Examples of protected health information include a patient’s name paired with a diagnosis, a medical record number, a birth date on a chart, a lab result labeled with a Social Security number, a photograph of a patient’s face, and the IP address logged when someone signs into a patient portal. Under HIPAA, protected health information (PHI) is any health, treatment, or payment information held by a covered entity or its business associate that can be tied to a specific person through one of 18 identifier categories set out in federal regulations.1eCFR. 45 CFR 160.103 – Definitions
Two conditions have to be met. The information must relate to someone’s past, present, or future health, healthcare, or payment for care. And it must identify that person, or be capable of identifying them. A cholesterol reading floating on its own is not PHI. The same reading printed on a chart with the patient’s name and date of birth is.
The Two-Part Test
PHI can live in any format. Electronic files, paper charts, spoken conversations between clinicians, faxes, voicemails, and images all qualify when the two conditions are met.2HHS.gov. The HIPAA Privacy Rule Format does not change the analysis; content and context do.
The identifying half of the test is where most confusion happens. HIPAA’s de-identification standard names 18 categories of identifiers that, when attached to health information, make it PHI. Strip all 18 and the data is no longer PHI under what the rule calls the “Safe Harbor” method.3eCFR. 45 CFR 164.514 – Other Requirements Relating to Uses and Disclosures of Protected Health Information
The 18 Identifiers, With Examples
Any of the following, appearing alongside health information at a covered entity or business associate, creates PHI.
- Names. Full names or partial names combined with other details.
- Geographic data smaller than a state. Street address, city, county, ZIP code, precinct. The first three digits of a ZIP code can be kept only if that three-digit zone covers more than 20,000 people by Census data; otherwise those digits must be replaced with 000.4HHS.gov. Guidance Regarding Methods for De-identification of Protected Health Information in Accordance with the HIPAA Privacy Rule
- Dates tied to the individual. Birth date, admission date, discharge date, date of death, appointment date. The year on its own may be kept; the month and day cannot.
- Telephone numbers.
- Fax numbers.
- Email addresses.
- Social Security numbers.
- Medical record numbers.
- Health plan beneficiary numbers.
- Account numbers.
- Certificate or license numbers.
- Vehicle identifiers and serial numbers, including license plates.
- Device identifiers and serial numbers. Pacemaker serial numbers and insulin pump identifiers are common examples.
- Web URLs.
- IP addresses.
- Biometric identifiers. Fingerprints, voiceprints, retinal scans.
- Full-face photographs and comparable images.
- Any other unique identifying number, characteristic, or code. This catch-all reaches things not listed above that could single out a person, such as a tattoo description or a tribal enrollment number.3eCFR. 45 CFR 164.514 – Other Requirements Relating to Uses and Disclosures of Protected Health Information
That last category is the one people miss. A file scrubbed of the first 17 identifiers can still be PHI if some other detail narrows the field enough to point at one person.
The Age-Over-89 Rule
Ages over 89 get special treatment. So few people in any given area are that old that an exact age like 94 or 101 can effectively identify the patient when combined with a diagnosis or location. The rule requires ages above 89 to be aggregated into a single “90 or older” bucket, and birth years that would reveal such an age must be removed or aggregated as well.4HHS.gov. Guidance Regarding Methods for De-identification of Protected Health Information in Accordance with the HIPAA Privacy Rule
The same logic runs through the whole framework. A gender, a ZIP code, and a date of birth taken together can identify a startling share of a population. A rare diagnosis in a small town narrows the field further. Details that look harmless on their own can become identifying when combined with public records, which is why the identifier list is broad and why the catch-all exists.
Who Has to Follow the Rules
The identifiers only turn information into PHI when a HIPAA-regulated organization is holding it. Three types of organizations, called covered entities, are directly regulated: healthcare providers who submit claims electronically (doctors, hospitals, pharmacies, labs), health plans (insurance companies, HMOs, Medicare, Medicaid, employer-sponsored plans), and healthcare clearinghouses that process billing data.5eCFR. 45 CFR 160.103 – Definitions
The rules also reach the vendors and contractors these organizations rely on, known as business associates. A cloud storage company hosting hospital records, a billing service processing claims, or an IT firm maintaining a clinic’s systems all qualify, and business associates face direct liability for mishandling PHI, unauthorized disclosures, and failing to report breaches.6HHS.gov. Direct Liability of Business Associates
Common Examples of What Is Not PHI
Plenty of health-related information sits outside HIPAA’s reach, even when it looks like it should be covered.
De-Identified Data
Health information stripped of all 18 identifiers under the Safe Harbor method is no longer PHI, as long as the covered entity has no reason to believe the remaining data could still identify someone. A second path, called Expert Determination, lets a qualified statistician certify that the risk of re-identification is very small. Data cleared either way can be used freely for research and public health without HIPAA restrictions.3eCFR. 45 CFR 164.514 – Other Requirements Relating to Uses and Disclosures of Protected Health Information
Employment Records
Health details your employer collects for sick leave, workers’ compensation, wellness programs, and insurance enrollment are not PHI, even though they contain medical information. The Privacy Rule does not apply to an employer acting in that capacity.7U.S. Department of Health & Human Services (HHS). Employers and Health Information in the Workplace If the same organization also operates as a healthcare provider or health plan, records held in that healthcare role remain PHI. What matters is which hat the organization is wearing when it holds the data.
School Health Records
Student health files kept by a school, including immunization records and school nurse notes, fall under the Family Educational Rights and Privacy Act (FERPA), not HIPAA. The PHI definition explicitly carves out education records covered by FERPA.1eCFR. 45 CFR 160.103 – Definitions A school nurse’s file on your child’s allergies and medications is protected by FERPA’s rules, not HIPAA’s.
Consumer Health Apps and Wearables
Data collected by a fitness tracker, a meditation app, or a period-tracking app generally is not PHI, because the app developer usually is not a HIPAA-covered entity. This surprises people. Your step counts and heart rate readings on a consumer app may have no HIPAA protection at all. The FTC’s Health Breach Notification Rule does apply to these apps, so if a health app suffers a data breach it must notify affected users, the FTC, and in some cases the media, even though HIPAA does not reach the data.8Federal Trade Commission. Updated FTC Health Breach Notification Rule Puts New Provisions in Place to Protect Users of Health Apps If the app sends your data to a hospital or insurer, that same data may become PHI once the covered entity is holding it.
Records of People Deceased More Than 50 Years
Protection does not last forever. Health information about a person who has been dead for more than 50 years is excluded from the definition of PHI.1eCFR. 45 CFR 160.103 – Definitions Up to that 50-year mark, records of deceased individuals remain protected on the same terms as those of the living.
Putting the Examples Together
The pattern is consistent across every example. Health information plus one of the 18 identifiers plus a covered entity or business associate holding the data equals PHI. Remove any one of those three ingredients and the information generally falls outside HIPAA, though other laws (FERPA for schools, the FTC’s Health Breach Notification Rule for consumer apps, state privacy statutes) may still apply. When in doubt about a specific record, work through the three ingredients in order before assuming HIPAA either does or does not cover it.