresses
- Social Security numbers
- Medical record numbers
- Health plan beneficiary numbers
- Account numbers
- Certificate/license numbers
- Vehicle identifiers and serial numbers
- Device identifiers and serial numbers
- Web URLs
- IP addresses
- Biometric identifiers (fingerprints, voiceprints)
- Full-face photographs and comparable images
- Any other unique identifying number, characteristic, or code
Attach any one of these to a diagnosis, treatment note, or billing record, and you're handling PHI. Period. That last catch-all identifier is the one that keeps compliance officers up at night — it means any code your organization assigns that could link back to an individual counts.
PHI Isn't Just in Your EHR — It's Everywhere
Here's what I see constantly in the field: organizations invest heavily in securing their electronic health record system while ignoring the dozen other places PHI lives. Think about appointment reminder texts, voicemails left on patient phones, paper sign-in sheets at the front desk, and the conversation your intake coordinator has in an open office.
Electronic PHI (ePHI) gets most of the regulatory attention because the HIPAA Security Rule sets specific administrative, physical, and technical safeguards for it. But the Privacy Rule covers PHI in all forms — electronic, paper, and oral. That hallway conversation I described at the top? It's a Privacy Rule problem, not a Security Rule problem.
This is exactly why verbal disclosure training matters as much as firewall configuration. Our course on Verbal Disclosures: Watch What You Say walks staff through the specific scenarios where spoken PHI creates real liability — waiting rooms, phone calls, elevator conversations, and more.
The $4.3 Million Mistake: When PHI Boundaries Get Ignored
In 2019, the University of Texas MD Anderson Cancer Center lost a case before an administrative law judge and was ordered to pay $4,348,000 in civil money penalties. The trigger? Unencrypted devices — a laptop and two USB drives — containing ePHI of over 33,000 individuals were lost or stolen. OCR found that MD Anderson had written encryption policies as far back as 2006 but never implemented them.
The lesson wasn't just about encryption. It was about understanding that HIPAA protects a category of information that demands consistent, enforced safeguards — not just written ones. Policies on paper mean nothing without implementation and workforce training. You can review the OCR enforcement page for MD Anderson for the full details.
What About Mental Health and Substance Abuse Records?
PHI from mental and behavioral health settings often carries extra protections. Psychotherapy notes — the personal notes a therapist keeps separate from the medical record — receive heightened protection under the Privacy Rule. They can't be disclosed for most purposes, even with a general authorization.
Substance use disorder records get a second layer of federal protection under 42 CFR Part 2, which restricts disclosure even further than standard HIPAA rules. If your organization handles behavioral health data, generic HIPAA training won't cut it. You need role-specific education, which is exactly what our HIPAA Training for Mental & Behavioral Health course delivers.
Quick Answer: What Category of Information Does HIPAA Protect?
HIPAA protects a category of information called Protected Health Information (PHI). PHI includes any individually identifiable health information — in electronic, paper, or oral form — held or transmitted by a covered entity or its business associates. It covers medical records, billing data, lab results, insurance claims, and any other health data linked to a specific person through one or more of the 18 HIPAA identifiers.
Common Misconceptions That Lead to Violations
"It's Not PHI if It's Already Public"
Wrong. If a patient posts their own diagnosis on social media, that doesn't give your staff permission to discuss it. The patient's voluntary disclosure doesn't change your obligations as a covered entity. Your workforce still needs authorization or a permitted use to share that information.
"De-Identified Data Is Always Safe"
Only if de-identification was done correctly. HHS allows two methods: the Expert Determination method and the Safe Harbor method. Safe Harbor requires removing all 18 identifiers and having no actual knowledge that the remaining data could identify someone. I've reviewed datasets that organizations called "de-identified" that still contained zip codes and dates of service — clearly not Safe Harbor compliant.
"HIPAA Only Applies to Doctors and Hospitals"
Covered entities include health plans, healthcare clearinghouses, and any healthcare provider that transmits health information electronically. Business associates — the vendors, consultants, IT firms, and billing companies that handle PHI on behalf of covered entities — are also directly liable under HIPAA. That's a lot more organizations than most people realize.
Practical Steps to Protect This Category of Information
After two decades of watching organizations stumble through compliance, here's what actually works:
- Map your PHI. Conduct a data inventory. Every system, filing cabinet, phone line, and third-party platform that touches PHI needs to be documented.
- Train every member of your workforce. Not just clinicians — receptionists, janitorial staff, volunteers, interns. Anyone who might encounter PHI needs role-appropriate training. HIPAA enforcement actions routinely cite insufficient workforce training as a contributing factor.
- Implement minimum necessary. Staff should access only the PHI they need for their specific job function. This isn't optional — it's a core Privacy Rule requirement under 45 CFR Part 164, Subpart E.
- Encrypt ePHI. Full disk encryption on all laptops, encrypted email for PHI transmissions, encrypted messaging platforms. The MD Anderson case should be all the motivation you need.
- Audit access logs. Regularly review who accessed what. Snooping — workforce members accessing records without a job-related reason — is one of the most common HIPAA violations and one of the easiest to detect with proper auditing.
Breach Notification: What Happens When Protection Fails
When PHI is compromised, the HIPAA Breach Notification Rule kicks in. Covered entities must notify affected individuals within 60 days. Breaches affecting 500 or more individuals require notification to HHS and prominent media outlets in the affected state. HHS publishes these on its public breach portal — commonly known as the "Wall of Shame."
In 2024 alone, OCR received reports of hundreds of breaches affecting 500 or more individuals. Each one represents an organization that failed to adequately protect the category of information HIPAA was designed to safeguard.
Your Next Move
Understanding that HIPAA protects a specific category of information — PHI — is step one. Step two is building systems, training, and culture that treat that information with the seriousness it demands. Every member of your workforce needs to know what PHI looks like in their daily role, where it hides, and what happens when it's mishandled.
If your team hasn't been trained recently — or if your training program doesn't address role-specific risks — start with the HIPAACertify training catalog. The penalties for ignorance are real, they're public, and they're growing.