Privacy Settings
This site uses third-party website tracking technologies to provide and continually improve our services, and to display advertisements according to users' interests. I agree and may revoke or change my consent at any time with effect for the future.
Deny
Accept All
Back to the Article Hub
SaaS Security
‍Examples of PHI and How to Protect Protected Health Information
Share
Copy to clipboard
Table of Contents

PHI is the most regulated, most targeted, and most widely distributed data category in healthcare IT. It lives across electronic health records, billing software, telehealth platforms, scheduling tools, and dozens of SaaS applications your team may not fully see. Knowing what qualifies as protected health information, where it sits in your stack, and how to govern access to it is the foundation of HIPAA compliance.

This article covers the definitive list of PHI identifiers, real-world examples, the line between PHI and non-PHI, the consequences of mishandling it, and how SaaS access governance protects PHI at scale.

What Is Protected Health Information (PHI)?

Protected health information (PHI) is information, including demographic information, that relates to an individual's past, present, or future physical or mental health or condition; the provision of health care to the individual; or the past, present, or future payment for that care; and that identifies the individual or could reasonably be used to identify them.

PHI under HIPAA is individually identifiable health information collected or maintained by a HIPAA-covered entity or its business associates. (What is Considered PHI under HIPAA?) Remove any of those conditions, the health context, the identifiability, or the covered-entity relationship, and the information may fall outside HIPAA's jurisdiction.

The U.S. Department of Health and Human Services issued the Privacy Rule to implement HIPAA requirements. It governs how covered entities use and disclose individual health information, and sets the standards for the rights individuals have over their own data.

Quick Reference: The 18 HIPAA Identifiers

HIPAA's Safe Harbor method requires removing 18 specific identifiers to de-identify PHI. (18 HIPAA Identifiers for PHI De-Identification) At a glance:

# Identifier Where it commonly lives in your stack
1 Name EHR, scheduling, CRM, billing
2 Geographic subdivision smaller than a state EHR, address books, marketing tools
3 Dates tied to an individual EHR, telehealth logs, intake forms
4 Phone number Patient portals, CRMs, appointment reminders
5 Fax number Document management, referral logs
6 Email address Patient communications, marketing platforms
7 Social Security number Intake forms, billing systems
8 Medical record number EHR
9 Health plan beneficiary number Claims, eligibility tools
10 Account number Billing, payment platforms
11 Certificate or license number Intake forms
12 Vehicle identifiers and serial numbers Specialty cases (rare)
13 Device identifiers and serial numbers Medical IoT, asset management
14 Web URL Patient portals, care plan links
15 IP address Telehealth logs, web app logs
16 Biometric identifiers Authentication systems
17 Full face photo or comparable image EHR, telehealth, imaging
18 Any other unique identifier Emerging data types

Detail on each follows.

The 18 PHI Identifiers in Detail

1. Name

A patient's full name, first, last, or combined, is PHI the moment it appears alongside health data. A spreadsheet column labeled "Patient" that holds "Jane Smith" next to a diagnosis code is a PHI record.

2. Geographic Subdivision

All geographic subdivisions smaller than a state, including street address, city, county, precinct, zip code, and their equivalent geocodes (List of HIPAA Identifiers), qualify. Even a zip code attached to a medical record creates protected data.

3. Dates Related to an Individual

Birthdates, admission and discharge dates, dates of death, and the exact age of any patient older than 89 are all identifiers. (HHS HIPAA Identifiers List) Aggregate calendar years on their own are not.

4. Phone Number

Any telephone number tied to a patient's health record is PHI, whether landline, mobile, or VoIP. This includes numbers stored in appointment reminders, contact logs, and CRMs.

5. Fax Number

Fax numbers are explicitly listed. Fax transmissions carrying medical records remain one of the most common vectors for unintentional PHI disclosure.

6. Email Address

A patient's email tied to a health record is PHI. Secure email tools exist because standard email transmission does not meet HIPAA's minimum security requirements.

7. Social Security Number

Social Security numbers are among the highest-risk identifiers, since they enable identity theft when combined with any health data. Treat every SSN in your systems as critical access-controlled data.

8. Medical Record Number

A medical record number (MRN) uniquely links a patient to their health history. MRNs are PHI even when they appear without a name, because the number alone points directly to an individual record.

