A Patient's Name on a Sign-In Sheet Cost One Practice $125,000

I got a call from a clinic manager who was genuinely confused. "We just have a paper sign-in sheet at the front desk," she said. "How can that be a HIPAA violation?" The answer floored her: that sign-in sheet, combined with the reason-for-visit column patients were filling out, created a document containing protected health information visible to every person in the waiting room.

Understanding what is considered private health information isn't just a compliance formality. It's the foundation every HIPAA decision rests on. Get it wrong, and your organization bleeds risk in ways you won't notice until OCR comes knocking.

Here's the hard truth: most workforce members — from front desk staff to billing coordinators — can't accurately define PHI. And that gap between what people assume and what the law actually says is where breaches live.

What Is Considered Private Health Information? The Actual Definition

HIPAA doesn't use the phrase "private health information." The legal term is protected health information (PHI). But the question behind the search is the same: what data does HIPAA actually protect?

PHI is any information that meets all three of these criteria:

  • It relates to an individual's past, present, or future physical or mental health condition, the provision of health care, or payment for health care.
  • It identifies the individual — or could reasonably be used to identify them.
  • It is created or received by a covered entity or business associate.

That's it. Three criteria. But the implications are enormous. A lab result with a patient's name is PHI. A voicemail confirming a therapy appointment is PHI. A billing record showing a procedure code tied to a date of birth is PHI. Even a photograph of a wound on a patient's arm, if it's stored on a clinic's phone, qualifies.

The U.S. Department of Health and Human Services lays this out clearly in its HIPAA Privacy Rule guidance.

The 18 Identifiers That Turn Health Data Into PHI

Health information alone isn't automatically PHI. A dataset of anonymous blood pressure readings with no identifying details doesn't trigger HIPAA protections. What flips the switch is the presence of one or more of the 18 HIPAA identifiers.

Here's the full list:

  • Name
  • Address (anything more specific than state)
  • Dates related to the individual (birth date, admission date, discharge date, date of death)
  • Phone number
  • Fax number
  • Email address
  • Social Security number
  • Medical record number
  • Health plan beneficiary number
  • Account number
  • Certificate or license number
  • Vehicle identifiers and serial numbers
  • Device identifiers and serial numbers
  • Web URLs
  • IP addresses
  • Biometric identifiers (fingerprints, voiceprints)
  • Full-face photographs and comparable images
  • Any other unique identifying number, characteristic, or code

Combine any of these with health or payment information at a covered entity, and you've got PHI. Period.

Why IP Addresses Catch People Off Guard

I've watched IT teams argue that IP addresses "aren't really identifying." They are. HHS included them deliberately. If your patient portal logs capture IP addresses alongside appointment data, that's electronic protected health information — ePHI — and it demands the full weight of the HIPAA Security Rule's administrative, physical, and technical safeguards.

Verbal PHI: The Breach Nobody Writes Down

Here's what I tell every client: PHI isn't just data in a computer. It's the conversation at the nursing station. It's the phone call a receptionist takes in a crowded hallway. It's the therapist who mentions a patient's name to a colleague in the elevator.

Verbal disclosures are one of the most under-addressed HIPAA risks in healthcare. Your workforce might lock down every server and encrypt every laptop, then casually discuss a patient's diagnosis within earshot of other patients' family members.

If your team handles sensitive conversations — and every healthcare team does — our course on Verbal Disclosures: Watch What You Say breaks down exactly where the lines are and how to stay on the right side of them.

The $5.5 Million Mistake: Memorial Healthcare System

In 2017, OCR settled with Memorial Healthcare System for $5.5 million after employees accessed the ePHI of 115,143 individuals without authorization. The root cause? The organization failed to review who had access to PHI and didn't audit access logs for years.

Memorial knew what PHI was in theory. But they didn't operationalize that knowledge. They didn't ask, "Who can see this data, and should they?" That question — applied daily — is worth more than any policy document sitting in a binder.

