A hospital billing clerk copies a spreadsheet of patient names, Social Security numbers, and diagnosis codes onto a USB drive to finish work at home. She loses the drive in a parking lot. Within weeks, the covered entity is reporting a breach to HHS, notifying every affected patient, and staring down a six-figure penalty. The twist? That single spreadsheet contained two overlapping categories of sensitive data — and the clerk didn't understand the difference between either one.
If you work in healthcare, you handle PHI PII data every single day. But most workforce members I've trained can't clearly explain where one ends and the other begins. That confusion isn't academic. It drives real compliance failures, real breaches, and real penalties from the Office for Civil Rights.
This post breaks down exactly what PHI and PII are, how they overlap, where they diverge, and what your organization must do to protect both.
PHI vs. PII: The Distinction That Keeps Getting People Fired
Let me start with the basics, because I've watched seasoned nurses, IT directors, and even compliance officers get this wrong.
PII — Personally Identifiable Information — is any data that can identify a specific individual. Think name, address, date of birth, Social Security number, driver's license number, email address, biometric data. PII is a broad concept used across industries and governed by various federal and state laws, including the Privacy Act of 1974 and the FTC Act.
PHI — Protected Health Information — is a HIPAA-specific term. PHI is individually identifiable health information that a covered entity or business associate creates, receives, maintains, or transmits. It includes medical records, lab results, prescription histories, billing records, and health plan enrollment data — but only when that information is linked to an identifier.
Here's the critical overlap: all PHI contains PII, but not all PII is PHI. A patient's name alone sitting in an HR file is PII. That same name attached to a radiology report in your EHR is PHI. Context determines classification, and classification determines which rules apply.
The 18 Identifiers That Turn Health Data Into PHI
HIPAA's Privacy Rule spells out 18 specific identifiers that make health information individually identifiable. If health data includes any one of these, you're looking at PHI:
- Names
- Geographic data smaller than a state
- All dates (except year) related to an individual
- Phone numbers
- Fax numbers
- Email addresses
- Social Security numbers
- Medical record numbers
- Health plan beneficiary numbers
- Account numbers
- Certificate/license numbers
- Vehicle identifiers and serial numbers
- Device identifiers and serial numbers
- Web URLs
- IP addresses
- Biometric identifiers
- Full-face photographs and comparable images
- Any other unique identifying number, characteristic, or code
Strip all 18 identifiers from a dataset, and you've de-identified it under the Safe Harbor method. It's no longer PHI. But leave even one — say, a date of birth next to a diagnosis — and HIPAA's full weight applies.
Why PHI PII Data Confusion Leads to Real Breaches
In my experience, the biggest compliance breakdowns happen when staff treat PHI like ordinary PII — or worse, like neither.
I've seen front desk staff email patient appointment confirmations with diagnosis codes to personal Gmail accounts. They knew the name was "private," but didn't realize the combination of name, appointment date, and treatment type created PHI subject to HIPAA's Security Rule and encryption requirements.
The consequences are well-documented. In 2018, OCR settled with Cottage Health for $3 million after ePHI for over 62,000 patients was exposed on the internet due to a failure to implement basic security measures. The data involved wasn't exotic — names, addresses, dates of birth, diagnoses, conditions, lab results, and Social Security numbers. Classic PHI PII data sitting in systems without adequate safeguards.
The lesson is stark: when your workforce doesn't understand what qualifies as PHI versus PII, they don't apply the right protections. And OCR doesn't grade on a curve.
What Does HIPAA Require for PHI That It Doesn't for PII Alone?
This is the question I get most often in training sessions, and it deserves a direct answer.
HIPAA's Requirements Apply Specifically to PHI
HIPAA's Privacy Rule governs how covered entities and business associates use and disclose PHI. The Security Rule mandates administrative, physical, and technical safeguards specifically for electronic PHI (ePHI). The Breach Notification Rule requires reporting unauthorized access to unsecured PHI to affected individuals, HHS, and in some cases the media.