9. Health Plan Beneficiary Number

Insurance member IDs and beneficiary numbers connect individuals to their coverage history. They appear in billing files, claims data, and EHR exports.

10. Account Number

Patient account numbers, used for billing and payment tracking, are PHI identifiers. They surface frequently in billing SaaS and require the same protection as clinical identifiers.

11. Certificate or License Number

Driver's license numbers, professional license numbers, and certificate identifiers in patient records qualify. Healthcare organizations collect these during intake more often than they realize.

12. Vehicle Identifiers and Serial Numbers

Vehicle identification numbers (VINs) and license plate numbers are identifiers under HIPAA only when associated with a patient's health, treatment, or payment. Parking-lot data stored separately from patient records does not qualify. (What is Considered PHI under HIPAA?)

13. Device Identifiers and Serial Numbers

Serial numbers for medical devices, pacemakers, infusion pumps, and wearables are PHI identifiers when linked to health information. The growing IoT footprint in hospitals makes this identifier increasingly consequential.

14. Web URL

A patient-specific URL, such as a link to a personal portal profile or a care plan document, is a PHI identifier if it resolves to identifiable health information.

15. IP Address

An IP address captured during a telehealth session or patient portal login is a PHI identifier. Many IT teams underestimate this one; log files from web applications in healthcare environments must be handled as PHI.

16. Biometric Identifiers

Biometric identifiers, including finger and voice prints are PHI. Fingerprint authentication systems and voice-based patient engagement platforms generate biometric data that falls under HIPAA's security framework.

17. Full Face Photo or Images

Full face photographic images and any comparable images are PHI. Patient photos in EHR systems, telehealth screenshots, and imaging files all qualify.

18. Any Other Unique Identifier

Any other unique identifying number, characteristic, or code (other than a code an investigator assigns to recode data) qualifies. This catch-all clause future-proofs HIPAA against emerging data types, from genomic sequences to AI model outputs derived from patient data.

Common PHI Examples and Non-Examples

Clinical Notes

A physician's progress note referencing a patient's name, date of visit, and diagnosis is PHI. The same note stripped of all 18 identifiers is de-identified and falls outside HIPAA's scope.

Billing Statements

An Explanation of Benefits (EOB) containing a patient's name, account number, treatment date, and procedure codes is PHI. It combines financial identifiers with health context, which makes it doubly regulated.

Wearable Health Data

Smartwatch heart rate data is not automatically PHI. It becomes PHI the moment a covered entity ingests it into a patient record or uses it for a treatment decision. A consumer fitness app operating outside a healthcare provider relationship is not a covered entity and does not create PHI in most cases.

De-Identified Research Data

Health information stripped of all 18 identifiers is not PHI. A dataset of vital signs by itself, for example, is not protected. (HIPAA PHI: Definition of PHI and List of 18 Identifiers) Reintroduce any one of the 18 identifiers and the full dataset reverts to PHI.

PHI vs PII vs ePHI Explained

PHI, PII (personally identifiable information), and ePHI are related but distinct.

PII is any data that identifies a person, such as a name, SSN, or address, with no health context required. PHI is the subset of PII that involves health condition, treatment, or payment within a covered-entity relationship. ePHI is PHI in electronic form.

The Privacy Rule governs how covered entities use and disclose PHI in any format. The Security Rule applies specifically to ePHI and establishes the technical, administrative, and physical safeguards that electronic PHI requires. (What are the 18 PHI identifiers?)

In practice: your EHR database is ePHI. A handwritten intake form is PHI but not ePHI. Both require protection; only ePHI triggers HIPAA's Security Rule controls.

When Data Stops Being PHI

Data stops being PHI under two conditions: when it is properly de-identified, or when it exits a covered-entity relationship entirely.

Some research data is personally identifiable but not PHI, because it was never associated with a healthcare service, treatment, payment, operation, or medical record. (HIPAA PHI: Definition of PHI and List of 18 Identifiers)

HIPAA recognizes two de-identification methods: Safe Harbor, which requires removing all 18 identifiers, and Expert Determination, which uses statistical analysis to confirm that re-identification risk is very low. (18 HIPAA Identifiers for PHI De-Identification) Either method, applied correctly, takes the data out of HIPAA's scope. Skip the method, retain even one identifier, and the dataset remains PHI.

