A medical assistant at a cardiology practice in Texas forwarded a spreadsheet to her personal email so she could "finish some work at home." The spreadsheet contained 3,200 patient names, dates of birth, and diagnosis codes. She didn't think it was a big deal — she thought it was just "office data." That single misunderstanding about what qualifies as protected health information cost the practice a breach investigation and months of remediation. This is exactly why understanding which of the following items does not contain PHI isn't just a quiz question — it's a daily operational decision your workforce makes dozens of times per shift.

I've spent years reviewing incidents that started because someone couldn't distinguish PHI from non-PHI. The line isn't always obvious, and that's the problem.

Which of the Following Items Does Not Contain PHI? The Direct Answer

If you've encountered this question on a HIPAA training exam, you've likely seen answer choices like these:

  • A. A hospital bill sent to a patient
  • B. A lab report with a patient's name and results
  • C. A medical device brochure with general product information
  • D. An appointment reminder with a patient's name and date

The answer is C — a medical device brochure with general product information. It contains no individually identifiable health information linked to a specific person. No name, no diagnosis, no treatment detail, no identifier. It's marketing material, not PHI.

The other options each tie health-related data to an identifiable individual — which is exactly what makes something PHI under the HIPAA Privacy Rule.

What Actually Makes Something PHI Under HIPAA

PHI isn't just medical records. The definition is broader than most people realize, and that breadth is where mistakes happen.

Under 45 CFR §160.103, protected health information is any individually identifiable health information that is created or received by a covered entity or business associate. It covers information that relates to a person's past, present, or future physical or mental health condition, the provision of healthcare, or payment for healthcare — and that identifies the individual or could reasonably be used to identify them.

Both conditions must be true. Health data alone isn't PHI. An identifier alone isn't PHI. Combined? That's PHI.

The 18 Identifiers That Trigger PHI Status

HHS defines 18 specific identifiers under the Safe Harbor de-identification method. When any of these are attached to health information, you're dealing with PHI:

  • Names
  • Geographic data smaller than a state
  • Dates (except year) related to an individual — birth date, admission date, discharge date, date of death
  • Phone numbers
  • Fax numbers
  • Email addresses
  • Social Security numbers
  • Medical record numbers
  • Health plan beneficiary numbers
  • Account numbers
  • Certificate/license numbers
  • Vehicle identifiers and serial numbers
  • Device identifiers and serial numbers
  • Web URLs
  • IP addresses
  • Biometric identifiers
  • Full-face photographs and comparable images
  • Any other unique identifying number, characteristic, or code

Strip all 18 from a dataset, and you've de-identified it. It's no longer PHI. Leave even one attached to health data, and every HIPAA safeguard applies.

Common Items That Trick People

In my experience, it's not the obvious examples that cause breaches. It's the gray-area items your staff handles every day without thinking twice.

Appointment Schedules

A printed schedule taped to the wall behind the front desk with patient names and appointment times? That's PHI. The appointment itself is "provision of healthcare." Add a name, and you've crossed the line. I've seen practices post these in plain view of waiting rooms — an easy violation to fix, but a common one.

Billing Records and Invoices

An invoice that lists a patient's name, the date of service, and a procedure code contains PHI. It ties a specific person to a specific healthcare service. Even an Explanation of Benefits (EOB) from a health plan qualifies. Your billing department handles PHI constantly.

Emails and Text Messages

An email from a nurse to a physician that says "Mrs. Rodriguez's A1C came back at 9.2" is ePHI. It's electronic, it's identifiable, and it's health information. If that email crosses an unencrypted channel, you have a potential breach on your hands.

Items That Are NOT PHI

Here's where clarity matters most. These items do not contain PHI:

  • A blank intake form (no patient data filled in)
  • A medical textbook describing symptoms of diabetes
  • A brochure about a new MRI machine
  • Aggregate statistics like "42% of our patients have hypertension" (no individual identifiers)
  • Employment records held by a covered entity in its role as employer
  • De-identified data that has had all 18 identifiers removed

That last one catches people. A covered entity's employment records — like an employee's sick days or workers' comp file — are explicitly excluded from PHI under the Privacy Rule, even though they might contain health information.

The $4.3 Million Lesson From MD Anderson

The University of Texas MD Anderson Cancer Center learned the cost of PHI mishandling the hard way. In 2018, an administrative law judge upheld $4,348,000 in penalties after unencrypted devices containing ePHI were lost or stolen. The stolen laptop and USB drives contained patient names, treatment information, and other identifiers — textbook PHI.

If that data had been de-identified or encrypted, the outcome would have been entirely different. The case wasn't about a sophisticated cyberattack. It was about basic classification: knowing what's PHI, knowing it's on that device, and encrypting accordingly. OCR's enforcement page for MD Anderson lays out the full timeline.

Why This Question Keeps Showing Up on Training Exams

There's a reason every serious HIPAA training program includes some version of "which of the following items does not contain PHI." It tests the foundational skill your entire compliance program depends on: can your workforce correctly classify information?

If they can't, everything downstream fails. Your access controls don't work if staff don't know what they're protecting. Your breach notification procedures don't trigger if no one recognizes PHI left in a printer tray. Your minimum necessary standard is meaningless if employees can't distinguish a patient chart from a supply order.

This is why OCR consistently emphasizes workforce training in its enforcement actions. A well-trained employee who understands PHI classification is your first and most effective line of defense. If your team hasn't completed updated HIPAA training, our HIPAA training catalog covers PHI identification scenarios in practical, real-world terms.

How to Build PHI Recognition Into Daily Operations

Label and Classify at the Point of Creation

Don't wait for an audit to figure out what's PHI. Train your staff to classify information the moment they create or receive it. A new intake form gets filled out? It's PHI. A vendor sends a product spec sheet? It's not. Make the determination immediately.

Run Tabletop Exercises

I recommend quarterly tabletop exercises where you present real-world scenarios to your team. Show them a screenshot of a scheduling board, a billing statement, a de-identified research dataset. Ask them: PHI or not? The conversations that follow are more valuable than any lecture.

Audit Your Physical Spaces

Walk through your office and look for exposed PHI. Sign-in sheets with full names and appointment reasons. Fax cover sheets sitting in shared areas. Computer screens visible from hallways. These are all common findings in OCR investigations, and they're all fixable in an afternoon.

Update Your Training Annually

HIPAA doesn't specify a training frequency, but annual training is the industry standard and what OCR expects to see. Your workforce changes, your systems change, and the threat landscape changes. If your last training session was more than 12 months ago, explore the workforce training options at HIPAACertify to get current.

The Bottom Line: Classification Is Compliance

Every HIPAA requirement — access controls, encryption, breach notification, business associate agreements — depends on one threshold question: is this PHI?

If your workforce can't answer that question correctly and consistently, your compliance program has a crack in its foundation. The quiz question about which items don't contain PHI isn't academic. It mirrors the exact judgment calls your receptionist, your billing clerk, and your IT admin make every single day.

Get this right, and every other compliance requirement becomes easier. Get it wrong, and you're one lost laptop or misdirected fax away from an OCR investigation.