A dermatology practice in New England thought appointment reminder postcards were harmless. They listed the patient's name, the date of their next visit, and the words "follow-up for skin biopsy results." That postcard — readable by any mail carrier, roommate, or nosy neighbor — was an impermissible disclosure of PHI. The practice learned this the hard way, after a patient complaint triggered an OCR investigation. Understanding PHI meaning isn't academic trivia. It's the difference between a compliant operation and a six-figure penalty.
If you've ever asked "what exactly counts as PHI?" you're not alone. I've consulted with hospitals, solo practitioners, and SaaS companies who all had a different — and often wrong — answer. Let's fix that right now.
PHI Meaning Under HIPAA: The Actual Definition
PHI stands for Protected Health Information. Under the HIPAA Privacy Rule, PHI is any information that relates to the past, present, or future physical or mental health of an individual, the provision of healthcare to that individual, or payment for healthcare — and that identifies the individual or could reasonably be used to identify them.
That second part is the one people miss. A diagnosis alone isn't PHI. A name alone isn't PHI. But combine a diagnosis with a name, a date of birth, or even a zip code, and you've got PHI. The definition lives in 45 CFR §160.103, and it's broader than most people expect.
The Three-Part Test I Use With Clients
When I'm training a new workforce, I boil PHI meaning down to three questions:
- Does it relate to health, healthcare, or payment for healthcare? This includes diagnoses, treatment plans, lab results, insurance claims, even billing codes.
- Does it identify — or could it identify — a specific person? Names, Social Security numbers, medical record numbers, email addresses, and even full-face photographs all count as identifiers under HIPAA.
- Is it held or transmitted by a covered entity or business associate? A covered entity includes health plans, healthcare clearinghouses, and most healthcare providers. Their vendors — business associates — are bound by the same rules.
If all three answers are yes, you're looking at PHI. Period.
The 18 Identifiers That Turn Health Data Into PHI
HHS spells out 18 specific identifiers that make health information "individually identifiable." Here they are:
- Names
- Geographic data smaller than a state
- All dates (except year) related to an individual — birth date, admission date, discharge date, date of death
- Phone numbers
- Fax numbers
- Email addresses
- Social Security numbers
- Medical record numbers
- Health plan beneficiary numbers
- Account numbers
- Certificate/license numbers
- Vehicle identifiers and serial numbers
- Device identifiers and serial numbers
- Web URLs
- IP addresses
- Biometric identifiers (fingerprints, voiceprints)
- Full-face photographs and comparable images
- Any other unique identifying number, characteristic, or code
That last one is a catch-all, and it's intentional. If your organization strips the first 17 identifiers but leaves a unique patient portal username that maps back to a person, you still have PHI.
ePHI: When PHI Goes Digital, the Stakes Go Up
Electronic Protected Health Information — ePHI — is PHI that's created, stored, transmitted, or received in electronic form. Think EHR records, emailed lab results, text messages about a patient, data sitting on a cloud server, or even a voicemail stored digitally.
The HIPAA Security Rule applies specifically to ePHI and requires covered entities and business associates to implement administrative, physical, and technical safeguards. In my experience, most breaches reported to OCR involve ePHI — lost laptops, misconfigured databases, phishing attacks that expose thousands of records at once.
A $1.5 Million Reminder About Unencrypted ePHI
In 2018, OCR settled with Filefax, Inc. for the improper disposal of patient records. But larger penalties have hit organizations that failed to protect ePHI in transit. The University of Texas MD Anderson Cancer Center fought a $4.3 million penalty related to unencrypted devices containing ePHI — a case that wound through the courts and reshaped how organizations approach encryption mandates. When people ask me what PHI meaning looks like in dollar terms, I point to cases like these.
What Doesn't Count as PHI (And Why People Get Confused)
Not every piece of health-related data is PHI. Here's where confusion creeps in:
- De-identified data: If you strip all 18 identifiers using the Safe Harbor method (or have a statistician certify re-identification risk is very small under the Expert Determination method), the data is no longer PHI under HIPAA.