You can review the full resolution agreement on the HHS enforcement page.

Mental Health Records: PHI With Extra Protections

Not all PHI is treated equally. Psychotherapy notes — the personal notes a therapist jots down during or after a session — receive heightened protection under the Privacy Rule. They're stored separately from the medical record, and most uses or disclosures require specific patient authorization. General consent for treatment, payment, or healthcare operations doesn't cover them.

This distinction trips up behavioral health practices constantly. I've seen group practices where therapists stored session notes in the same shared EHR folder as general treatment records, making them accessible to billing staff who had no business seeing them.

If your organization provides mental or behavioral health services, the regulatory landscape is stricter than general healthcare. Our HIPAA Training for Mental & Behavioral Health course covers these nuances in detail, including 42 CFR Part 2 considerations for substance use disorder records.

What Doesn't Count as PHI

Equally important is knowing what falls outside HIPAA's scope. These are not PHI:

  • De-identified data. If all 18 identifiers have been stripped and there's no reasonable basis to re-identify the individual, HIPAA no longer applies.
  • Employment records. Health information in an employment record held by a covered entity in its role as employer isn't PHI under the Privacy Rule.
  • Education records. Records covered by FERPA (Family Educational Rights and Privacy Act) are excluded.
  • Data held by non-covered entities. Your fitness app tracking your heart rate isn't PHI — unless it's sharing data with a covered entity or business associate.

This is where context matters. The same data point — say, a diagnosis of diabetes — can be PHI in one setting and not in another. It depends on who holds it and how it's linked to an identifiable person.

How Breaches Happen When Staff Can't Define PHI

In my experience, the majority of HIPAA breaches don't involve hackers or sophisticated cyberattacks. They involve workforce members who didn't recognize that the information they were handling qualified as PHI.

Here are scenarios I've investigated firsthand:

  • A medical assistant texted a patient's lab results to a personal cell phone to "save time." That's an unauthorized disclosure of ePHI on an unsecured device.
  • A billing clerk emailed a spreadsheet of patient names, dates of service, and insurance IDs to a personal Gmail account to "work from home." Unencrypted ePHI, sent to a non-compliant platform.
  • A receptionist confirmed a patient's appointment and diagnosis over the phone to someone who claimed to be a family member — without verifying identity or authorization. Verbal PHI disclosure to an unauthorized recipient.

Every one of these incidents traces back to the same root cause: the person didn't fully understand what is considered private health information, or they didn't apply that understanding in the moment.

Protecting PHI: The Non-Negotiable Steps

Knowing the definition is step one. Protecting PHI is the ongoing work. Here's what your organization needs at a minimum:

Administrative Safeguards

Conduct a thorough risk analysis. Train every workforce member — not just clinicians — on what qualifies as PHI and how to handle it. Document your policies and enforce them. Review access controls at least annually.

Physical Safeguards

Lock filing cabinets. Position computer screens away from public view. Secure printed documents. Shred anything containing PHI before disposal.

Technical Safeguards

Encrypt ePHI at rest and in transit. Implement unique user IDs and automatic logoff. Maintain audit logs. Use multi-factor authentication for remote access.

HHS provides a detailed security rule summary at hhs.gov/hipaa/for-professionals/security.

The simplest rule of thumb I give to every client: if health or payment information can be connected to a specific person, treat it as PHI. Don't wait for legal to weigh in. Don't assume someone else is handling it. Protect it now.

Your organization's ability to answer "what is considered private health information" shouldn't depend on one compliance officer. Every person who touches patient data — schedulers, coders, nurses, IT staff, executives — needs to know the answer cold.

That's not aspirational. That's the minimum standard HHS expects, and it's what OCR will measure you against when something goes wrong. Invest in workforce training that makes this knowledge stick. Browse our full HIPAA training catalog to find courses built for your team's specific roles and risks.