A Single Misrouted Fax Cost This Clinic $125,000
A small physician practice in Tennessee faxed a patient's lab results to a local gym instead of a referring specialist. One misdialed number. One sheet of paper. The Office for Civil Rights (OCR) investigated, found systemic failures in how the practice handled protected health information, and the settlement hit six figures.
That story captures exactly why understanding PHI and HIPAA isn't optional — it's the foundation of every compliance program in healthcare. If you've ever searched "PHI and HIPPA" (yes, with the common misspelling), you're in the right place. Let's clear up what PHI actually is, how HIPAA protects it, and what happens when your organization gets it wrong.
What Exactly Is PHI Under HIPAA?
Protected Health Information — PHI — is any individually identifiable health information that a covered entity or business associate creates, receives, maintains, or transmits. That's the textbook definition. Here's what it means in practice.
PHI includes a patient's name linked to a diagnosis, a Social Security number on a billing record, an email address in a pharmacy database, or a photograph taken during a clinical visit. If you can use the information to identify a specific person and it relates to their health condition, treatment, or payment for care, it's PHI.
The 18 Identifiers You Need to Memorize
HHS defines 18 specific identifiers that make health information "individually identifiable." They include names, dates (except year), phone numbers, geographic data smaller than a state, Social Security numbers, medical record numbers, device identifiers, biometric data, and full-face photographs, among others.
Strip all 18 from a dataset, and it's no longer PHI — it's de-identified data. Leave even one attached, and you're in HIPAA territory.
PHI vs. ePHI: The Distinction That Trips People Up
When PHI exists in electronic form — in an EHR, on a laptop, in a text message, stored on a thumb drive — it becomes electronic protected health information (ePHI). The HIPAA Security Rule applies specifically to ePHI and requires administrative, physical, and technical safeguards.
I've seen organizations assume that paper records are the bigger risk because they're harder to track. The reality? OCR enforcement data tells a different story. Lost or stolen electronic devices, unencrypted email transmissions, and misconfigured cloud servers account for the majority of large breach reports on the HHS Breach Portal.
Common ePHI Mistakes I See Constantly
- Texting patient information on personal phones without encryption
- Storing discharge summaries in shared Google Drives with no access controls
- Emailing lab results to patients without verifying the address
- Leaving EHR sessions open on shared workstations
Every one of these is a violation waiting to become a breach.
The $4.3 Million Wake-Up Call from MD Anderson
If you want to understand how seriously OCR takes PHI and HIPAA violations, look at the University of Texas MD Anderson Cancer Center case. OCR imposed a $4.3 million civil monetary penalty after three separate breaches involving unencrypted devices — a stolen laptop and two lost thumb drives containing ePHI of over 33,000 individuals.
MD Anderson argued that encryption wasn't required, only "addressable" under the Security Rule. An administrative law judge and the HHS Departmental Appeals Board both disagreed. The penalty stood. The lesson? "Addressable" doesn't mean "optional." If you choose not to encrypt, you'd better document why and implement an equivalent safeguard.
Who Does HIPAA Actually Apply To?
HIPAA's Privacy and Security Rules apply to covered entities — health plans, healthcare clearinghouses, and healthcare providers who transmit health information electronically. They also apply to business associates: the billing companies, IT vendors, cloud storage providers, and shredding services that handle PHI on behalf of covered entities.
If your organization touches PHI in any form, you're on the hook. Period.
Your Workforce Is Your Biggest Variable
Here's something I tell every client: technology doesn't violate HIPAA. People do. Your nurses, front-desk staff, billing specialists, and even your physicians are the ones who access, share, and sometimes mishandle PHI every day.
That's why workforce training isn't just a checkbox — it's your single most effective compliance control. OCR looks for evidence of regular, role-specific training in virtually every investigation. If you can't produce it, expect a corrective action plan at minimum.
For clinical teams, I recommend starting with a structured program like the HIPAA Training for Nurses course, which maps compliance concepts directly to real clinical workflows.
What Counts as a PHI Breach?
A breach is any unauthorized acquisition, access, use, or disclosure of PHI that compromises its security or privacy. Under the Breach Notification Rule, covered entities must perform a four-factor risk assessment to determine whether a breach has occurred:
- The nature and extent of the PHI involved
- Who accessed or received the PHI
- Whether the PHI was actually acquired or viewed
- The extent to which the risk has been mitigated
If the assessment shows more than a low probability of compromise, you must notify affected individuals within 60 days, report to HHS, and — if the breach affects 500 or more people — notify prominent media outlets in the state.
The Penalty Tiers You Should Know
OCR enforces HIPAA violations across four penalty tiers, ranging from $137 to $68,928 per violation, with annual caps reaching into the millions. These numbers are adjusted periodically for inflation. Willful neglect that goes uncorrected carries the steepest penalties.
But financial penalties are only part of the damage. Breach notification costs, legal fees, credit monitoring for affected patients, and reputational harm can dwarf the OCR settlement itself.
How to Protect PHI in Your Organization Right Now
You don't need a six-figure consulting engagement to start closing gaps. Here's what I tell small and mid-size practices to do immediately.
Conduct an Actual Risk Analysis
Not a questionnaire someone filled out in 2019. A real, documented assessment of where ePHI lives, how it moves, and what could go wrong. OCR has cited the failure to conduct a comprehensive risk analysis in case after case — including the Premera Blue Cross $6.85 million settlement and the Anthem $16 million settlement.
Encrypt Everything That Moves
Laptops. Phones. USB drives. Email. If ePHI travels on it or lives on it, encrypt it. Encryption is the single most effective technical safeguard, and it provides a safe harbor under the Breach Notification Rule. If an encrypted device is lost or stolen and the key wasn't compromised, it's not a reportable breach.
Train Every Member of Your Workforce — Every Year
HIPAA requires training for all workforce members, including volunteers and trainees. Make it role-specific. A billing clerk faces different PHI risks than a nurse in a busy ER. Explore the full HIPAA training catalog to find courses that match your team's actual responsibilities.
Document Everything
Policies, training records, risk analyses, incident response plans, business associate agreements — if it isn't documented, it didn't happen. OCR investigators ask for documentation first. Your compliance program is only as strong as the paper trail behind it.
Quick Answer: What Is the Relationship Between PHI and HIPAA?
PHI is what HIPAA protects. HIPAA is the federal law — the Health Insurance Portability and Accountability Act — that establishes national standards for safeguarding protected health information. The Privacy Rule governs how PHI can be used and disclosed. The Security Rule requires specific safeguards for ePHI. The Breach Notification Rule dictates what happens when PHI protections fail. Together, they form the regulatory framework that every covered entity and business associate must follow.
Stop Treating Compliance as a One-Time Project
PHI and HIPAA compliance isn't something you "finish." It's an ongoing operational discipline. Your patient data changes. Your technology changes. Your workforce turns over. Threats evolve. The organizations that avoid OCR settlements and breach headlines are the ones that treat compliance as a living program — with regular training, updated risk analyses, and leadership that actually cares about protecting patient information.
I've watched organizations spend millions recovering from breaches they could have prevented with a few thousand dollars of investment in training and encryption. Don't be one of them.