A hospital employee in Texas forwarded a patient's appointment confirmation to a personal email so she could "follow up from home." The email contained the patient's name, date of birth, medical record number, and diagnosis. She thought it was harmless. The resulting breach investigation cost her employer over $100,000 in corrective actions and legal fees. The root cause? Nobody on staff fully understood what PHI includes.

I've seen this pattern dozens of times. Organizations assume PHI is just medical records sitting in a filing cabinet or an EHR system. They're wrong. PHI includes a far broader set of data than most people realize, and that misunderstanding is one of the biggest drivers of preventable HIPAA violations in 2026.

What PHI Includes: The 18 Identifiers You Need to Know

Let's get specific. Under the HIPAA Privacy Rule, protected health information is any individually identifiable health information held or transmitted by a covered entity or its business associates. That covers information in any form — electronic, paper, or oral.

But here's where it gets granular. HHS defines 18 specific identifiers that, when linked to health information, make that data PHI. If any one of these is attached to a health condition, treatment, or payment record, you're dealing with PHI:

  • Names
  • Geographic data smaller than a state (street address, city, zip code)
  • Dates directly related to an individual (birth date, admission date, discharge date, date of death)
  • Phone numbers
  • Fax numbers
  • Email addresses
  • Social Security numbers
  • Medical record numbers
  • Health plan beneficiary numbers
  • Account numbers
  • Certificate/license numbers
  • Vehicle identifiers and serial numbers (including license plates)
  • Device identifiers and serial numbers
  • Web URLs
  • IP addresses
  • Biometric identifiers (fingerprints, voiceprints)
  • Full-face photographs and comparable images
  • Any other unique identifying number, characteristic, or code

That last one is the catch-all, and it's the one that trips people up the most. A tattoo description in a chart note? That could qualify. A unique patient portal username? Potentially PHI.

The Mistake That Cost Lukes-Roosevelt Hospital $387,200

In 2016, OCR settled with New York-Presbyterian Hospital for treating a film crew's access to patient areas too casually. Patients were filmed without authorization, exposing PHI through visual identifiers — faces, medical conditions visible on-screen, and bedside charts. The total settlement across related cases exceeded $2.2 million.

The staff didn't hand over medical records. They didn't email lab results. They simply let cameras roll in areas where PHI was visible. That's how broad the definition reaches.

I've consulted with organizations that were genuinely shocked to learn that a photograph of a patient's room — with a whiteboard showing their name and medication schedule — constitutes PHI. It does. Every single time.

ePHI: Where Digital Data Makes Everything Harder

Electronic protected health information (ePHI) follows the same rules but adds an entire layer of Security Rule requirements. Any PHI that's created, stored, transmitted, or received electronically is ePHI.

That includes data in your EHR, obviously. But it also includes:

  • Text messages between clinicians that mention a patient by name
  • Voicemails left on a patient's phone with test results
  • Spreadsheets on a shared drive tracking patient appointments
  • Emails with billing information that include patient identifiers
  • Data stored on medical devices like insulin pumps or pacemaker monitors

In my experience, the most dangerous ePHI lives in the places nobody thinks to look — the Excel file on a manager's desktop, the screenshot in a group chat, the backup drive nobody encrypted.

IP Addresses and Web URLs: The Identifiers Everyone Forgets

Here's one that catches even experienced compliance officers off guard. IP addresses are on the list of 18 identifiers. If your organization runs a patient portal and logs IP addresses alongside health information, that log file contains PHI.

Same goes for web URLs. If a URL contains patient-specific parameters — like a unique session ID tied to a patient's health record — that URL is PHI. Your IT team needs to understand this. Your web developers need to understand this. And your business associate agreements with hosting providers need to reflect it.

PHI vs. De-Identified Data: Where the Line Falls

Data stops being PHI when it's properly de-identified under one of two methods outlined by HHS. The Safe Harbor method requires removing all 18 identifiers and having no actual knowledge that the remaining data could identify someone. The Expert Determination method requires a qualified statistical expert to certify that re-identification risk is very small.

