A front-desk employee at a pediatric clinic in Texas mentioned a patient's diagnosis to the child's school counselor over the phone. She thought she was helping. That single phone call triggered a breach report, an OCR investigation, and a $75,000 settlement. The information she shared — a child's name linked to a behavioral health condition — was PHI protected health information, and she never realized it.

I've seen this pattern hundreds of times. The problem isn't malice. It's a fundamental misunderstanding of what PHI actually is, where its boundaries sit, and how easily your workforce can cross them without training.

This post breaks down exactly what qualifies as PHI protected health information, what falls outside the definition, and the real-world consequences organizations face when they get it wrong.

What Is PHI Protected Health Information, Exactly?

PHI is any individually identifiable health information that a covered entity or business associate creates, receives, maintains, or transmits. That's the textbook answer from HHS's Privacy Rule guidance. But here's where it gets practical.

Three elements must be present for information to qualify as PHI:

  • It relates to health. A past, present, or future physical or mental health condition, provision of healthcare, or payment for healthcare.
  • It identifies an individual. The information either names the person or includes enough detail that someone could reasonably identify them.
  • It's held or transmitted by a covered entity or business associate. The same data in a personal diary isn't PHI. In your EHR system, it is.

All three must overlap. Remove one, and the data may fall outside the HIPAA Privacy Rule's reach. But in a clinical or administrative setting, that overlap happens constantly — often in ways your staff doesn't recognize.

The 18 Identifiers That Make Health Data PHI

HHS defines 18 specific identifiers that, when combined with health information, create PHI. Your team should know these cold:

  • Names
  • Geographic data smaller than a state
  • All dates (except year) related to the individual — birth dates, admission dates, discharge dates, date of death
  • Phone numbers
  • Fax numbers
  • Email addresses
  • Social Security numbers
  • Medical record numbers
  • Health plan beneficiary numbers
  • Account numbers
  • Certificate or license numbers
  • Vehicle identifiers and serial numbers
  • Device identifiers and serial numbers
  • Web URLs
  • IP addresses
  • Biometric identifiers (fingerprints, voiceprints)
  • Full-face photographs and comparable images
  • Any other unique identifying number, characteristic, or code

Strip all 18 from a dataset, and you have de-identified information — no longer PHI under the Safe Harbor method. Leave even one attached to a health condition, and you're in HIPAA territory.

The Mistakes I See Most Often — And They're Not Technical

When people hear "PHI breach," they picture hackers. In my experience, the most common PHI violations involve voices, not servers.

A nurse discussing a patient's medication in an elevator. A billing specialist confirming an appointment over the phone to someone who isn't the patient. A therapist leaving a voicemail that reveals a diagnosis. These are all PHI disclosures, and they happen every day in covered entities across the country.

That's why I recommend every organization invest in targeted training like Verbal Disclosures: Watch What You Say. It covers the exact scenarios where staff unknowingly share PHI protected health information in conversation — and how to stop it.

ePHI: PHI's Digital Twin

Electronic protected health information — ePHI — carries the same definition as PHI but lives in digital form. Your EHR, email system, patient portal, cloud backups, even text messages between clinicians — all potential ePHI containers.

The HIPAA Security Rule applies specifically to ePHI and demands administrative, physical, and technical safeguards. If your organization transmits or stores health information electronically (and in 2026, that's every organization), the Security Rule isn't optional. It's the baseline.

The $5.1 Million Lesson From a Health System That Didn't Train Its Workforce

In 2017, Memorial Healthcare System paid $5.1 million to settle with OCR after employees accessed the ePHI of 115,143 individuals without authorization. The employees used login credentials belonging to a former worker at an affiliated physician's office. HHS found that Memorial lacked proper access controls and failed to regularly review information system activity — both Security Rule requirements.

The settlement wasn't just about technology gaps. It was about workforce awareness. Employees accessed records they had no treatment, payment, or operations reason to view. A culture of PHI awareness — built through consistent training — would have flagged this behavior far earlier.

