A Receptionist, a Waiting Room, and a $125,000 Fine

A front desk employee at a medical clinic called out a patient's full name and the name of the specialist they were there to see — in a packed waiting room. Someone recorded it. A complaint landed at HHS. What followed was an OCR investigation, a corrective action plan, and a settlement that could have been avoided if the staff understood one thing: what counts as protected health information.

That's the gap I see over and over. Healthcare organizations train their teams on HIPAA in the abstract, but when I ask staff to list specific protected health information examples, most can only name two or three. They miss the ones that actually get them in trouble.

This post gives you concrete, real-world examples of PHI — the kind your workforce encounters every shift. Not theory. Not legalese. Just the information you need to keep your organization off the OCR's enforcement page.

What Exactly Qualifies as Protected Health Information?

PHI is any individually identifiable health information that a covered entity or business associate creates, receives, maintains, or transmits. The key phrase is individually identifiable. A diagnosis by itself isn't PHI. A diagnosis linked to a person's name, date of birth, or medical record number is.

The HIPAA Privacy Rule, codified at 45 CFR §160.103, defines PHI broadly. It covers information in any form — paper, electronic (ePHI), or spoken aloud. That last one catches people off guard. A verbal conversation in a hallway is just as regulated as a record in your EHR.

18 Identifiers: The Protected Health Information Examples That Matter Most

HHS defines 18 specific identifiers that, when combined with health data, create PHI. Here's the full list with the real-world context your team needs:

The Ones Everyone Knows

  • Names — Patient names on intake forms, prescription labels, appointment reminders.
  • Dates — Birth dates, admission dates, discharge dates, dates of death. Any date directly related to an individual (except year alone for patients over 89).
  • Phone numbers — Home, cell, work. This includes numbers stored in staff personal devices.
  • Social Security numbers — Still collected by many billing departments, and still one of the most damaging identifiers in a breach.

The Ones That Trip People Up

  • Email addresses — That patient email in your scheduling system? PHI. Sending unencrypted appointment details to it? A potential breach.
  • Medical record numbers — Unique to each patient. Even without a name attached, this identifier alone can link back to an individual.
  • Health plan beneficiary numbers — Insurance ID numbers fall squarely in this category.
  • Geographic data smaller than a state — Street addresses, ZIP codes (first three digits are okay only if the ZIP covers more than 20,000 people), city names.
  • Account numbers — Billing account numbers used by your practice or hospital.
  • Certificate or license numbers — Driver's license, professional license, any government-issued number tied to the patient.

The Ones Almost Everyone Forgets

  • Device identifiers and serial numbers — An implanted pacemaker's serial number linked to a patient record? PHI.
  • Vehicle identifiers — License plate numbers captured by hospital parking systems and linked to patient visits.
  • Web URLs — A patient portal URL that contains identifiable query strings.
  • IP addresses — Logged by telehealth platforms and patient portals. Often overlooked in breach risk assessments.
  • Biometric identifiers — Fingerprints, voiceprints, retinal scans used for facility access tied to patient records.
  • Full-face photographs — Clinical photos, ID badge photos, any image that could identify a patient.
  • Any other unique identifying number or code — This catch-all covers anything else that could reasonably identify an individual.

If any of these identifiers are linked to information about a person's past, present, or future health condition, treatment, or payment for care — you're looking at PHI.

The Examples Your Staff Encounters Before Lunch

Let me walk you through what a typical morning looks like in terms of PHI exposure:

8:05 AM: A medical assistant pulls up tomorrow's schedule to confirm appointments. That screen shows patient names, phone numbers, and appointment reasons. Every field is PHI.

8:30 AM: A therapist discusses a client's treatment plan with a colleague in a break room. Two other staff members overhear the client's name and diagnosis. That verbal exchange is PHI — and it's one of the most common violations I've seen. Our course on Verbal Disclosures: Watch What You Say was built specifically for this scenario.

9:15 AM: A billing specialist emails a claim with a patient's name, date of birth, and diagnosis code to a clearinghouse. That email contains ePHI. If it's unencrypted, your organization just created a risk event.