- Employment records: Health information in employment records held by a covered entity in its role as an employer is generally not treated as PHI under the Privacy Rule.
- Data held by non-covered entities: Your fitness app tracking your heart rate? Not PHI — unless the app is a business associate of a covered entity. This is a gap that confuses consumers and providers alike.
I've seen compliance officers over-classify data, locking down information that doesn't meet the PHI definition and creating workflow bottlenecks. I've also seen them under-classify, leaving real PHI exposed in shared drives. Both extremes cost time, money, and trust.
Why Getting PHI Meaning Wrong Leads to Real Breaches
Most HIPAA breaches I've investigated didn't start with a hacker. They started with someone who didn't understand what PHI is. A receptionist who texted a patient's appointment details to the wrong number. A billing clerk who emailed a spreadsheet of claim data to a personal Gmail account. A well-meaning nurse who posted a patient success story on social media with just enough detail to identify the individual.
OCR's enforcement actions page is a graveyard of organizations that made exactly these mistakes. The breach notification requirements under HIPAA kick in whenever unsecured PHI is accessed, used, or disclosed in a way not permitted by the Privacy Rule. And once you notify HHS of a breach affecting 500 or more individuals, your organization's name goes on a public list — sometimes called the "Wall of Shame."
What Qualifies as a PHI Breach?
A breach is the acquisition, access, use, or disclosure of PHI in a manner not permitted by the Privacy Rule that compromises the security or privacy of the PHI. Under the Breach Notification Rule, you must presume a breach occurred unless you can demonstrate — through a four-factor risk assessment — that there's a low probability the PHI was actually compromised. Your organization carries the burden of proof, not the patient.
How to Train Your Workforce on PHI Meaning (Without Boring Them)
Here's what I tell every compliance officer I work with: your staff doesn't need to memorize 45 CFR. They need to recognize PHI when it's in front of them — on a screen, in a conversation, on a fax cover sheet.
Effective workforce training covers three things:
- Recognition: Can your front-desk staff identify the 18 identifiers? Do they know that a patient's email address combined with a prescription refill note is PHI?
- Handling: Do your employees know the minimum necessary standard — that they should access only the PHI they need to do their job?
- Reporting: Does every member of your workforce know how to report a suspected breach internally, and how fast they need to do it?
If you're looking for a structured program that covers all of this, our HIPAA Introduction Training for 2026 walks through PHI identification, handling requirements, and breach response — built specifically for workforce members who need practical knowledge, not legal theory.
PHI in 2026: New Risks Your Organization Should Watch
The definition of PHI hasn't changed, but the attack surface has. Telehealth platforms, AI-powered clinical tools, remote workforce devices, and cloud-based EHR systems all create new vectors for PHI exposure. OCR has signaled increased scrutiny on tracking technologies — like website pixels and analytics tools — that may capture PHI without patient authorization.
If your organization uses any online scheduling tool, patient portal, or digital intake form, you need to confirm that PHI isn't being inadvertently shared with third-party analytics or advertising platforms. The penalties for getting this wrong are not theoretical — OCR has already pursued enforcement actions in this space.
Stay Ahead With the Right Training
Compliance isn't a one-time event. Regulations evolve, risks shift, and your workforce turns over. Browse our full HIPAA training catalog to find courses that match your organization's size, risk profile, and compliance needs.
The Bottom Line on PHI Meaning
PHI is any individually identifiable health information held by a covered entity or business associate. It includes 18 categories of identifiers and covers data in any form — paper, electronic, or oral. Misunderstanding PHI meaning is the root cause of the majority of preventable HIPAA violations I've seen in two decades of consulting.
Your organization doesn't need perfect compliance. It needs a workforce that can look at a piece of data and answer one question correctly: "Is this PHI?" Get that right, and everything else — access controls, breach notification, business associate agreements — falls into place.