A therapist in a small group practice mentioned a patient's name and diagnosis to a colleague in a crowded elevator. No chart was opened. No computer was hacked. But that single sentence — overheard by a stranger — became a federal complaint. If you're wondering what is protected health information or PHI, that story is your answer in miniature. PHI isn't just what lives in your EHR. It's every scrap of data that connects a person's identity to their health, and it travels in ways most people never think about.

This post breaks down exactly what PHI includes, where it hides, and what the Office for Civil Rights (OCR) does when organizations get careless with it. If you touch patient data in any capacity — billing, front desk, clinical, IT — this applies to you.

What Is Protected Health Information or PHI Under HIPAA?

Under the HIPAA Privacy Rule, PHI is any individually identifiable health information that a covered entity or business associate creates, receives, maintains, or transmits. That's the textbook version. Here's what it means in practice.

PHI has two components that must exist together. First, there must be health information — a diagnosis, a treatment plan, a lab result, a prescription, a billing code. Second, that information must be linked to an identifier that can reveal who the patient is.

HHS defines 18 specific identifiers that turn ordinary health data into PHI. Strip every one of them, and the data is considered de-identified. Leave even one, and you're handling PHI with all the compliance obligations that come with it.

The 18 Identifiers That Make Data PHI

  • Names
  • Geographic data smaller than a state
  • All dates (except year) related to an individual — birth, admission, discharge, death
  • Phone numbers
  • Fax numbers
  • Email addresses
  • Social Security numbers
  • Medical record numbers
  • Health plan beneficiary numbers
  • Account numbers
  • Certificate/license numbers
  • Vehicle identifiers and serial numbers
  • Device identifiers and serial numbers
  • Web URLs
  • IP addresses
  • Biometric identifiers (fingerprints, voiceprints)
  • Full-face photographs and comparable images
  • Any other unique identifying number, characteristic, or code

That last one is a catch-all, and it's intentional. If there's any reasonable basis to identify the individual, the data qualifies as PHI.

PHI Lives in More Places Than You Think

I've seen organizations laser-focused on their EHR while ignoring a filing cabinet full of intake forms in an unlocked break room. PHI doesn't care about the medium. It exists on paper, in conversations, on whiteboards, in voicemails, and in text messages between clinicians who think encryption is optional.

When PHI is stored or transmitted electronically, HIPAA calls it ePHI — electronic protected health information. The HIPAA Security Rule applies specifically to ePHI and requires administrative, physical, and technical safeguards. But the Privacy Rule covers PHI in all forms, including that sticky note with a patient's name and appointment time stuck to a monitor.

Common PHI Hiding Spots Your Team Misses

  • Appointment reminder texts sent through non-compliant platforms
  • Patient sign-in sheets visible to other patients
  • Verbal conversations at the front desk within earshot of the waiting room
  • Printed documents left on shared printers
  • Old hard drives and laptops that were never wiped before disposal
  • Screenshots shared in team group chats

Verbal disclosures are one of the most overlooked risk areas. A quick hallway conversation about a patient's medication can become a reportable incident if the wrong person overhears it. Our course on Verbal Disclosures: Watch What You Say walks your staff through exactly these scenarios.

The $1.5 Million Mistake: When PHI Gets Mishandled

In 2018, OCR settled with Filefax, Inc. for $100,000 after the company left medical records — including PHI — accessible in an unlocked vehicle. Those records were found by the public. The fine was modest because Filefax was a small operation. Larger entities pay exponentially more.

Advocate Medical Group paid $5.55 million in 2016 after multiple breaches involving unencrypted laptops containing ePHI of approximately 4 million patients. The laptops were stolen from vehicles and an office — physical security failures compounded by a lack of encryption.

These cases share a theme. The organizations knew they handled PHI. They just underestimated where it lived and how easily it could walk out the door.

Who Needs to Know What PHI Is? Everyone on Your Payroll

HIPAA's Privacy Rule applies to every member of a covered entity's workforce. That includes employees, volunteers, trainees, and contractors who work under your direct control. The law doesn't distinguish between a physician and a janitor who empties trash cans full of unshredded patient records.

In my experience, the biggest compliance gaps sit with non-clinical staff. Receptionists who confirm appointment details over the phone. IT contractors who image drives without wiping them. Billing specialists who email spreadsheets with patient identifiers to personal accounts.

Workforce training isn't a nice-to-have. It's a regulatory requirement under 45 CFR § 164.530(b). Every workforce member must receive training on your organization's privacy policies and procedures. If you're in behavioral health, the stakes climb even higher because of the sensitivity of substance use and psychotherapy records. Our HIPAA Training for Mental & Behavioral Health course addresses the unique PHI challenges in that setting.

PHI vs. Health Information: Where's the Line?

Not all health information is PHI. A dataset showing that 12% of patients in a county have diabetes — with no identifiers attached — is health information, not PHI. A research paper describing treatment outcomes using de-identified data isn't PHI either.

The line is identification. The moment you can link a health fact to a specific human being, you've crossed into PHI territory. And "link" doesn't require a name. A zip code combined with a birth date and a diagnosis can be enough to re-identify someone, especially in small communities.

This distinction matters for breach notification. If you lose a file containing de-identified data, you don't trigger the breach notification requirements under HIPAA. If that same file has a single medical record number attached, you're on the clock — 60 days to notify affected individuals and HHS.

Quick Reference: Is It PHI?

Ask two questions. Does the data include health information (diagnosis, treatment, payment for care)? Can you identify the individual it relates to, directly or indirectly? If both answers are yes, it's PHI. Treat it accordingly.

How to Protect PHI in 2026

Technology moves faster than regulation. Your staff are using AI transcription tools, cloud storage, telehealth platforms, and wearable device data — all of which can generate or transmit ePHI. Here's what I tell every organization I work with.

Start With a Risk Analysis

You can't protect what you haven't mapped. Conduct a thorough risk analysis to identify every system, device, and workflow where PHI exists. HHS has stated repeatedly that failure to perform a risk analysis is the single most common HIPAA violation.

Train for the Real World

Generic compliance videos don't change behavior. Your team needs scenario-based training that reflects their actual workflows. A front desk coordinator faces different PHI risks than a database administrator. Train accordingly. Browse our full HIPAA training catalog for role-specific options.

Encrypt Everything Electronic

Encryption is addressable under the Security Rule, not optional in any practical sense. If a laptop with encrypted ePHI is stolen, it's not a reportable breach under the safe harbor provision. If it's unencrypted, you're writing notification letters and potentially writing checks to OCR.

Lock Down Verbal and Physical PHI

Implement reasonable safeguards for conversations — lower voices, use private spaces, close doors. Shred paper records. Lock filing cabinets. These low-tech controls prevent high-cost violations.

The Bottom Line on PHI

Understanding what is protected health information or PHI isn't an academic exercise. It's the foundation of every HIPAA obligation your organization carries — from access controls to breach response. PHI is broader than most people assume, it lives in more places than most organizations track, and mishandling it triggers real financial and reputational consequences.

Get your workforce trained. Map your data. And never assume that a conversation, a sticky note, or an old laptop doesn't count. Under HIPAA, it almost certainly does.