A nurse at a mid-size clinic texted a photo of a patient's intake form to a colleague — just to ask a quick question about a medication. That single text message triggered a breach investigation, a corrective action plan, and months of scrutiny from the Office for Civil Rights. The nurse had no idea the intake form contained protected health information. She thought it was "just a name and a prescription."

If you've ever searched what is PHI HIPAA, you're asking the most foundational question in healthcare privacy. And getting it wrong — even slightly — is the root cause of most HIPAA violations I've seen over two decades of consulting.

What Is PHI Under HIPAA? A Direct Answer

Protected health information, or PHI, is any individually identifiable health information that a covered entity or business associate creates, receives, stores, or transmits. That's the short version. The longer version matters more.

PHI has two components that must exist together:

  • Information that relates to a person's past, present, or future physical or mental health condition, the provision of healthcare, or payment for healthcare.
  • Information that identifies the individual — or could reasonably be used to identify them.

Remove either piece, and it's no longer PHI. A diagnosis code sitting alone in a spreadsheet with no names, dates, or identifiers? Not PHI. That same code linked to a patient name and date of birth? Absolutely PHI.

The U.S. Department of Health and Human Services defines PHI under the HIPAA Privacy Rule, which applies to covered entities — health plans, healthcare clearinghouses, and healthcare providers who transmit information electronically.

The 18 Identifiers That Turn Health Data Into PHI

HIPAA's Privacy Rule specifies 18 types of identifiers. When any one of them is combined with health information, you're dealing with PHI. I've watched organizations stumble on identifiers they never considered — like zip codes or device serial numbers.

Here's the full list:

  • Names
  • Geographic data smaller than a state (street address, city, zip code)
  • All dates directly related to an individual (birth date, admission date, discharge date, date of death)
  • Phone numbers
  • Fax numbers
  • Email addresses
  • Social Security numbers
  • Medical record numbers
  • Health plan beneficiary numbers
  • Account numbers
  • Certificate/license numbers
  • Vehicle identifiers and serial numbers (including license plates)
  • Device identifiers and serial numbers
  • Web URLs
  • IP addresses
  • Biometric identifiers (fingerprints, voiceprints)
  • Full-face photographs and comparable images
  • Any other unique identifying number, characteristic, or code

That last one is the catch-all, and it's deliberately broad. If your organization assigns patients a unique internal ID, that ID is an identifier under HIPAA.

Paper, Digital, and Spoken — PHI Lives Everywhere

PHI isn't limited to electronic records. A conversation in a hospital hallway where a patient's name and diagnosis are mentioned — that's PHI. A printed lab report sitting in an unlocked mailbox — PHI. A voicemail from a pharmacy confirming a prescription — PHI.

When PHI exists in electronic form, HIPAA calls it ePHI, and the HIPAA Security Rule kicks in with its own administrative, physical, and technical safeguard requirements.

The $4.3 Million Mistake: Why PHI Definitions Aren't Academic

In 2016, the University of Texas MD Anderson Cancer Center lost an unencrypted USB drive and a stolen laptop — both containing ePHI. OCR imposed a $4.3 million civil monetary penalty. The institution argued the data wasn't truly identifiable. The administrative law judge disagreed.

I've seen organizations try to rationalize their way out of PHI classifications. "It's just a billing code." "We only shared the patient's first name." "The email didn't have a diagnosis." None of these arguments hold up when OCR comes knocking.

The lesson: if there's any reasonable basis to identify the individual from the health data you hold, treat it as PHI. Full stop.

What Doesn't Count as PHI?

This is where I see confusion multiply. Not every piece of health-related data qualifies as PHI under HIPAA. Here's what falls outside the definition:

  • De-identified data. If all 18 identifiers have been removed and there's no reasonable basis to re-identify the individual, it's not PHI. HHS outlines two methods — expert determination and safe harbor — for proper de-identification.
  • Employment records. Health information in employment records held by a covered entity acting as an employer is excluded from the Privacy Rule's definition of PHI.
  • Education records. Records covered by the Family Educational Rights and Privacy Act (FERPA) are not PHI under HIPAA.
  • Data held by non-covered entities. Your fitness tracker data held by a tech company that isn't a covered entity or business associate? Not PHI under HIPAA — though other laws may apply.

Why Your Staff Gets PHI Wrong — And What It Costs

In my experience, the gap between knowing the textbook definition of PHI and recognizing it in daily workflows is enormous. Frontline staff handle PHI dozens of times per shift. They forward emails, print documents, discuss cases at nursing stations, and log into shared workstations.

Every one of those actions is a potential exposure point.

Anthem Inc. paid $16 million to OCR in 2018 — the largest HIPAA settlement in history — after a breach affecting nearly 79 million individuals. The root cause involved cyberattack vectors, but the scope of the damage traced directly back to massive stores of ePHI that weren't adequately protected.

Workforce training isn't a checkbox. It's the single most effective control against PHI mishandling. If your nurses and clinical staff haven't completed scenario-based training recently, our HIPAA Training for Nurses course walks through real clinical workflows where PHI decisions happen in seconds.

The Receptionist Problem

Here's a scenario I use in every training session. A patient calls and asks for their lab results. The receptionist confirms the patient's name and reads the results over the phone — without verifying identity first. That receptionist just disclosed PHI to an unverified caller.

Now multiply that by every phone call, every fax, every patient portal message across your organization. PHI exposure isn't dramatic. It's mundane, repetitive, and preventable.

PHI and Breach Notification: The 60-Minute Window

When PHI is impermissibly accessed, used, or disclosed, HIPAA's Breach Notification Rule triggers a cascade of obligations. Your organization must conduct a risk assessment, notify affected individuals, report to HHS, and in some cases notify media outlets.

The first hour after discovering a potential PHI breach is the most critical. Decisions made — or not made — in that window shape everything that follows. Our First 60 Minutes: Incident Response course gives your team a concrete playbook for those high-pressure moments.

How to Protect PHI: Five Steps That Actually Work

I've audited organizations ranging from solo dental practices to 12-hospital health systems. The ones that protect PHI effectively share common traits:

  • Minimum necessary standard. They limit PHI access to only what each workforce member needs for their specific role. No blanket access.
  • Encryption everywhere. ePHI at rest and in transit is encrypted. Period. This alone would have prevented the MD Anderson penalty.
  • Ongoing training. Not annual slide decks — actual scenario-based training tied to job functions. Our HIPAA Introduction Training 2026 covers the fundamentals every new hire needs on day one.
  • Physical safeguards. Locked file cabinets, badge-access workstations, clean desk policies. Low-tech, high-impact.
  • Incident response plans. Written, tested, and rehearsed — not buried in a policy binder no one has opened since 2019.

PHI vs. PII: A Distinction Worth Understanding

People frequently confuse PHI with PII — personally identifiable information. PII is a broader concept used across industries. PHI is specific to HIPAA and requires the health information component.

A Social Security number by itself is PII. A Social Security number linked to a prescription record at a covered entity is PHI. The distinction matters because HIPAA imposes specific penalties, breach notification timelines, and safeguard requirements that general PII frameworks don't.

What Happens When You Get PHI Right

Organizations that deeply understand what is PHI under HIPAA operate differently. Their staff pauses before hitting "reply all." Their IT teams encrypt by default. Their compliance officers sleep better.

Getting PHI right isn't about memorizing 18 identifiers. It's about building a culture where every person who touches health data understands the weight of what they're handling — and has the training to handle it properly.

That culture doesn't build itself. It starts with leadership that takes PHI seriously and invests in the training and tools to back it up. Browse our full HIPAA training catalog to find courses built for every role in your organization.