A Spreadsheet That Cost $6.85 Million
In 2018, Premera Blue Cross agreed to pay $6.85 million to the Office for Civil Rights after a breach exposed the PHI data of over 10.4 million individuals. The root cause? A phishing email that gave attackers access to systems containing names, Social Security numbers, dates of birth, clinical information, and financial data. Every single item on that list qualified as protected health information under HIPAA.
I've spent years helping covered entities and business associates understand a deceptively simple question: what exactly is PHI data, and when does mishandling it cross the line from a policy gap into a federal enforcement action?
If you're reading this, you probably handle health information in some capacity — and you need a precise, practical understanding of what HIPAA actually protects. Not the textbook version. The version that keeps your organization out of an OCR corrective action plan.
What Qualifies as PHI Data Under HIPAA
Protected health information — PHI — is any individually identifiable health information that a covered entity or business associate creates, receives, maintains, or transmits. That's the legal definition from 45 CFR Part 160. But let me break it into something you can actually use.
PHI data exists when two things collide: a piece of health information and an identifier that links it to a specific person. A diagnosis code sitting alone in an anonymous dataset? Not PHI. That same diagnosis code attached to a patient name, medical record number, or email address? That's PHI, and HIPAA's full regulatory weight applies.
The 18 Identifiers You Must Know
HHS defines 18 specific identifiers that, when combined with health information, create PHI. Here are the ones I see most often tripping up organizations:
- Names — first, last, or any combination
- Dates — birth dates, admission dates, discharge dates, dates of death
- Phone and fax numbers
- Email addresses
- Social Security numbers
- Medical record numbers
- Health plan beneficiary numbers
- Device identifiers and serial numbers
- Full-face photographs and comparable images
- Any other unique identifying number, characteristic, or code
That last bullet is the catch-all, and it's the one that bites hardest. Internal patient IDs, barcodes on wristbands, even unique URLs tied to a patient portal — all of these can qualify.
ePHI: Where Most Breaches Actually Happen
When PHI data lives in electronic form — on a server, in an EHR, inside an email, on a laptop — it becomes electronic protected health information (ePHI). And this is where the overwhelming majority of enforcement actions originate.
The HIPAA Security Rule applies specifically to ePHI. It requires administrative, physical, and technical safeguards. Miss any one of these, and you've created the exact gap attackers exploit.
In my experience, the most common ePHI failures look like this:
- Unencrypted laptops containing patient records left in cars or at home offices
- Staff emailing patient lists through personal Gmail accounts
- Cloud storage folders with wide-open access permissions
- Legacy systems running unpatched software
Every single one of these is preventable. Every single one has led to real OCR settlements.
The Anthem Breach: $16 Million and a Wake-Up Call
Anthem Inc. paid $16 million to OCR in 2018 — the largest HIPAA settlement in history at the time — after a cyber attack compromised the ePHI of nearly 79 million people. OCR's investigation found that Anthem failed to conduct an enterprise-wide risk analysis, had insufficient access controls, and lacked adequate monitoring. The PHI data exposed included names, dates of birth, Social Security numbers, and health plan IDs.
That $16 million wasn't a fine for getting hacked. It was a fine for failing to have the safeguards that would have prevented or mitigated the hack.
What Doesn't Count as PHI Data
This question comes up in almost every training session I lead. Here's the bright line.
De-identified data is not PHI. If you strip all 18 identifiers from a health dataset using the Safe Harbor method — or have a qualified statistician certify that the risk of re-identification is very small using the Expert Determination method — the result is no longer PHI under HIPAA.
Employment records held by a covered entity in its role as an employer are not PHI. If you run a hospital and your HR department has employee sick leave records, those records aren't covered by HIPAA — they're covered by other laws like FMLA and ADA, but not the Privacy Rule.
Education records covered by FERPA are not PHI. A university health clinic's treatment records for students typically fall under FERPA, not HIPAA, because the educational institution is the custodian.
Getting these distinctions wrong leads to two problems: either you over-protect data and create workflow bottlenecks, or you under-protect actual PHI and expose your organization to enforcement risk.
How OCR Decides to Investigate Your PHI Data Practices
OCR doesn't investigate every complaint. But here's what I've seen trigger the deepest scrutiny:
- Breach reports involving 500+ individuals. These are posted publicly on the HHS Breach Portal — often called the "Wall of Shame" — and they virtually guarantee an OCR investigation.
- Complaints filed by patients or employees. A single disgruntled employee who reports that PHI data was left on a shared desktop can trigger a compliance review.
- Patterns of smaller breaches. Three or four breaches involving fewer than 500 records each still get aggregated and reviewed annually.
Once OCR opens an investigation, they ask for your risk analysis, your policies, your training records, and your breach notification documentation. If any of those are missing or outdated, the settlement amount climbs fast.
The Workforce Training Gap That Keeps Showing Up
Here's a pattern I've seen at least a dozen times: an organization has solid technical safeguards — encryption, firewalls, access controls — but their workforce training is nonexistent or last happened in 2021. OCR treats this as a systemic failure.
HIPAA requires that every member of a covered entity's workforce receive training on the organization's privacy and security policies. Not once. Not at onboarding. On an ongoing, regular basis. And the training has to be specific to each role's actual contact with PHI data.
A nurse handling patient intake forms faces different PHI data risks than a billing specialist processing claims. Generic, one-size-fits-all training doesn't satisfy the standard — and it doesn't change behavior. That's why role-specific programs like HIPAA training built for nurses and clinical workflows exist. They map compliance requirements to the exact situations your clinical staff encounters every shift.
If your organization hasn't refreshed its workforce training program recently, explore updated HIPAA training courses that reflect current enforcement trends and regulatory expectations.
What Happens When You Get Breach Notification Wrong
The Breach Notification Rule requires covered entities to notify affected individuals, HHS, and in some cases the media, when unsecured PHI is compromised. "Unsecured" means the PHI data wasn't rendered unusable through encryption or destruction.
Timing matters enormously. You have 60 calendar days from the date of discovery — not the date of the breach itself, but the date you knew or should have known about it. Miss that window, and you face a separate violation on top of whatever caused the breach in the first place.
I've seen organizations delay notification because they were still investigating. OCR has been clear: investigation can continue after notification. Waiting too long is never the right call.
Five Steps to Lock Down Your PHI Data Right Now
You don't need a six-month initiative to improve your posture. Start here:
- Run a current risk analysis. Not the one from 2023. A new one that reflects your current systems, workforce, and data flows.
- Audit access controls. Who can see PHI data in your systems right now? If the answer is "more people than need to," fix it this week.
- Encrypt everything at rest and in transit. Full-disk encryption on every device. TLS on every email that carries PHI.
- Document your training. Date, attendee name, topics covered, acknowledgment signature. OCR asks for this in every investigation.
- Test your breach response plan. Run a tabletop exercise. Find out where the plan breaks before a real incident does.
The Bottom Line on PHI Data
PHI data isn't an abstract compliance concept. It's the specific, identifiable health information your organization touches every day — and it's the exact thing OCR measures you against when something goes wrong.
The organizations that avoid seven-figure settlements aren't the ones that never get breached. They're the ones that can show OCR a documented risk analysis, current training records, reasonable safeguards, and a tested incident response plan. That's the difference between a breach that gets resolved and a breach that becomes a headline.
Your patients trust you with their most sensitive information. Protect it like it matters — because to OCR, and to the people whose data you hold, it does.