A hospital employee in Texas forwards a patient's lab results to her personal Gmail account so she can "finish up charting at home." She doesn't think twice about it. Six months later, that email is part of an OCR investigation, and the hospital is staring down a six-figure settlement. The core issue? Nobody on her team could clearly articulate the PHI data definition — so nobody recognized the violation happening in real time.
I've seen this pattern play out in clinics, billing companies, and health plans more times than I can count. The staff isn't malicious. They just don't understand what PHI actually is, where the boundaries fall, and why it matters. This post will fix that for you and your organization.
The PHI Data Definition Under HIPAA, Explained Simply
Protected Health Information — PHI — is any information about a person's health status, healthcare provision, or payment for healthcare that can be linked to a specific individual. That's the short version. The legal definition lives in 45 CFR §160.103, and it's broader than most people expect.
Here's what trips people up: the data doesn't have to be a diagnosis or a medical record to qualify as PHI. A patient's name sitting next to an appointment date is PHI. A phone number attached to a prescription refill request is PHI. An email address linked to a therapy session is PHI.
The key is the combination. Health information alone — without an identifier — is not PHI. An identifier alone — without health context — is not PHI. Put them together, and you've created something HIPAA protects with teeth.
What Qualifies as an "Identifier"? The 18 Elements You Must Know
HHS defined exactly 18 types of identifiers that, when connected to health information, create PHI. Here's the full list:
- Names
- Geographic data smaller than a state
- Dates (except year) related to an individual — birth date, admission date, discharge date, date of death
- Phone numbers
- Fax numbers
- Email addresses
- Social Security numbers
- Medical record numbers
- Health plan beneficiary numbers
- Account numbers
- Certificate/license numbers
- Vehicle identifiers and serial numbers (including license plates)
- Device identifiers and serial numbers
- Web URLs
- IP addresses
- Biometric identifiers (fingerprints, voiceprints)
- Full-face photographs and comparable images
- Any other unique identifying number, characteristic, or code
That last one is the catch-all, and it's intentionally broad. If your organization uses a proprietary patient ID number, that's an identifier. If you assign codes that can be traced back to a person, that's an identifier.
The $1.5 Million Mistake: When Organizations Get the PHI Data Definition Wrong
In 2018, OCR settled with Filefax, Inc. for $100,000 after the company left medical records — PHI — in an unlocked vehicle that was then left at a recycling facility. The records included names, dates, Social Security numbers, and treatment information. It was a small company. The fine could have been catastrophic.
Larger organizations haven't been spared. Advocate Health Care Network paid $5.55 million in 2016 after multiple breaches involving ePHI — including stolen laptops containing unencrypted records of roughly 4 million patients. The underlying problem in case after case? Staff and leadership didn't fully grasp what constituted PHI, where it lived, and how to protect it.
These aren't abstract regulatory stories. They're budget-destroying events that start with someone saying, "I didn't think that was PHI."
PHI vs. ePHI: A Critical Distinction Your Staff Needs to Understand
Electronic Protected Health Information — ePHI — is simply PHI that's created, stored, transmitted, or received electronically. The PHI data definition covers both paper and electronic formats, but the Security Rule applies specifically to ePHI.
In my experience, this is where most training programs fall short. Staff learn the Privacy Rule basics but never internalize that the spreadsheet on their desktop, the text message to a colleague, and the cloud-based scheduling system all contain ePHI that demands specific technical, physical, and administrative safeguards.
If your workforce handles any electronic systems — and in 2026, that's everyone — they need to understand ePHI as a subset of the broader PHI definition. Our HIPAA Introduction Training 2026 course breaks this distinction down in practical, scenario-based modules that stick.
What Is NOT Considered PHI? Drawing the Line
This question deserves a direct answer because it's one of the most searched and most misunderstood aspects of HIPAA.
Data is NOT PHI when:
- It has been properly de-identified according to the Safe Harbor or Expert Determination methods described in HHS de-identification guidance.
- It contains health information but no identifier — for example, "a 45-year-old male presented with chest pain" with no name, date, or location attached.
- It exists outside a covered entity or business associate relationship. Your Fitbit data sitting on your personal phone is not PHI under HIPAA (though other laws may apply).
- It pertains to someone deceased for more than 50 years.
Employment records held by a covered entity in its role as an employer are also excluded, even if they contain health data. This confuses HR departments constantly. If your hospital collects a sick note from an employee, that note isn't PHI under HIPAA — it's an employment record governed by other laws.
Why the PHI Data Definition Matters More in 2026 Than Ever
Three trends are making the PHI boundary harder to manage this year.
1. AI and Analytics Tools Are Everywhere
Healthcare organizations are feeding data into machine learning models, population health dashboards, and AI-driven clinical tools. Every one of those data pipelines needs to be evaluated: does the data contain identifiers? If yes, it's PHI, and the full weight of HIPAA applies — including breach notification requirements and business associate agreements for any third-party vendor touching that data.
2. Telehealth Isn't Slowing Down
Every video visit, patient portal message, and remote monitoring reading generates ePHI. Your staff needs to know that the chat transcript from a telehealth visit carries the exact same legal protections as a paper chart in a locked filing cabinet.
3. OCR Is Enforcing Aggressively
OCR's enforcement actions have made clear that "we didn't know" is not a defense. The agency has levied penalties ranging from tens of thousands to millions of dollars, and a consistent theme in resolution agreements is inadequate workforce training on what PHI is and how to handle it.
How to Build the PHI Data Definition Into Your Compliance Program
Knowing the definition isn't enough. You need to operationalize it. Here's what I recommend to every covered entity and business associate I work with:
Map your PHI. Conduct a data inventory. Where does PHI live in your organization — EHRs, email, paper files, portable devices, cloud storage, text messages? You can't protect what you haven't found.
Train everyone, not just clinicians. Front desk staff, IT teams, billing departments, volunteers, and contractors all encounter PHI. Workforce training must reach every person who could access, transmit, or overhear protected data. Explore the full course catalog at HIPAACertify to find role-appropriate training options.
Test understanding regularly. Annual checkbox training doesn't work. Use scenario-based questions: "Is a patient's name on a sign-in sheet PHI?" (Yes.) "Is an aggregate report showing 200 patients with diabetes, with no identifiers, PHI?" (No, if properly de-identified.) These exercises reveal gaps before OCR does.
Update your risk analysis. Every new system, workflow, or vendor relationship changes your PHI landscape. Your risk analysis under the Security Rule needs to reflect current reality, not last year's infrastructure.
The Bottom Line on PHI
The PHI data definition is deceptively simple on the surface: individually identifiable health information held by a covered entity or business associate. But in practice, it's the single concept that determines whether HIPAA's full regulatory framework applies to a given piece of data — or doesn't.
Get it wrong, and you're exposed to OCR investigations, breach notification obligations, civil monetary penalties, and reputational damage that no press release can undo. Get it right, and you've built the foundation every other HIPAA safeguard rests on.
If your team can't confidently define PHI and spot it in their daily workflows, that's the gap to close first. The HIPAA Introduction Training 2026 course is built to do exactly that — quickly, clearly, and in a way your workforce will actually remember.