A Receptionist, a Fax Machine, and a $1.5 Million Mistake
In 2018, a medical center in Tennessee faxed a patient's complete treatment records to the wrong number — a local business that had nothing to do with healthcare. The document included diagnoses, medications, Social Security numbers, and insurance details. That single misdirected fax triggered an OCR investigation that uncovered years of sloppy data handling. The result: Touchstone Medical Imaging paid $3 million to settle HIPAA violations.
The staff member who pressed "Send" probably couldn't have told you exactly what is PHI information. That knowledge gap cost the organization everything. If you work at a covered entity — a hospital, clinic, health plan, clearinghouse, or any of their business associates — understanding PHI isn't optional. It's the foundation every other HIPAA requirement sits on.
What Is PHI Information, Exactly?
PHI stands for Protected Health Information. It's any information about a person's health, healthcare services, or payment for healthcare that can be linked back to a specific individual. The definition comes directly from the HIPAA Privacy Rule at 45 CFR §160.103.
Here's the critical detail most people miss: health data alone isn't PHI. A blood pressure reading of 140/90, by itself, isn't protected. But attach that reading to a name, date of birth, medical record number, or any other identifier — and it instantly becomes PHI.
PHI has two ingredients, and both must be present:
- Health information: Anything about a person's past, present, or future physical or mental health condition, the provision of healthcare, or payment for healthcare.
- Individual identifiers: Data points that can identify the person or provide a reasonable basis for identification.
The 18 Identifiers That Turn Health Data into PHI
HHS defined exactly 18 types of identifiers. When any one of them is combined with health information, you're looking at PHI. Here's the full list:
- Names
- Geographic data smaller than a state
- Dates (except year) related to an individual — birth date, admission date, discharge date, date of death
- Phone numbers
- Fax numbers
- Email addresses
- Social Security numbers
- Medical record numbers
- Health plan beneficiary numbers
- Account numbers
- Certificate/license numbers
- Vehicle identifiers and serial numbers
- Device identifiers and serial numbers
- Web URLs
- IP addresses
- Biometric identifiers (fingerprints, voiceprints)
- Full-face photographs and comparable images
- Any other unique identifying number, characteristic, or code
That last one is a catch-all, and it's there on purpose. If a data element can reasonably identify a patient, it counts. I've seen organizations get tripped up by employee badge numbers linked to internal patient records. If it points back to a person, it's an identifier.
ePHI: The Digital Version That Keeps CISOs Up at Night
When PHI exists in electronic form — stored on a server, transmitted via email, sitting on a laptop hard drive — it becomes electronic Protected Health Information, or ePHI. The HIPAA Security Rule applies specifically to ePHI and demands administrative, physical, and technical safeguards.
Think about everywhere ePHI lives in your organization: EHR systems, billing platforms, email inboxes, cloud backups, text messages between clinicians, even voicemail systems. Every single one of those locations needs documented protections.
In my experience, most breaches reported to OCR involve ePHI. Lost laptops, unencrypted email attachments, misconfigured cloud storage — these are the everyday scenarios that generate breach notifications and enforcement actions.
Does PHI Include Paper Records?
Absolutely. A printed lab report in a hallway printer tray is PHI. A sticky note with a patient name and diagnosis on a nurse's monitor is PHI. The Privacy Rule covers PHI in any form — paper, electronic, or oral. I've investigated incidents where cleaning staff found patient records in regular trash bins instead of shred consoles. That's a violation, full stop.
What Doesn't Count as PHI?
Not everything in a healthcare setting qualifies. Understanding the boundaries prevents your staff from either ignoring real risks or wasting time locking down data that doesn't need HIPAA-level protection.
These are not PHI:
- De-identified data: Health information stripped of all 18 identifiers using the Safe Harbor or Expert Determination methods described in the Privacy Rule.
- Employment records: A covered entity's HR records about its own employees — even if they include health data from a workers' comp claim — are not PHI under HIPAA (though other laws may apply).
- Education records: Covered by FERPA, not HIPAA, when held by educational institutions.
- Health data held by non-covered entities: Your fitness tracker data, the health info you share on a consumer app — these typically fall outside HIPAA unless a covered entity or business associate is involved.
Why Getting This Wrong Costs Real Money
OCR doesn't fine organizations for having PHI. Every covered entity has PHI — that's the nature of healthcare. OCR fines organizations for failing to protect it.
Consider the Premera Blue Cross settlement in 2020: $6.85 million after a breach exposed the ePHI of over 10.4 million individuals. The root cause? A phishing email that went undetected for nine months. Staff didn't recognize the threat, and technical safeguards failed to compensate.
In almost every major enforcement action I've studied, workforce training — or the lack of it — shows up as a contributing factor. When your front desk staff, billing team, and clinical employees don't understand what PHI information is, they can't protect it. They share it on social media. They leave it on screens in public areas. They send it to personal email accounts for convenience.
Social Media: The PHI Minefield Nobody Talks About Enough
A nurse posts a photo of a whiteboard during a hectic shift. In the background, a patient's name and room number are visible. That's a PHI disclosure. A medical assistant vents about a difficult patient encounter on a private Facebook group, including enough detail for someone to identify the patient. That's a PHI disclosure, too.
These aren't hypothetical scenarios. They happen constantly. If your organization hasn't addressed this head-on, our Social Media & PHI training course walks your team through real-world examples and clear policies they can actually follow.
What Should Your Organization Do Right Now?
Knowing what PHI information is represents step one. Here's what comes next:
1. Map Every Place PHI Lives
Conduct a thorough data inventory. Document every system, device, filing cabinet, and workflow that touches PHI. You can't protect what you haven't identified.
2. Train Every Member of Your Workforce
HIPAA requires training for all workforce members — not just clinicians. That includes volunteers, contractors, and administrative staff. Our HIPAA Introduction Training 2026 covers PHI identification, the Privacy and Security Rules, and practical scenarios your team will actually encounter.
3. Build an Incident Response Plan Before You Need One
When a breach happens — and statistically, it will — the first 60 minutes determine whether the damage stays contained or spirals. A panicked employee who doesn't know the reporting chain can turn a minor incident into a reportable breach. Our First 60 Minutes: Incident Response course gives your team a clear, rehearsed playbook for those critical early moments.
4. Review Business Associate Agreements
Your vendors who handle PHI need signed BAAs with specific obligations. If a cloud storage provider, billing service, or IT contractor touches PHI and doesn't have a current BAA, your organization carries the liability.
The Quick-Reference Answer: What Counts as PHI?
PHI is any health information — past, present, or future — about an individual's condition, treatment, or payment that is linked to one or more of the 18 HIPAA identifiers. It exists in electronic, paper, and oral forms. It applies to covered entities (health plans, healthcare providers who transmit electronically, clearinghouses) and their business associates. Protecting PHI requires administrative, physical, and technical safeguards under the HIPAA Privacy and Security Rules.
Your Staff Will Handle PHI Today — Make Sure They're Ready
Every person in your organization who can see, hear, or touch patient information needs to understand what PHI is and what the rules require. That's not a suggestion from HHS. It's a regulatory mandate with real enforcement behind it.
The organizations that avoid seven-figure penalties aren't lucky. They're trained. They've mapped their data. They've rehearsed their response plans. They've made PHI awareness part of their culture, not a once-a-year checkbox.
Start building that culture today. Browse our full HIPAA training catalog and give your workforce the knowledge that stands between your organization and the next OCR investigation.