A hospital employee in Texas once posted a photo of a whiteboard in a break room. In the background, barely legible, was a patient's name next to a diagnosis code. That single Instagram story triggered a breach investigation, a six-figure settlement, and the termination of three staff members. The employee didn't think the whiteboard counted as patient data. She was wrong — and her organization paid for it.
If you've ever asked what is considered PHI information, you're asking the right question. But the answer is wider, stranger, and more consequential than most people expect. I've spent years consulting with covered entities who were stunned to learn that appointment dates, vehicle license plates, and even photographs without names attached can all qualify as protected health information under HIPAA.
What Is Considered PHI Information? The Actual Definition
Protected Health Information — PHI — is any individually identifiable health information that is created, received, maintained, or transmitted by a covered entity or its business associates. That's the regulatory definition from HHS's Privacy Rule page. But let me translate it into plain English.
PHI exists at the intersection of two things: health data and identity. A diagnosis by itself isn't PHI. A name by itself isn't PHI. But combine a name with a diagnosis — or a medical record number with a treatment plan — and you've crossed the line.
The key phrase is "individually identifiable." If information can be used alone or in combination to identify a specific person, and it relates to their past, present, or future health condition, healthcare services, or payment for those services, it's PHI. Period.
The 18 Identifiers That Make Health Data PHI
HHS didn't leave this to guesswork. The HIPAA de-identification standard lists exactly 18 identifiers. When any of these are linked to health information, you're handling PHI:
- Names
- Geographic data smaller than a state (street address, city, ZIP code)
- All dates directly related to an individual (birth date, admission date, discharge date, date of death) — and all ages over 89
- Phone numbers
- Fax numbers
- Email addresses
- Social Security numbers
- Medical record numbers
- Health plan beneficiary numbers
- Account numbers
- Certificate or license numbers
- Vehicle identifiers and serial numbers (including license plates)
- Device identifiers and serial numbers
- Web URLs
- IP addresses
- Biometric identifiers (fingerprints, voiceprints)
- Full-face photographs and comparable images
- Any other unique identifying number, characteristic, or code
That last one is the catch-all, and it's intentional. If your organization creates an internal patient tracking code, that code is an identifier. If a wearable device generates a unique ID tied to a patient's health data, that's an identifier too.
The Surprise Identifiers That Trip Up Real Organizations
In my experience, the identifiers that cause the most trouble aren't the obvious ones like names and Social Security numbers. Everyone knows to protect those. It's the edge cases that create real risk.
Appointment Dates
An appointment date linked to a clinic's schedule is PHI. I've seen dental offices post daily schedules on shared Google Docs without access controls. Every patient name paired with a date and time slot is a PHI disclosure waiting to happen.
IP Addresses
If your patient portal logs IP addresses alongside health records, that log contains ePHI — electronic protected health information. Your IT team needs to treat those logs with the same security as the medical records themselves.
Photographs
A full-face photo is an identifier. A dermatology practice that photographs a skin condition and stores the image alongside clinical notes is storing PHI, even if the filename doesn't include the patient's name. The photo itself is the identifier.
This is exactly why workforce training on social media and PHI is critical. Your staff may not realize that a selfie in a clinical setting can expose identifiers they never intended to share.
PHI vs. ePHI: Why the Distinction Matters
ePHI is simply PHI in electronic form. It includes data in EHR systems, emails, text messages, cloud storage, portable drives, and even voicemail systems. The HIPAA Security Rule applies specifically to ePHI and requires administrative, physical, and technical safeguards.
Here's the critical point: a sticky note with a patient's name and blood pressure reading is PHI, governed by the Privacy Rule. That same data typed into a spreadsheet on a laptop becomes ePHI, governed by both the Privacy Rule and the Security Rule. The obligations expand the moment data goes digital.
The $1.5 Million Fine That Started With a Spreadsheet
In 2018, OCR settled with Cottage Health for $3 million after ePHI for over 62,000 patients was exposed due to a server misconfiguration. The data included names, addresses, dates of birth, diagnoses, and Social Security numbers — a textbook example of identifiers linked to health information. The organization failed to perform adequate risk analysis on systems storing ePHI.
