A Single Fax Changed Everything for This Clinic
A dermatology practice in New England accidentally faxed a patient's lab results to a local pizza shop. The wrong number. An honest mistake. But that one page contained a name, a date of birth, a diagnosis, and a Social Security number. Within weeks, OCR had opened an investigation.
The clinic's compliance officer later told me the staff didn't fully understand what counted as protected information. They thought it was just medical records — charts, prescriptions, imaging. They were wrong. And if your workforce has the same gap, you're carrying the same risk.
So let's start at the foundation. PHI is an acronym for Protected Health Information, and it's far broader than most people realize.
PHI Is an Acronym For Protected Health Information — Here's the Full Definition
Under HIPAA, Protected Health Information refers to any individually identifiable health information that a covered entity or business associate creates, receives, maintains, or transmits. That definition comes directly from 45 CFR §160.103.
Let me break that down into two parts, because both matter equally.
"Individually Identifiable"
The information must relate to a specific person. It has to identify the individual — or provide a reasonable basis for identification. A blood pressure reading sitting alone on a sticky note isn't PHI. But attach a patient name or medical record number to it, and it becomes PHI instantly.
"Health Information"
This covers any data related to a person's past, present, or future physical or mental health condition, the provision of healthcare, or the payment for healthcare services. That last one catches people off guard. Billing records, insurance claims, payment histories — all PHI.
The 18 Identifiers That Turn Data Into PHI
HHS defines 18 specific identifiers under the HIPAA Privacy Rule. When any of these are linked to health information, you're dealing with PHI. Here's the full list:
- Names
- Geographic data smaller than a state
- Dates (except year) related to an individual — birth, admission, discharge, death
- Phone numbers
- Fax numbers
- Email addresses
- Social Security numbers
- Medical record numbers
- Health plan beneficiary numbers
- Account numbers
- Certificate/license numbers
- Vehicle identifiers and serial numbers
- Device identifiers and serial numbers
- Web URLs
- IP addresses
- Biometric identifiers (fingerprints, voiceprints)
- Full-face photographs and comparable images
- Any other unique identifying number, characteristic, or code
That eighteenth category is the catch-all. It's deliberately broad. If a data element can be used to identify a patient — even indirectly — treat it as PHI.
ePHI: When PHI Goes Digital, the Stakes Get Higher
When Protected Health Information is created, stored, or transmitted in electronic form, it becomes ePHI — electronic Protected Health Information. The HIPAA Security Rule applies specifically to ePHI and requires covered entities and business associates to implement administrative, physical, and technical safeguards.
I've seen organizations assume their paper-based patient intake forms don't fall under the Security Rule. They're right about that narrow point. But the moment a staff member scans that form into a shared drive or emails it to a referral partner, it's ePHI. And every safeguard requirement kicks in.
The HHS Security Rule guidance page is the best starting point if you need to audit your technical controls.
What Doesn't Count as PHI?
This question deserves a clear answer because I hear it constantly.
De-identified data is not PHI. If you strip all 18 identifiers from a dataset and have no reasonable basis to re-identify individuals, HIPAA no longer governs that data. The Privacy Rule outlines two acceptable methods for de-identification: expert determination and safe harbor. Both are described in HHS's de-identification guidance.
Employment records held by a covered entity in its role as an employer are also excluded from PHI. Your employee sick notes in HR files aren't PHI under HIPAA — though other laws may still protect them.
Education records covered by FERPA are carved out as well. A university health center's student records may fall under FERPA rather than HIPAA, depending on the arrangement.
The $1.5 Million Mistake Most Organizations Don't See Coming
In 2018, OCR settled with Filefax, Inc. for $100,000 after PHI from medical records was found dumped in an unlocked vehicle accessible to unauthorized individuals. That might sound small, but consider: Filefax was a records storage company — a business associate. They didn't even provide healthcare. They just handled PHI.
Larger settlements have driven the point home even harder. Premera Blue Cross paid $6.85 million in 2020 after a breach affecting over 10.4 million people. The root cause? Failures in security controls around ePHI.
These aren't edge cases. They're patterns. When organizations fail to define PHI correctly for their workforce, they fail to protect it. And OCR doesn't accept "we didn't know" as a defense.
Why Your Staff Needs More Than a Definition
Knowing that PHI is an acronym for Protected Health Information is the easy part. The hard part is teaching your workforce to recognize PHI in the wild — in a voicemail, on a whiteboard in a hallway, in an appointment reminder text message, on a screen visible to a waiting room.
In my experience, organizations that invest in structured HIPAA workforce training see measurably fewer incidents. Not because training is magic, but because it forces your team to confront real scenarios. The definition alone won't prevent a breach. Pattern recognition will.
Does Every Employee Need to Know This?
Yes. The HIPAA Privacy Rule requires covered entities to train all workforce members on PHI policies and procedures. That includes volunteers, trainees, and part-time staff — not just clinicians. The receptionist who confirms appointments by phone handles PHI. The IT contractor who migrates your EHR database handles ePHI. Everyone in the chain matters.
If your training program hasn't been updated recently, start with the HIPAACertify training catalog to find role-specific courses that cover PHI identification, breach notification requirements, and practical safeguards.
PHI in the Age of AI and Cloud Platforms
Here's where this gets urgent for 2026. Organizations are feeding patient data into AI tools, cloud-based scheduling platforms, and third-party analytics dashboards — often without executing business associate agreements. Every one of those tools that touches PHI triggers HIPAA obligations.
I recently reviewed a behavioral health practice that was using a popular AI transcription service to convert therapy session recordings into clinical notes. The recordings contained names, diagnoses, and treatment plans. That's PHI flowing to a third-party vendor with no BAA in place. The exposure was staggering.
If your organization uses any cloud-based tool that processes patient information, ask one question first: Is there a signed business associate agreement? If not, stop using it until there is one.
Quick Reference: PHI vs. Non-PHI
- PHI: A lab report with a patient's name, DOB, and diagnosis sent via fax
- Not PHI: Aggregate hospital admission statistics with no identifiers
- PHI: An insurance claim form with a member ID and procedure codes
- Not PHI: A medical textbook description of diabetes symptoms
- PHI: A voicemail from a pharmacy confirming a patient's prescription by name
- Not PHI: De-identified research data stripped of all 18 identifiers
The Bottom Line for Your Organization
PHI is an acronym for Protected Health Information, but understanding those three words requires more than a glossary entry. It requires knowing the 18 identifiers, recognizing PHI in every format — paper, electronic, verbal — and training every workforce member to handle it properly.
OCR has made clear through years of enforcement that ignorance about PHI is itself a compliance failure. The organizations that avoid seven-figure penalties aren't lucky. They're trained.
Start with the fundamentals. Review the HIPAA training options at HIPAACertify and make sure your team can answer not just what PHI stands for — but what it looks like in their daily work.