10:00 AM: A front desk coordinator leaves a voicemail for a patient, mentioning their prescription refill by name. PHI, transmitted verbally, to a device that might be shared with family members.

Every one of these protected health information examples happens in real clinics, every day. And every one of them can trigger an OCR complaint if mishandled.

What Doesn't Count as PHI (and Why the Distinction Matters)

Not everything in a medical setting is PHI. Understanding the boundary is just as critical as knowing the examples.

  • De-identified data — If all 18 identifiers are removed and there's no reasonable basis to re-identify the individual, it's no longer PHI under the Privacy Rule.
  • Employment records — Health information in employment records held by a covered entity in its role as an employer is excluded from the HIPAA definition of PHI.
  • Education records — Records covered under FERPA (such as student health records held by a school) are not PHI under HIPAA.
  • Aggregate data — "42% of patients in our practice have hypertension" is a statistic, not PHI, as long as it can't be traced to individuals.

The trap I see organizations fall into: assuming something isn't PHI because it "doesn't seem sensitive." A patient's name and appointment date might feel routine, but it meets the HIPAA definition of individually identifiable health information. Sensitivity doesn't determine PHI status — identifiability does.

Real Enforcement: What Happens When PHI Gets Mishandled

OCR doesn't issue warnings. It issues corrective action plans and financial penalties.

In 2023, Yakima Valley Memorial Hospital settled with OCR for $240,000 after 23 security guards were found to have improperly accessed patient medical records without a job-related need. The PHI involved? Names, diagnoses, and treatment information in the EHR — textbook protected health information examples that staff accessed out of curiosity, not malice. (HHS enforcement page)

The root cause in nearly every case I've reviewed isn't a firewall failure. It's a workforce training failure. Staff didn't understand what PHI was, or they didn't grasp the consequences of accessing or disclosing it improperly.

Mental Health Records: PHI With Extra Protections

If your organization handles behavioral or mental health data, the stakes are even higher. Psychotherapy notes get an additional layer of protection under 45 CFR §164.508 — they generally require specific patient authorization before disclosure, even for treatment purposes.

A client's therapy session notes, substance use disorder records, and psychiatric evaluations are all protected health information examples that demand extra caution. I've worked with behavioral health practices that had solid general HIPAA training but had never addressed the unique requirements for mental health PHI.

If that sounds familiar, our HIPAA Training for Mental & Behavioral Health course addresses these nuances head-on — from 42 CFR Part 2 substance use protections to psychotherapy note handling.

How to Audit Your PHI Exposure in 30 Minutes

Here's a quick exercise I recommend to every compliance officer I work with:

  • Walk your facility. Look at every screen, printout, whiteboard, and sign-in sheet visible from patient areas. If you can see an identifier linked to health information, it's exposed PHI.
  • Check the fax machine. Are incoming faxes sitting in an open tray in a shared hallway? That's a breach waiting to happen.
  • Listen. Stand near the front desk, the break room, and the nursing station for five minutes each. Count how many times you hear a patient's name paired with clinical information.
  • Review your last 10 outgoing emails. Were any unencrypted? Did any contain patient identifiers?

This exercise alone has led to immediate corrective actions in more practices than I can count. You don't need a consultant to find the gaps. You need 30 minutes and a critical eye.

Your Staff Can't Protect What They Can't Identify

The single biggest compliance failure I see is this: organizations assume their workforce knows what PHI is. They don't test it. They don't reinforce it. And when OCR comes knocking after a breach notification, the investigation reveals that staff couldn't list more than three protected health information examples.

That's not a knowledge gap. That's an organizational risk.

Build PHI recognition into your onboarding, your annual training, and your daily operations. Use real examples — the appointment screen, the voicemail, the hallway conversation. Make it tangible. Browse our full HIPAA training catalog for role-specific courses built to close exactly these gaps.

Because in my experience, the organizations that avoid OCR settlements aren't the ones with the biggest budgets. They're the ones whose front-line staff can look at a screen, a document, or a conversation and say with confidence: that's PHI, and here's how I handle it.