A Single Spreadsheet Took Down a $3 Million Settlement
In 2018, the University of Texas MD Anderson Cancer Center lost an unencrypted laptop and two thumb drives. Those devices contained names, dates of birth, medical record numbers, and treatment details for over 33,000 patients. The OCR didn't just slap them on the wrist — an administrative law judge upheld $4.3 million in civil money penalties. All because patient identifiers weren't encrypted on portable media.
So what are patient identifiers, exactly? They're the 18 specific data elements that — when linked to health information — transform ordinary data into Protected Health Information (PHI) under HIPAA. Every covered entity and business associate in the country needs their workforce to recognize them on sight. Miss even one, and you're staring down a potential breach notification, an OCR investigation, and penalties that can climb into the millions.
This post walks through every single identifier, explains why each one matters, and gives you the operational playbook to keep them locked down.
The Official List: 18 HIPAA Patient Identifiers
The HIPAA Privacy Rule, codified at 45 CFR Part 164, Subpart E, establishes the framework for de-identification. Within that framework, HHS defines exactly 18 types of patient identifiers. When any one of them is attached to health information — a diagnosis, a prescription, a lab result — that data becomes PHI.
Here they are:
- Names — Full name, maiden name, aliases.
- Geographic data smaller than a state — Street address, city, county, ZIP code (the first three digits are allowed only if the geographic unit contains more than 20,000 people).
- Dates (except year) — Birth date, admission date, discharge date, date of death, and all ages over 89.
- Phone numbers
- Fax numbers
- Email addresses
- Social Security numbers
- Medical record numbers
- Health plan beneficiary numbers
- Account numbers
- Certificate/license numbers
- Vehicle identifiers and serial numbers — Including license plate numbers.
- Device identifiers and serial numbers
- Web URLs
- IP addresses
- Biometric identifiers — Fingerprints, voiceprints, retinal scans.
- Full-face photographs — And any comparable images.
- Any other unique identifying number, characteristic, or code
That last catch-all is intentionally broad. It covers anything that could reasonably identify a patient, even if it doesn't fit neatly into the first 17 categories.
Why Your Front-Desk Staff Needs to Know This List Cold
I've audited clinics where the medical director could rattle off HIPAA regulations in their sleep, but the receptionist didn't realize a ZIP code plus a diagnosis constitutes PHI. That gap is where breaches happen.
Patient identifiers don't just live in electronic health records. They show up in appointment reminder texts, paper sign-in sheets, voicemails left on answering machines, and screenshots shared between departments over unsecured channels. Every single person in your workforce who touches patient data needs to know what qualifies as a patient identifier.
This is exactly why structured HIPAA workforce training matters. You can't rely on a one-page handout from 2019 and hope for the best. Your team needs current, scenario-based education that puts these 18 identifiers into the context of their daily work.
What Are Patient Identifiers vs. De-Identified Data?
This is one of the most commonly confused concepts in HIPAA compliance. Here's the short answer, designed for quick reference:
Patient identifiers are any of the 18 data elements that can link information to a specific individual. Remove all 18 — and confirm that the remaining data can't be used alone or combined to identify someone — and you have de-identified data, which HIPAA no longer protects.
There are two paths to de-identification under the Privacy Rule:
Safe Harbor Method
Strip all 18 identifiers. Confirm that the covered entity has no actual knowledge that the remaining information could identify someone. This is the method most organizations use because it's straightforward.
Expert Determination Method
Hire a qualified statistician who applies accepted statistical and scientific principles to certify that the risk of identification is "very small." This is less common but gives organizations more flexibility in the data they retain for research.
Either way, the 18 identifiers are the starting line. You can't de-identify data if your workforce doesn't know what identifiers look like in the first place.
The Identifiers That Catch Organizations Off Guard
Names and Social Security numbers are obvious. Nobody argues about those. But in my experience, the identifiers that trip organizations up are the less intuitive ones.
