A therapist mentions a patient's name and diagnosis in a hallway conversation with a colleague. A front-desk staffer leaves a printed appointment list face-up on the counter. A billing clerk emails a spreadsheet of patient names, Social Security numbers, and insurance IDs to the wrong address. Every one of these involves protected health information examples that trigger HIPAA obligations — and every one of them has led to real enforcement actions.
If your workforce can't identify PHI when it's staring them in the face, your organization is already at risk. This post walks through the specific data elements that make information "protected," the formats PHI takes, and the real-world mistakes that cost covered entities millions.
What Exactly Makes Health Information "Protected"?
Not all health data is PHI. HIPAA's Privacy Rule defines protected health information as individually identifiable health information that is created, received, maintained, or transmitted by a covered entity or business associate. Two conditions must be true simultaneously: the information relates to a person's health, treatment, or payment — and it can identify that person.
A blood pressure reading scribbled on a sticky note with no name attached? Not PHI. That same reading in a chart linked to Jane Doe's medical record number? Absolutely PHI.
HHS spells this out in the Privacy Rule at 45 CFR Part 160 and Subparts A and E of Part 164. If you haven't read the actual regulatory text, I'd encourage you to skim it at least once — it's shorter than you think.
18 Identifiers: The Core Protected Health Information Examples
The Privacy Rule lists 18 specific identifiers that, when linked to health data, create PHI. Here they are — and I've grouped them so your team can actually remember them.
Direct Identity Markers
- Names — first, last, maiden, aliases
- Social Security numbers
- Medical record numbers
- Health plan beneficiary numbers
- Account numbers
- Certificate or license numbers
- Full-face photographs and comparable images
Location and Contact Details
- Geographic data smaller than a state — street addresses, city, county, ZIP code (first three digits are okay only if the ZIP covers more than 20,000 people)
- Phone numbers
- Fax numbers
- Email addresses
- URLs
- IP addresses
Time-Based Identifiers
- Dates related to the individual — birth date, admission date, discharge date, date of death (year alone is permitted)
Device and Vehicle Identifiers
- Device identifiers and serial numbers
- Vehicle identifiers and serial numbers (including license plates)
Biometric and Unique Codes
- Biometric identifiers — fingerprints, voiceprints, retinal scans
- Any other unique identifying number, characteristic, or code
Combine any of these with health, treatment, or payment information, and you've got PHI. Your staff needs to internalize this list — not memorize it like a test, but recognize these elements instinctively when they encounter them on a screen, on paper, or in conversation.
The $1.5 Million Mistake: When Staff Don't Recognize PHI
In 2018, OCR settled with Cottage Health for $3 million after ePHI — electronic protected health information — for over 62,500 patients was exposed on the internet due to a server misconfiguration. The data included names, addresses, dates of birth, diagnoses, conditions, lab results, and Social Security numbers. Almost every identifier category was represented.
What made it worse? Cottage Health had already experienced a similar breach and had signed a corrective action plan. The organization's workforce failed to recognize how broadly PHI was stored and transmitted. You can review OCR's enforcement results at HHS's Resolution Agreements page.
I've seen smaller organizations assume they're safe because they "don't have that much data." But a single intake form at a behavioral health clinic contains a patient's name, date of birth, address, phone number, insurance ID, and presenting complaint. That's six identifiers linked to health information — on one sheet of paper.
PHI Isn't Just Digital: Verbal and Paper Examples Your Team Forgets
When most people hear protected health information examples, they think databases and EHR systems. But PHI exists in three forms, and the two non-digital ones cause the most accidental disclosures.
Verbal PHI
A nurse calling out a patient's full name and medication in a shared waiting area. A psychiatrist discussing a case on a cell phone in a coffee shop. A receptionist confirming a diagnosis over the phone to an unverified caller.
These aren't hypotheticals — they're patterns I encounter in nearly every risk assessment I conduct. If your team hasn't taken targeted training on this, our course Verbal Disclosures: Watch What You Say addresses exactly these scenarios with practical examples.
Paper PHI
Sign-in sheets that show the patient's reason for visit. Printed lab results left in a shared printer tray. Superbills stacked on a counter. Faxes sent to the wrong number. Paper is the original data breach vector, and it's still one of the most common.
Electronic PHI (ePHI)
This is the category that gets the most regulatory attention because the Security Rule adds specific safeguards for it. ePHI includes anything stored or transmitted electronically — EHR records, email, text messages, billing software, cloud backups, even voicemail recordings that contain patient information.
What Doesn't Count as PHI? Drawing the Line
This is the question I get asked most often, and getting it right matters for both compliance and operations.
De-identified data is not PHI. If you strip all 18 identifiers and have no reasonable basis to believe the information can identify an individual, HIPAA's Privacy Rule no longer applies. HHS provides detailed guidance on de-identification methods — the "Safe Harbor" method and the "Expert Determination" method — at HHS's De-Identification Guidance page.
Employment records held by a covered entity in its role as an employer are not PHI, even if they contain health information. Your HR file with a doctor's note for an employee's sick leave is governed by other laws (ADA, FMLA), not HIPAA.
Education records covered by FERPA are also excluded. A university health clinic's treatment records for students may straddle this line — another reason behavioral health and campus counseling staff need specialized HIPAA training for mental and behavioral health.
Why Your Workforce Needs Specific PHI Recognition Training
Here's what happens in practice. An organization writes a policy that says "protect PHI." Staff nod during orientation. Then a medical assistant texts a photo of a wound to a colleague using a personal phone, not realizing the patient's wristband — with name, DOB, and MRN — is visible in the frame.
That's a breach. It's reportable. And it was entirely preventable with scenario-based training that drills protected health information examples into daily workflows.
OCR has consistently stated that workforce training is not a one-time checkbox. The Privacy Rule at 45 CFR § 164.530(b) requires training for all workforce members, and it must be specific enough to be meaningful. Generic slide decks don't cut it.
What Effective PHI Training Covers
- Recognition of all 18 identifiers in context — not just a list, but real scenarios
- Verbal disclosure risks in clinical, administrative, and public settings
- Proper handling of paper records, faxes, and printed output
- ePHI security basics: encryption, access controls, device management
- Breach notification obligations when PHI is improperly disclosed
If you're building or refreshing your training program, our full course catalog covers these topics across clinical specialties and role types.
Quick Reference: Is It PHI?
Use this three-part test every time you're unsure:
- Does it relate to health, treatment, or payment? If no, it's not PHI.
- Can it identify a specific individual — directly or when combined with other available data? If no, it's not PHI.
- Was it created, received, maintained, or transmitted by a covered entity or business associate? If no, HIPAA doesn't apply (though other laws might).
All three must be true. If they are, you're handling PHI, and every safeguard in the Privacy Rule and Security Rule applies.
The Bottom Line on PHI Examples
PHI is broader than most people think and narrower than some compliance officers fear. The 18 identifiers are the backbone — learn them, train on them, and build your policies around them. Your organization's biggest vulnerability isn't a sophisticated cyberattack. It's a well-meaning employee who doesn't realize that a patient's name plus their appointment date plus their diagnosis equals a HIPAA obligation.
Recognize it. Protect it. Train your people until they can spot it without thinking.