I've reviewed "de-identified" datasets from healthcare organizations that still contained zip codes, dates of service, and ages over 89. None of those qualify as de-identified under Safe Harbor. If you strip 17 identifiers but leave one, you still have PHI.

What Does PHI Include Under HIPAA?

PHI includes any information about a patient's past, present, or future physical or mental health condition, the provision of healthcare, or payment for healthcare — when that information is combined with one or more of the 18 identifiers listed by HHS. It applies to data in any form: written, electronic, or spoken aloud. Even a verbal conversation in a hallway where a patient's name and diagnosis are mentioned constitutes PHI under the Privacy Rule.

Oral PHI: The Risk Nobody Documents

Your organization probably has policies for handling paper records and securing electronic systems. But what about conversations?

A nurse discussing a patient's condition by name in an elevator. A receptionist confirming a diagnosis over the phone within earshot of the waiting room. A physician leaving a detailed voicemail on a patient's home phone that a family member overhears.

All of these involve PHI. The Privacy Rule doesn't limit its scope to written or electronic records. Oral disclosures count, and OCR has investigated complaints arising from overheard conversations.

In my experience, the fix here isn't silence — it's awareness. Staff need to know that PHI includes spoken information and adjust their behavior accordingly. Lower voices, use private spaces, limit details in voicemails.

Why Your Workforce Training Probably Falls Short

Here's the pattern I see over and over. An organization trains staff on HIPAA basics during onboarding. The training says "protect patient information" and moves on. Nobody drills into the 18 identifiers. Nobody explains that a license plate number linked to a patient visit log is PHI. Nobody covers oral disclosures.

Then a breach happens, and during the OCR investigation, the organization can't demonstrate that its workforce understood the scope of PHI. That's a training failure, and it's one of the most common findings in enforcement actions.

The 2018 settlement with Anthem Inc. — $16 million, the largest HIPAA settlement in history — included findings related to insufficient technical controls, but it also highlighted the importance of comprehensive workforce awareness. You can read the full resolution agreement on HHS.gov.

If your training program doesn't specifically address what PHI includes — all 18 identifiers, oral disclosures, ePHI in unexpected places — it's time to upgrade. Our HIPAA training catalog covers these exact scenarios with role-specific modules that go beyond the basics.

Business Associates and the PHI Blind Spot

Your covered entity might have a solid grasp on PHI. But what about your billing company? Your cloud storage provider? Your shredding service?

Business associates handle PHI on your behalf, and they're directly liable under the HIPAA Omnibus Rule. If your business associate doesn't understand that PHI includes device serial numbers or biometric identifiers, their ignorance becomes your risk.

I always recommend requiring business associates to complete the same caliber of workforce training your internal staff receives. A signed BAA means nothing if the people handling your data don't understand what they're protecting. Consider pointing your partners toward role-appropriate HIPAA training as part of your vendor management process.

The Audit Question That Exposes Gaps

When I conduct readiness assessments, I ask staff one simple question: "Give me five examples of PHI that aren't medical records." Most people freeze after naming date of birth and Social Security number.

If your team can't answer that question confidently, your training program has a gap. And gaps are exactly where breaches originate.

Three Steps to Lock This Down in 2026

First, audit your data inventory. Map every place PHI lives — not just your EHR, but email servers, shared drives, mobile devices, paper logs, and backup tapes. You can't protect what you haven't found.

Second, retrain with specificity. Generic "protect patient privacy" language doesn't cut it. Your workforce needs to know the 18 identifiers by heart and recognize PHI in all its forms — electronic, paper, and oral.

Third, pressure-test your business associates. Review BAAs, verify their training programs, and confirm they understand the full scope of what PHI includes. A single uninformed vendor can trigger a breach notification that lands on your desk.

PHI includes far more than most healthcare organizations realize. The organizations that take the time to learn the full scope — and train every member of their workforce accordingly — are the ones that stay off OCR's enforcement page.