I've seen smaller organizations assume these enforcement actions only hit large health systems. They don't. OCR has settled with solo practices, dental offices, and small behavioral health providers. The OCR resolution agreements page makes that clear.

Does PHI Include Mental and Behavioral Health Records?

Yes — and mental health records often carry additional protections. Psychotherapy notes, for instance, receive a higher level of protection under the Privacy Rule. A covered entity generally cannot disclose psychotherapy notes without the individual's specific authorization, even for treatment, payment, or healthcare operations purposes.

This distinction trips up a lot of organizations. Standard PHI rules apply to a diagnosis of depression in a medical chart. But a therapist's private session notes? Those are psychotherapy notes, and the rules are stricter.

If your practice touches mental or behavioral health, your workforce needs specialty-specific training. I point organizations to HIPAA Training for Mental & Behavioral Health because the nuances in this space — 42 CFR Part 2 for substance use disorder records, state-level consent laws, psychotherapy note carve-outs — are too important for a generic HIPAA overview.

What Doesn't Count as PHI? The Boundaries Matter

Not everything health-related is PHI. Understanding the boundaries prevents both over-restriction and under-protection.

Data That Falls Outside PHI

  • De-identified data. Health data stripped of all 18 identifiers (or certified by a statistician under the Expert Determination method) is not PHI.
  • Employment records. Health information in an employment record held by a covered entity in its role as employer — such as a sick note in an HR file — is generally not PHI under HIPAA.
  • Education records. Health data covered by FERPA (the Family Educational Rights and Privacy Act) is excluded from HIPAA's definition of PHI.
  • Data held by non-covered entities. Your fitness tracker company, a wellness app that isn't connected to a covered entity — they may hold health data, but it's not PHI under HIPAA. (The FTC's Health Breach Notification Rule may apply instead.)

These distinctions aren't academic. I've watched compliance officers lock down employee HR files under HIPAA when those records weren't PHI to begin with. Misclassification wastes resources and creates confusion about where real PHI risks live.

How to Protect PHI Across Your Organization

Knowing the definition isn't enough. Your organization needs operational controls that reflect how PHI actually moves through your workflows.

Five Steps That Actually Work

  • Map your PHI flows. Document where PHI enters, moves through, and exits your organization. Include paper, digital, and verbal channels.
  • Apply minimum necessary. Workforce members should access only the PHI they need for their specific job function. Not more.
  • Train role by role. A front-desk employee faces different PHI risks than a billing specialist or a clinician. Tailor your training accordingly — explore the full course catalog for role-specific options.
  • Encrypt ePHI in transit and at rest. Full-disk encryption on workstations, TLS for email, encrypted messaging for clinical communication.
  • Audit access logs monthly. Don't wait for a breach report. Proactive log reviews catch unauthorized access before it becomes a headline.

Breach Notification: What Happens When PHI Gets Out

When PHI is accessed, used, or disclosed in a way the Privacy Rule doesn't permit, it's presumed to be a breach unless you can demonstrate a low probability of compromise through a four-factor risk assessment.

If it qualifies as a breach, the clock starts ticking:

  • Notify affected individuals within 60 days of discovery.
  • Notify HHS — immediately for breaches affecting 500+ individuals, or annually for smaller breaches.
  • Notify prominent media outlets if the breach affects 500+ residents of a single state or jurisdiction.

I've seen organizations delay notification because they "weren't sure" the data qualified as PHI. That uncertainty itself is the problem. If your workforce can't identify PHI protected health information on sight, your breach response will always lag behind the threat.

PHI Isn't a Technicality — It's the Core of HIPAA

Every safeguard in the Privacy Rule, every control in the Security Rule, every notification requirement in the Breach Notification Rule — they all exist to protect PHI. If your team can't define it, spot it, and handle it correctly, nothing else in your compliance program matters.

Start with the fundamentals. Make sure every workforce member — from the CEO to the part-time receptionist — can answer one question: "Is this PHI?" Get that right, and the rest of your compliance program has a foundation to stand on.