A Receptionist's Casual Comment Cost a Hospital $4.3 Million
In 2019, the University of Rochester Medical Center agreed to pay $3 million to HHS after failing to encrypt mobile devices containing patient data. But the breach didn't start with a hacker. It started with workforce members who didn't fully understand what protected health information under HIPAA actually included — and what devices it lived on.
I've seen this pattern repeat across organizations of every size. The problem isn't malice. It's ignorance. Staff members don't realize that a patient's name on a sticky note, a diagnosis mentioned in a hallway, or an appointment reminder sent to the wrong email address all involve PHI. And every one of those mistakes can trigger an OCR investigation.
This post breaks down exactly what qualifies as protected health information under HIPAA, where organizations consistently get it wrong, and the specific steps you need to take to protect it. If you handle any patient data — electronic, paper, or verbal — this applies to you.
What Exactly Is Protected Health Information Under HIPAA?
PHI is any individually identifiable health information that a covered entity or business associate creates, receives, maintains, or transmits. That's the textbook answer. Here's what it means in practice.
PHI has two components that must exist together. First, the information must relate to a person's past, present, or future physical or mental health condition, the provision of healthcare, or payment for healthcare. Second, it must include one or more of the 18 identifiers that can link that information to a specific individual.
The 18 Identifiers That Make Health Data PHI
HHS defines 18 specific identifiers that transform health data into PHI. Here they are:
- Names
- Geographic data smaller than a state
- Dates (except year) related to an individual — birth, admission, discharge, death
- Phone numbers
- Fax numbers
- Email addresses
- Social Security numbers
- Medical record numbers
- Health plan beneficiary numbers
- Account numbers
- Certificate or license numbers
- Vehicle identifiers and serial numbers
- Device identifiers and serial numbers
- Web URLs
- IP addresses
- Biometric identifiers (fingerprints, voiceprints)
- Full-face photographs and comparable images
- Any other unique identifying number, characteristic, or code
Strip all 18 identifiers, and you've got de-identified data — no longer PHI. Leave even one, and HIPAA's full weight applies.
The Three Forms of PHI Your Staff Probably Forget About
Most compliance officers focus on electronic protected health information — ePHI. That makes sense. It's where the big breaches happen. But HIPAA covers PHI in three distinct forms, and your workforce needs to understand all of them.
1. Electronic PHI (ePHI)
This is PHI stored or transmitted electronically. EHR systems, emails, text messages, cloud storage, USB drives, even voicemail recordings. The HIPAA Security Rule applies specifically to ePHI and requires administrative, physical, and technical safeguards.
2. Paper PHI
Printed lab results left on a printer tray. Intake forms sitting in an unlocked filing cabinet. Prescription pads with patient names. I once walked into a small clinic and found a stack of patient encounter forms sitting on a break room table next to someone's lunch. Paper PHI is easy to overlook and impossible to encrypt.
3. Verbal PHI
This is the one that gets people in trouble most often. A nurse discussing a patient's diagnosis in a crowded elevator. A front desk worker confirming a patient's appointment within earshot of the waiting room. A therapist leaving a detailed voicemail on a shared family phone. Our course on Verbal Disclosures: Watch What You Say covers exactly these scenarios, because verbal PHI violations are among the hardest to undo and the easiest to commit.
$16 Million in Penalties: What Happens When PHI Goes Unprotected
OCR doesn't issue fines for theoretical risks. They investigate real breaches that affect real people. And the settlements are staggering.
Anthem Inc. paid $16 million in 2018 — the largest HIPAA settlement in history — after a cyberattack exposed the ePHI of nearly 79 million people. OCR's investigation found that Anthem failed to conduct an enterprise-wide risk analysis, a fundamental requirement of the Security Rule.
Premera Blue Cross paid $6.85 million in 2020 after a breach affecting over 10.4 million individuals. Again, the root cause traced back to inadequate risk analysis and insufficient security measures for ePHI.
These aren't edge cases. They're the predictable result of organizations that treated PHI protection as a checkbox rather than a daily practice.