Geographic Data Below State Level
A city name next to a rare diagnosis can narrow identification down to a handful of people. I've seen researchers assume that county-level data was safe for a public report. It wasn't. If your dataset includes geographic data smaller than a state and it's linked to health information, it's PHI.
Dates Beyond Year
Birth dates are the classic offender. But discharge dates, surgery dates, and even the date a prescription was filled can serve as identifiers. And for patients over 89, even the age itself becomes an identifier — it must be aggregated into a single category of "90 and over."
IP Addresses and URLs
Telehealth platforms, patient portals, and connected medical devices generate IP addresses constantly. If your organization logs IP addresses alongside clinical data, you're creating ePHI. Your IT team needs to treat those logs with the same level of protection as a medical chart.
Device Identifiers
Think about pacemakers, insulin pumps, and CPAP machines. Each has a serial number. If that serial number sits in a database next to a treatment record, it's PHI. Medical device manufacturers and the healthcare providers who use them both need to account for this.
Real Penalties for Mishandling Patient Identifiers
OCR doesn't issue theoretical warnings. They issue settlements and civil money penalties that show up in press releases.
In 2020, Premera Blue Cross agreed to a $6.85 million settlement after a cyberattack exposed the PHI of 10.4 million individuals. The compromised data included names, addresses, dates of birth, Social Security numbers, and clinical information. OCR's investigation found systemic noncompliance with HIPAA Security Rule requirements — the exact controls designed to protect patient identifiers in electronic form.
These aren't edge cases. They're the natural consequence of treating patient identifiers casually. When your organization fails to inventory where identifiers live, who has access to them, and how they're protected, you're one phishing email away from a reportable breach.
A Practical Checklist for Protecting Patient Identifiers
Knowing the list is step one. Protecting identifiers across your organization is step two. Here's where to focus:
- Inventory your PHI. Map every system, workflow, and physical location where patient identifiers exist. Paper charts, EHRs, billing systems, email threads, backup tapes — all of it.
- Apply minimum necessary. Every workforce member should access only the identifiers required for their specific role. A billing clerk doesn't need clinical notes. A lab tech doesn't need Social Security numbers.
- Encrypt ePHI at rest and in transit. The MD Anderson case proved that unencrypted portable devices are indefensible. Full-disk encryption and TLS for data in transit are baseline requirements.
- Train every role. Your security officer, your nurses, your janitorial staff, your IT vendors — anyone who might encounter PHI needs to know what patient identifiers look like. Our HIPAA training catalog includes role-specific courses designed for exactly this.
- Audit access logs. If someone accesses patient identifiers outside their job function, you need to know about it before OCR does.
- Implement breach notification protocols. Under the HIPAA Breach Notification Rule, any unauthorized acquisition, access, use, or disclosure of PHI — including a single patient identifier tied to health data — triggers an assessment and potentially a notification to HHS, affected individuals, and in some cases the media.
The Catch-All Identifier: Number 18
I want to circle back to the 18th identifier: "any other unique identifying number, characteristic, or code." This is HHS's safety net, and it's more relevant in 2026 than ever.
Genetic sequencing data, wearable device IDs, blockchain wallet addresses linked to health payments, unique patient portal usernames — none of these fit cleanly into the first 17 categories, but any of them could identify a person when linked to health information. The 18th identifier exists to cover exactly these scenarios.
If your organization assigns any unique code or number to a patient and links it to clinical data, treat it as a patient identifier. Period.
Stop Guessing, Start Training
I've reviewed hundreds of breach reports over the years. The pattern is almost always the same: an employee didn't recognize that a specific piece of data was a patient identifier, handled it carelessly, and triggered a chain of events that ended with an OCR investigation.
The fix isn't complicated. It's education — real, current, scenario-based training that meets your workforce where they actually work. Whether your team operates in a 400-bed hospital or a two-provider dental practice, the 18 identifiers apply equally. Browse our complete HIPAA training catalog to find courses built for every role in your organization.
Patient identifiers are the building blocks of PHI. Your entire compliance program rises or falls on whether your people can spot them.