A $4.3 Million Mistake That Started With a Spreadsheet

In 2016, the University of Texas MD Anderson Cancer Center lost an unencrypted USB drive containing patient names, diagnoses, and treatment records. OCR investigated and levied a $4.3 million penalty. The data on that thumb drive was both PHI and PII — but the penalty came because MD Anderson failed to protect it as PHI under HIPAA.

That distinction — between PHI and PII — is something I watch organizations get wrong almost every week. They treat the terms as interchangeable. They're not. And the confusion creates real compliance gaps that cost real money.

If you've ever stared at a privacy policy trying to figure out whether a data element is PHI, PII, or both, this breakdown will save you hours and potentially thousands of dollars. Understanding PHI PII differences isn't academic — it determines which laws apply, who enforces them, and what happens when something goes wrong.

What Is PII? The Broader Bucket

PII — Personally Identifiable Information — is any data that can identify a specific individual. Think Social Security numbers, email addresses, driver's license numbers, biometric data, even IP addresses in some contexts.

PII is a concept that spans multiple regulatory frameworks. NIST defines it. The FTC enforces against its misuse. State privacy laws like the California Consumer Privacy Act regulate it. There's no single federal PII law — instead, a patchwork of regulations covers different sectors.

Common PII Data Elements

  • Full name
  • Social Security number
  • Date of birth
  • Home address
  • Phone number
  • Email address
  • Financial account numbers
  • Biometric identifiers (fingerprints, facial recognition data)

Here's the key point: PII exists everywhere. Your HR department has it. Your marketing team collects it. Your IT help desk logs it. PII is not limited to healthcare.

What Is PHI? PII's Healthcare-Specific Cousin

PHI — Protected Health Information — is a HIPAA-specific term. It refers to individually identifiable health information that is created, received, maintained, or transmitted by a covered entity or business associate.

For data to qualify as PHI, it needs two ingredients:

  • An identifier — a name, address, date of birth, or any of HIPAA's 18 identifiers
  • A healthcare connection — the data relates to a person's past, present, or future health condition, treatment, or payment for care

A name on a grocery store loyalty card is PII. That same name attached to a prescription fill record at a pharmacy is PHI. Context is everything.

HIPAA's 18 Identifiers

The HHS de-identification guidance lists 18 specific identifiers that, when paired with health data, create PHI. These include names, geographic data smaller than a state, dates (except year) related to an individual, phone numbers, fax numbers, email addresses, Social Security numbers, medical record numbers, health plan beneficiary numbers, account numbers, certificate/license numbers, vehicle identifiers, device identifiers, web URLs, IP addresses, biometric identifiers, full-face photographs, and any other unique identifying number.

Remove all 18 identifiers using HIPAA's Safe Harbor method, and the data is considered de-identified — no longer PHI, no longer subject to the Privacy Rule.

PHI PII: Where They Overlap and Where They Don't

This is where I see the most confusion in the field. Here's the simplest way I explain it to the compliance teams I work with:

All PHI contains PII, but not all PII is PHI.

A patient's name and diagnosis? That's both PII and PHI. A patient's name on a hospital parking garage receipt with no health data attached? That's PII only. An employee's Social Security number in a payroll system? PII, but not PHI — unless that employee is also a patient and the SSN is linked to treatment records in a clinical system.

Why the Distinction Matters for Your Organization

Different data types trigger different legal obligations. If you're a covered entity or business associate handling PHI, you answer to the HIPAA Privacy Rule, the Security Rule, and the Breach Notification Rule — all enforced by OCR at HHS. Mishandle PII that isn't PHI, and you might face action from the FTC, state attorneys general, or sector-specific regulators — but not OCR.

I've seen organizations waste months building HIPAA compliance programs around data that was never PHI in the first place. I've also seen the opposite — healthcare organizations treating PHI as "just PII" and failing to apply the safeguards HIPAA demands. Both mistakes are expensive.

