The Spreadsheet That Cost a Hospital $4.3 Million
In 2019, the University of Texas MD Anderson Cancer Center lost a final appeal and faced $4.3 million in penalties — partly because unencrypted devices contained patient names, treatment records, and medical record numbers that wandered out the door on a stolen laptop and lost USB drives. The data on those devices was PHI. And the people who lost track of it didn't fully understand what PHI consisted of in the first place.
If you're asking what can PHI consist of, you're asking the right question at the right time. Most HIPAA breaches I've investigated trace back to a workforce that couldn't identify protected health information when it was sitting right in front of them — in an email, on a sticky note, or buried in a billing spreadsheet.
Let me walk you through exactly what counts, what doesn't, and where organizations consistently get it wrong.
What Can PHI Consist Of? The Direct Answer
Protected health information is any individually identifiable health information that a covered entity or business associate creates, receives, maintains, or transmits. Under the HIPAA Privacy Rule, PHI consists of two linked components:
- Health information — data relating to an individual's past, present, or future physical or mental health condition, the provision of healthcare, or payment for healthcare.
- Individual identifiers — data elements that can identify the person or provide a reasonable basis for identification.
Strip away the identifiers completely and properly, and you have de-identified data — no longer PHI. Keep even one identifier attached to health information, and you're holding PHI that HIPAA protects. The full regulatory text lives in 45 CFR Part 160.
The 18 Identifiers That Make Health Data PHI
HHS lists 18 specific identifiers under the Safe Harbor de-identification method. When any of these attach to health information, you've got PHI on your hands:
- Names
- Geographic data smaller than a state (street address, city, zip code)
- All dates directly related to an individual (birth date, admission date, discharge date, date of death) — and all ages over 89
- Phone numbers
- Fax numbers
- Email addresses
- Social Security numbers
- Medical record numbers
- Health plan beneficiary numbers
- Account numbers
- Certificate or license numbers
- Vehicle identifiers and serial numbers (including license plates)
- Device identifiers and serial numbers
- Web URLs
- IP addresses
- Biometric identifiers (fingerprints, voiceprints, retinal scans)
- Full-face photographs and comparable images
- Any other unique identifying number, characteristic, or code
That last bullet is the catch-all, and it's the one that trips people up most often. A patient's tattoo description in a clinical note? That could qualify. A unique employee badge number cross-referenced with a treatment record? Also PHI.
It's Not Just Medical Records
Here's where I see the biggest gap in workforce understanding. PHI doesn't live exclusively inside electronic health record systems. I've found PHI in places that made compliance officers physically wince:
- Appointment reminder texts sent through personal cell phones
- Voicemail messages left on answering machines with diagnosis details
- Billing invoices mailed to patients listing procedure codes
- Whiteboards in nursing stations with patient names and room numbers
- Screenshots of patient portals saved to personal cloud drives
If it ties a person's identity to their health, treatment, or payment — it's PHI. Format doesn't matter. Paper, electronic, verbal. All of it counts.
ePHI: The Digital Subset That Demands Extra Safeguards
When PHI exists in electronic form — on a server, in an email, on a thumb drive, in a text message — it becomes electronic protected health information (ePHI). The HIPAA Security Rule specifically governs ePHI and requires covered entities and business associates to implement administrative, physical, and technical safeguards.
The distinction matters because ePHI triggers requirements that paper PHI does not: encryption standards, access controls, audit logs, and transmission security. OCR has made this a consistent enforcement priority. The HHS breach settlement page shows a pattern of penalties tied directly to unsecured ePHI.
In my experience, organizations that treat all digital communications as potential ePHI carriers — not just their EHR — are the ones that avoid breach notification headaches.
The Gray Areas Where Organizations Stumble
Scheduling Information
A patient's name plus an appointment time at a cardiology clinic? That's PHI. The appointment itself reveals something about the individual's health condition. I've seen dental practices post next-day schedules in break rooms visible to janitorial staff. That's a Privacy Rule violation waiting to happen.
Billing and Payment Data
An invoice showing a patient's name and the amount billed for a colonoscopy is PHI. Payment records are explicitly included in the HIPAA definition. Your billing department handles PHI every single day, and every person in that department needs to know it.
Research Data
If a research dataset includes any of the 18 identifiers alongside health information, it's PHI — even if the research team promises they'll de-identify it "later." Later doesn't protect you from an OCR investigation today.
Deceased Individuals
PHI protections apply to deceased individuals for 50 years after death. I still run into organizations that assume the rules expire when a patient does. They don't.
The $1.5 Million Lesson From Failing to Know What PHI Looks Like
In 2018, OCR settled with Filefax, Inc. for $100,000 after the company left medical records — including patient names, SSNs, and lab results — in an unlocked vehicle accessible to the public. The records were later found dumped at a public recycling facility. A relatively small settlement, but the reputational damage was enormous.
Larger penalties hit harder. Athens Orthopedic Clinic paid $1.5 million in 2020 after a breach exposed records of over 208,000 patients. The root cause included failures in business associate oversight and access controls. Staff didn't fully grasp the scope of what the hackers had accessed because they hadn't been trained on the full picture of what PHI consists of.
These aren't theoretical risks. They're budget-destroying, career-ending events that proper workforce training prevents. If your team hasn't completed updated training recently, our HIPAA training catalog covers PHI identification in practical, scenario-based modules.
What Doesn't Count as PHI
Not everything health-related qualifies. Understanding the boundaries prevents both over-restriction and under-protection:
- Employment records held by a covered entity acting as an employer (e.g., sick leave records in HR files) — not PHI under HIPAA, though other laws may protect them.
- De-identified data that has been stripped of all 18 identifiers under Safe Harbor, or certified by a statistical expert under the Expert Determination method.
- Education records covered by FERPA, even if they contain health information.
- Data held by entities that are not covered entities or business associates — your fitness app company isn't governed by HIPAA unless it has a BA relationship with a covered entity.
The HHS guidance on de-identification is the definitive resource on where the line falls.
How to Train Your Workforce to Recognize PHI Everywhere
Telling your staff "protect PHI" without teaching them to spot it is like telling someone to avoid landmines without giving them a map. Here's what actually works:
- Use real examples from their department. Front desk staff need different training than IT. Billers need different scenarios than nurses.
- Test with actual documents. Hand them a redacted billing statement and ask them to circle every element that makes it PHI. You'll be surprised how many they miss.
- Cover verbal PHI. Elevator conversations, phone calls in shared spaces, and hallway consults are breach vectors that no firewall can stop.
- Retrain annually at minimum. OCR expects ongoing workforce training, not a one-time onboarding checkbox.
Role-specific training matters more than generic slide decks. Our HIPAA workforce training courses break this down by job function so your team actually retains what they learn.
PHI Travels Further Than You Think
Every time I conduct a risk assessment, I find PHI in at least three places the organization didn't know about. A shared Google Drive folder. A text thread between a physician and a home health aide. An old laptop in a storage closet that nobody wiped.
Understanding what can PHI consist of isn't an academic exercise. It's the foundation of every safeguard, every policy, and every breach prevention strategy your organization implements. Get this wrong, and everything built on top of it crumbles.
Start with the 18 identifiers. Audit where health information intersects with them across every department, every device, and every communication channel. Then train your people to see what they've been missing.
Because OCR won't ask whether your staff meant to expose PHI. They'll ask whether you taught them what it was.