Are IP Addresses Considered PHI Under HIPAA? The Two Conditions

Under HIPAA, an IP address is considered protected health information (PHI) when a covered entity or its business associate handles it in a way that ties it to an individual’s health information. On its own, an IP address is just a device identifier. The moment it sits next to health data inside a regulated organization’s system, HIPAA’s privacy and security rules apply to it.

The Two Conditions That Turn an IP Address Into PHI

Federal regulations list “Internet Protocol (IP) address numbers” as one of 18 identifiers that can make health information individually identifiable.1eCFR. 45 CFR 164.514 Being on that list does not automatically make every IP address PHI. Two things have to be true at the same time.

First, the IP address has to be connected to health-related information: a diagnosis, a treatment, an appointment, a prescription, a payment for care, or similar data about a person’s past, present, or future health.2HHS.gov. Guidance Regarding Methods for De-identification of Protected Health Information Second, that combined data has to be in the hands of a HIPAA-covered entity or a business associate acting on its behalf. Covered entities are healthcare providers that transmit information electronically, health plans, and healthcare clearinghouses.3HHS.gov. Covered Entities and Business Associates Business associates are outside vendors that handle PHI for those entities.

Miss either condition and the IP address is not PHI. An IP address logged by a general e-commerce site is outside HIPAA entirely, because the company is not a covered entity. An IP address logged by a hospital web server during an anonymous visit that has no meaningful health connection also falls outside the definition. But an IP address recorded when a patient logs into a portal to view lab results is PHI, because it identifies a person and travels with their health data inside a regulated system.

Remote patient monitoring works the same way. When a wearable transmits blood pressure or glucose readings to a provider’s server and the server logs the device’s IP address alongside those readings, that address is PHI.

Authenticated Pages vs. Public Webpages

The clearest line runs between login-protected pages and public ones.

On authenticated pages, the analysis is settled. When a patient signs in to check lab results, refill a prescription, or pay a bill, the system knows who they are and is delivering health information to them. Any IP address collected during that session is PHI.4HHS.gov. Use of Online Tracking Technologies by HIPAA Covered Entities and Business Associates

Public webpages are where the law recently shifted. In a December 2022 bulletin, the HHS Office for Civil Rights took the position that IP addresses collected on unauthenticated hospital webpages could be PHI if the visit itself suggested the person was seeking care, such as browsing an oncology or cardiology page. In June 2024, a federal court in Texas rejected that reading. In American Hospital Association v. Becerra, the court held that an IP address tied to a visit to an unauthenticated public webpage is not individually identifiable health information, finding that such metadata neither relates to a person’s health condition nor reasonably identifies them. The guidance was vacated to that extent.4HHS.gov. Use of Online Tracking Technologies by HIPAA Covered Entities and Business Associates

The current picture: IP addresses gathered through patient portals and other logged-in systems are PHI. IP addresses gathered from anonymous visitors browsing public pages generally are not. HHS has said it is evaluating next steps, so the boundary may move again.

Where Most Organizations Actually Get Caught: Tracking Pixels

The practical exposure for healthcare organizations rarely comes from a debate about what an IP address is. It comes from third-party tracking code. Tools like Google Analytics and the Meta Pixel are embedded on websites to measure traffic and ad performance, and they routinely collect visitor IP addresses, browsing behavior, and device identifiers, then transmit that data to the vendor’s servers.

When those tools run on authenticated pages where patients interact with their health information, the data they send is PHI. Sharing it with an analytics or advertising vendor without a business associate agreement in place violates HIPAA. A BAA obligates the vendor to protect the data under the same standards as the covered entity.5HHS.gov. Business Associate Contracts Most major ad and analytics platforms do not sign BAAs, which effectively rules out standard tracking pixels behind a patient login.

Enforcement has already reached real dollars. One hospital system faced a $300,000 settlement after pixels on its website transmitted patient IP addresses and browsing activity to third-party advertising platforms without authorization. The organization had to contact every third party that received PHI to request deletion, audit all third-party tools on its sites, and publicly disclose which vendors receive PHI and what data they collect.

If your organization runs tracking code, the pages to look at first are anything behind a login and anything where a user submits health-related information, such as appointment scheduling forms or symptom checkers.

Safeguards That Apply Once an IP Address Is PHI

Once an IP address qualifies as PHI, the HIPAA Security Rule requires administrative, physical, and technical safeguards to protect it.6HHS.gov. Summary of the HIPAA Security Rule

Administrative measures include a documented risk analysis, a risk management program to reduce identified vulnerabilities, workforce training, sanction procedures for policy violations, and a designated security official responsible for the program.7eCFR. 45 CFR 164.308 – Administrative Safeguards

Technical measures matter most for IP data, because IP addresses live in server logs, analytics dashboards, and application databases rather than in filing cabinets. The regulations require access controls, unique user IDs that tie system activity to specific individuals, audit controls that log access and use, integrity mechanisms that detect unauthorized changes, and transmission security including encryption for data sent over networks.8eCFR. 45 CFR 164.312 – Technical Safeguards Encryption is classified as “addressable” rather than “required,” which does not mean optional. It means the entity must implement it if reasonable or document why an equivalent alternative is appropriate.

Breach Notification When IP Addresses Are Exposed

If IP addresses that qualify as PHI are accessed, acquired, or disclosed without authorization, HIPAA’s breach notification rules apply. The covered entity must notify each affected individual in writing within 60 days of discovering the breach, describing what happened, what information was involved, what the individual should do, and what the entity is doing to investigate and prevent further problems.9eCFR. 45 CFR 164.404

If the breach affects more than 500 residents of a single state or jurisdiction, the entity must also notify prominent media outlets in that area within the same 60-day window.10eCFR. 45 CFR 164.406 – Notification to the Media The Secretary of HHS must be notified separately: within 60 days for breaches affecting 500 or more individuals, and through an annual log for smaller ones.

Pixel incidents cross the 500-person threshold easily. A tracking script running on authenticated pages for a few months can expose IP addresses and browsing behavior for thousands of patients before anyone notices.

Penalties

Civil monetary penalties are tiered by the violator’s level of culpability. The 2026 inflation-adjusted amounts are:11GovInfo. Federal Register, Volume 91 Issue 18

  • Did not know: $145 to $73,011 per violation, up to $2,190,294 per calendar year for identical violations.
  • Reasonable cause (not willful neglect): $1,461 to $73,011 per violation, same annual cap.
  • Willful neglect, corrected within 30 days: $14,602 to $73,011 per violation, same annual cap.
  • Willful neglect, not corrected within 30 days: $73,011 to $2,190,294 per violation, with a $2,190,294 annual cap.

Criminal penalties apply when someone knowingly obtains or discloses individually identifiable health information in violation of HIPAA. A basic violation carries up to a $50,000 fine and one year in prison. If the offense involves false pretenses, the maximum increases to $100,000 and five years. If the information was obtained for commercial advantage, personal gain, or malicious harm, the penalty rises to $250,000 and up to ten years.12GovInfo. 42 USC 1320d-6

The “did not know” tier matters in the tracking context. Many healthcare organizations installed analytics pixels years ago without considering HIPAA. Ignorance does not eliminate liability, but organizations that find a problem and fix it within 30 days face much lower exposure than those that learn about a violation and let it sit.