I bring up cases like this not to scare you but to show what's at stake when your staff doesn't understand what is considered PHI information. These weren't malicious actors. These were configuration oversights and training gaps.
What Doesn't Count as PHI
Not everything health-related is PHI. Understanding the boundaries prevents over-restriction, which can slow down operations and frustrate staff.
De-Identified Data
If you strip all 18 identifiers from a dataset and have no reasonable basis to believe the remaining information can identify an individual, it's no longer PHI. Researchers use de-identified data constantly. But the stripping has to be thorough — leaving even one identifier in the mix means it's still protected.
Employment Records
Health information in employment records held by a covered entity in its role as an employer is not PHI under HIPAA. Your HR files with employee sick notes? HIPAA doesn't cover those. Other laws might, but the Privacy Rule doesn't.
Education Records
Student health records covered by FERPA are excluded from HIPAA's definition of PHI. A university health center operating under FERPA follows different rules.
Who Has to Protect PHI? Covered Entities and Business Associates
HIPAA's obligations around PHI apply to covered entities — health plans, healthcare clearinghouses, and healthcare providers who transmit health information electronically — and their business associates. If your organization fits one of these categories, every piece of PHI you touch carries compliance requirements.
Business associates often underestimate their exposure. A billing company, a cloud hosting provider, an IT managed services firm — if they create, receive, maintain, or transmit PHI on behalf of a covered entity, they're on the hook. OCR has made that clear through enforcement actions against business associates directly.
What Happens When PHI Is Exposed
When PHI is improperly accessed, used, or disclosed, HIPAA's Breach Notification Rule kicks in. Your organization must notify affected individuals, HHS, and in some cases the media. The timeline is strict: notification must happen within 60 days of discovering the breach.
The first hour after discovering a potential breach is the most critical. Decisions made in that window determine whether the incident stays manageable or spirals. I always recommend organizations train their incident response teams with scenario-based exercises like our First 60 Minutes: Incident Response course. Knowing what to do before the crisis hits is the difference between a contained incident and a headline.
How to Train Your Workforce to Recognize PHI
Every member of your workforce — not just clinicians, not just IT — needs to know what is considered PHI information. The receptionist who confirms an appointment over the phone is handling PHI. The janitor who sees a document in the recycling bin instead of the shred bin is encountering PHI. The marketing intern posting a photo from the lobby could be exposing PHI.
Effective workforce training covers three things:
- Identification: Can your staff spot PHI in all its forms — paper, electronic, verbal?
- Handling: Do they know the minimum necessary standard? Are they sharing only what's needed for the task at hand?
- Reporting: When something goes wrong — a misdirected fax, an unlocked workstation, a suspicious email — do they know exactly who to tell and how fast?
If you're building or refreshing your training program, our full course catalog covers these scenarios and more with role-specific modules designed for real-world application.
A Quick Litmus Test You Can Use Today
When your team isn't sure whether something qualifies as PHI, have them ask two questions:
- Does this information relate to a person's health, healthcare, or payment for healthcare?
- Can this information — alone or combined with other available data — identify a specific individual?
If both answers are yes, treat it as PHI. Full stop. When in doubt, protect it. The cost of over-protecting data that turns out not to be PHI is zero. The cost of under-protecting data that is PHI can be millions.
PHI Doesn't Expire
One misconception I encounter constantly: people assume PHI from deceased patients or closed accounts is no longer protected. HIPAA protects the PHI of deceased individuals for 50 years after death. Old records aren't safe records. If your organization stores archived data from patients who haven't been seen in a decade, those records carry the same obligations as today's intake forms.
Understanding what is considered PHI information isn't an academic exercise. It's the foundation every other HIPAA requirement rests on. Get this wrong, and your risk assessments, your access controls, your breach response plans — all of it is built on sand. Get it right, and compliance becomes a system instead of a scramble.