None of these rules apply to PII that isn't also PHI. If your hospital's HR department mishandles an employee's Social Security number in a payroll context, that's a PII issue — potentially governed by state data breach laws or the FTC — but it's not a HIPAA violation.
Where the Lines Blur
The confusion multiplies when a single system stores both types. Your EHR contains PHI. Your HR platform contains PII. But what about a workforce health screening program administered through your benefits department? That data is often both PII and PHI, and it requires HIPAA-level protections.
I always tell clients: when in doubt, protect it like PHI. The cost of over-protecting data is zero. The cost of under-protecting it can be catastrophic.
The $2.3 Million Wake-Up Call for Inadequate Workforce Training
In 2016, OCR imposed a $3.9 million penalty on Feinstein Institute for Medical Research after a laptop containing ePHI of approximately 13,000 patients and research participants was stolen from an employee's car. Among OCR's findings: insufficient security management processes, a lack of policies governing portable devices, and inadequate workforce training.
That last finding matters here. When your staff can't distinguish between PHI PII data types, they make bad decisions about what to encrypt, where to store files, and how to transmit information. Training isn't a checkbox — it's the mechanism that prevents your team from becoming your biggest vulnerability.
If your nursing staff needs role-specific guidance, our HIPAA training course for nurses and clinical workflow covers exactly how PHI moves through clinical environments and where the risks concentrate.
Five Actions to Protect PHI and PII in Your Organization
Here's what I recommend to every covered entity I work with:
1. Classify Your Data Before You Secure It
You can't protect what you haven't categorized. Map every system, application, and workflow that touches individually identifiable information. Label it PHI, PII, or both. Then apply protections accordingly.
2. Encrypt ePHI Everywhere — No Exceptions
Encryption is an addressable specification under the Security Rule, but "addressable" doesn't mean optional. If you choose not to encrypt, you must document an equivalent alternative measure. In practice, just encrypt. It's 2026 — there's no defensible reason not to.
3. Train Your Workforce on Data Types, Not Just Policies
Most HIPAA training programs teach rules. The best ones teach recognition. Your staff should be able to look at a spreadsheet, an email, or a chart and immediately identify whether it contains PHI, PII, or both — and know what protections each requires. Explore our full HIPAA training catalog for role-specific courses that build this exact competency.
4. Implement Minimum Necessary Standards
The Privacy Rule's minimum necessary standard requires covered entities to limit PHI access to only what's needed for a specific task. This applies to internal uses, disclosures to business associates, and routine requests. Review your access controls quarterly.
5. Prepare for Breach Notification — for Both Data Types
A PHI breach triggers HIPAA's Breach Notification Rule, which requires notification to affected individuals within 60 days, a report to HHS, and for breaches affecting 500 or more individuals, media notification. A PII-only breach may trigger state notification laws. Your incident response plan should address both scenarios with specific playbooks.
Quick Reference: PHI vs. PII at a Glance
- PII: Any data that identifies an individual. Governed by various federal/state laws. Applies across all industries.
- PHI: Health information linked to an identifier, held by a covered entity or business associate. Governed specifically by HIPAA. Applies to healthcare.
- ePHI: PHI in electronic form. Subject to HIPAA's Security Rule, which mandates specific technical, physical, and administrative safeguards.
- Overlap: PHI always contains PII elements. Protecting PHI means protecting the PII within it — but PII outside a healthcare context requires its own protections.
Stop Treating These Terms as Interchangeable
Every time I hear someone say "PHI and PII are basically the same thing," I know that organization has a gap. These terms describe different legal categories with different regulatory consequences. Treating them as synonyms leads to misapplied safeguards, incomplete risk analyses, and the kind of sloppy data handling that lands organizations on OCR's Breach Portal.
Your workforce doesn't need a law degree. They need clear, practical training that shows them exactly what PHI PII data looks like in their daily work — and what to do when they encounter it. That's the difference between a compliant organization and a cautionary tale.