The $2.1 Million Wake-Up Call for Misclassifying Data

Sentara Hospitals discovered this the hard way. In 2019, Sentara mailed billing statements containing patient diagnoses to wrong addresses. When patients complained to OCR, Sentara initially argued the mailings weren't reportable breaches. OCR disagreed — the data was PHI, the mailing was an impermissible disclosure, and the failure to report it as a breach compounded the violation. The result: a $2.175 million settlement.

Sentara's mistake was partly a classification problem. They underestimated what counted as PHI. Your organization can't afford to make the same error.

How Does ePHI Fit Into This?

ePHI is simply PHI in electronic form. The HIPAA Security Rule applies specifically to ePHI and requires administrative, physical, and technical safeguards — encryption, access controls, audit logs, and more.

Every piece of ePHI is also electronic PII. But the Security Rule's requirements go far beyond what most PII frameworks demand. If your team thinks general cybersecurity hygiene is enough for ePHI, they're wrong. HIPAA's Security Rule mandates a formal risk analysis, documented policies, workforce training, and ongoing evaluation.

What Does HIPAA Require That PII Frameworks Don't?

Breach Notification With a 60-Day Clock

Under HIPAA's Breach Notification Rule, covered entities must notify affected individuals within 60 days of discovering a breach of unsecured PHI. Breaches affecting 500 or more individuals also require notification to OCR and prominent media outlets. Most PII frameworks don't impose this kind of structured, time-bound obligation.

Business Associate Agreements

If a vendor touches your PHI, you need a Business Associate Agreement. Period. PII frameworks rarely require this level of contractual control over downstream data handlers.

Minimum Necessary Standard

HIPAA's Privacy Rule says you should only use, disclose, or request the minimum amount of PHI needed for the task. This standard doesn't exist in most PII regulations.

Training Your Workforce to Tell the Difference

Here's what happens in the real world: a front-desk employee at a medical practice emails a patient's name and appointment time to the wrong person. Is that a HIPAA breach? It depends — is the appointment time linked to health information?

Your staff needs to understand these distinctions at a practical level. Not in abstract policy language, but in the context of their actual daily workflows. That's why I recommend role-specific training programs like our HIPAA training for nurses and clinical workflows, which addresses real scenarios involving both PHI and PII in clinical settings.

Workforce training isn't a one-and-done checkbox. OCR has cited insufficient training as a contributing factor in multiple enforcement actions. Your entire team — from billing to IT to clinical staff — needs to know what PHI PII distinctions look like in their specific roles.

Build a Classification Habit

I tell every organization I work with to implement a simple data classification step: before storing, sharing, or transmitting any personal data, ask two questions.

  • Can this data identify a specific person? (If yes, it's PII.)
  • Is it connected to health conditions, treatment, or payment for care — and is it held by or on behalf of a covered entity? (If yes, it's PHI.)

That two-question test takes five seconds. It can prevent a six-figure fine.

Quick Reference: PHI vs PII at a Glance

  • PII: Any data identifying an individual. Governed by NIST guidance, FTC Act, state laws. Applies across all sectors.
  • PHI: Individually identifiable health information held by covered entities or business associates. Governed by HIPAA. Enforced by OCR.
  • ePHI: PHI in electronic form. Subject to HIPAA Security Rule's technical safeguards.
  • Overlap: PHI always contains PII. PII is only PHI when it includes health data in a HIPAA-covered context.

What Should You Do Next?

Start with a data inventory. Identify every system, spreadsheet, and shared drive where your organization stores personal data. Classify each data element: is it PII only, or is it PHI? Document your findings and update your risk analysis accordingly.

Then invest in workforce training that reflects these distinctions. Browse our full catalog of HIPAA training courses to find programs tailored to your team's roles and responsibilities.

The line between PHI and PII isn't always obvious. But in my experience, the organizations that draw it clearly — and train their people to respect it — are the ones that avoid the call from OCR.