Where the Confusion Starts — And Where Breaches Follow
In my experience, most PHI violations trace back to three recurring gaps in workforce understanding.
Gap 1: "It's Not PHI If It's Just a Name"
Wrong. A patient's name alone isn't PHI. But a patient's name combined with the fact that they visited your dermatology clinic on Tuesday? That's PHI. The name becomes an identifier the moment it's linked to a healthcare context.
Gap 2: "We Only Need to Worry About Digital Records"
The Privacy Rule doesn't care about the medium. A whiteboard in a nurse's station with patient names and room numbers is PHI. A verbal conversation about a patient's mental health treatment is PHI. Every form counts equally under HIPAA enforcement.
Gap 3: "Business Associates Handle Their Own Compliance"
You're still responsible. If your billing company, cloud vendor, or shredding service mishandles PHI, OCR will investigate you too. Business associate agreements exist for exactly this reason, and they need teeth — not just signatures.
Mental Health PHI Gets Extra Protection — And Extra Scrutiny
If your organization provides mental or behavioral health services, you're operating in an even more sensitive zone. Psychotherapy notes receive heightened protection under the Privacy Rule. They can't be disclosed for treatment, payment, or healthcare operations without explicit patient authorization — a standard that's stricter than for most other PHI.
This distinction trips up even experienced compliance teams. General mental health information in a medical record (diagnosis, medications, treatment plans) follows standard PHI rules. But a therapist's private session notes? Those sit in a separate legal category.
If you work in this space, our HIPAA Training for Mental & Behavioral Health walks through these distinctions with scenario-based examples your clinical staff will actually remember.
How Long Must You Protect PHI? Longer Than You Think
HIPAA doesn't set a single expiration date on PHI protection. The Privacy Rule requires covered entities to retain certain documentation — policies, authorizations, notices — for six years from the date of creation or the date last in effect. But state laws often extend retention requirements further.
And here's the part people miss: PHI doesn't stop being PHI when a patient dies. HHS has clarified that the Privacy Rule protects a deceased individual's PHI for 50 years following the date of death. Your obligations don't end when a patient relationship does.
A Quick-Reference Definition for Your Team
What is protected health information under HIPAA? PHI is any information about a person's health status, healthcare treatment, or healthcare payment that can be linked to that specific individual through one or more of 18 identifiers defined by HHS. It exists in electronic, paper, and verbal forms. HIPAA's Privacy Rule, Security Rule, and Breach Notification Rule all govern how covered entities and business associates must handle it.
Five Steps to Protect PHI Starting This Week
You don't need a six-month project plan to start closing gaps. Here's what I recommend to every organization I work with.
- Conduct a current-state risk analysis. Not the one you did in 2022. A current one that reflects your actual systems, workforce, and data flows today. OCR looks for this first in every investigation.
- Audit verbal disclosure practices. Shadow your front desk, your nursing stations, and your call center for one day. You'll find PHI exposure you didn't know existed.
- Encrypt every device that touches ePHI. Laptops, phones, tablets, USB drives. Encryption is an addressable safeguard under the Security Rule, but "addressable" doesn't mean "optional."
- Train every workforce member — not just clinicians. Janitorial staff who see patient charts. IT contractors who access servers. Volunteers who answer phones. HIPAA's definition of "workforce" is broader than your HR roster. Browse our full training catalog for role-specific options.
- Review your business associate agreements. Make sure they're current, signed, and actually enforceable. An outdated BAA is almost as dangerous as no BAA at all.
The Bottom Line: PHI Is Broader Than You Assume
Protected health information under HIPAA extends far beyond medical records in an EHR system. It's the appointment reminder your staff leaves on a voicemail. It's the billing statement sitting in an open mailbox. It's the IP address logged when a patient accesses your portal.
Every one of those data points carries the full weight of HIPAA enforcement behind it. OCR has made that clear through years of investigations, corrective action plans, and eight-figure settlements.
Your job isn't to memorize every regulation. It's to build a culture where your entire workforce — from the C-suite to the cleaning crew — understands that PHI is everywhere, in every form, and protecting it is non-negotiable.