Where PHI Lives in Your SaaS Stack

PHI rarely sits in one place anymore. A single patient encounter can scatter identifiers across the EHR, the scheduling platform, the patient portal, the telehealth tool, the billing system, the secure messaging app, the document management platform, and the analytics warehouse. Each of these is a SaaS application with its own access model, audit log, and risk profile.

The practical implication for IT and compliance teams: protecting PHI is now a SaaS governance problem as much as a clinical systems problem. Three patterns show up repeatedly:

The same identifier appears in multiple systems. A patient's name and MRN may exist in the EHR, the billing platform, and the marketing automation tool, each with different access policies and different administrators.

Access accumulates over time. A clinician who rotates between departments, a contractor who renews twice, a vendor who joined for a pilot and stayed: each accrues permissions that were never reviewed against current job function.

PHI ends up in unsanctioned tools. A clinician syncing notes to a personal cloud drive, or a billing coordinator using an unapproved spreadsheet plugin, creates PHI exposure that the IT team cannot see in the EHR audit log.

This is the surface area where HIPAA enforcement and breach risk actually meet. The next sections cover what happens when that surface goes unmanaged, and what good governance looks like.

Consequences of PHI Breaches and Fines

HIPAA violations fall into a four-tier penalty system based on the level of knowledge and intent behind the breach. The Office for Civil Rights evaluates whether the organization was aware of the violation and how it responded after discovery. (HIPAA Breach Notification: Legal Risks and Penalties)

Per-violation minimums begin at $141 for a covered entity or business associate that did not know and could not have known with reasonable diligence. Maximums for most violations reach $71,162. For willful neglect that is not timely corrected, the maximum per-violation penalty extends to $2,134,831. Confirm current figures before quoting, since HHS adjusts them periodically.

Enforcement has remained active. In 2024, 22 OCR investigations led to penalties or settlements, with one state attorney general's fine exceeding $6 million. (HIPAA Violation Fines)

Criminal exposure exists in parallel and scales with intent: up to $50,000 and one year in prison for wrongful disclosure; up to $100,000 and five years if obtained under false pretenses; up to $250,000 and ten years if for commercial advantage, personal gain, or malicious harm. (Maximum Fine for HIPAA Violation)

Beyond fines, HIPAA's Breach Notification Rule requires covered entities to notify affected individuals, HHS, and in some cases the media within 60 days of discovery. Delay or incomplete notification compounds penalties and creates additional legal exposure.

The financial weight is reinforced by industry data: IBM's 2025 Cost of a Data Breach report puts the average healthcare breach cost at $7.42 million, the highest of any industry. (IBM Cost of a Data Breach 2025)

How to Protect PHI in Cloud and SaaS Apps

PHI no longer resides only in EHR systems behind hospital firewalls. The mitigations below address the SaaS dispersion that defines modern healthcare IT.

Encrypt at Rest and in Transit

Encryption is the minimum viable technical safeguard for ePHI. HHS has proposed to require encryption of ePHI at rest and in transit. In practice, this means AES-256 (or equivalent) for stored data and TLS 1.2 or higher for data in motion. An unencrypted laptop stolen from a clinician is an automatic breach; an encrypted one generally is not, because the data is rendered unreadable.

Enforce Least Privilege

PHI must be accessible only to users who need it for their job. Least privilege applies to every account, not just administrators, and requires ongoing review as roles change. Quarterly access reviews are the baseline mechanism; manual reviews are slow and error-prone, which is where automation pays off.

Monitor Shadow IT

Shadow IT, the category of applications employees adopt outside of formal IT approval, is a direct PHI risk. 86% of health system IT executives report shadow IT challenges, and the examples are familiar: a clinician syncing patient notes to a personal cloud account, a billing coordinator using an unsanctioned productivity tool. You cannot protect data you cannot see.

Rehab for JAPAN, a healthcare company driving digital transformation in nursing care, faced exactly this problem during rapid expansion. After implementing Josys, the IT team gained visibility into every SaaS application linked to each employee account, which allowed them to identify and contain shadow IT before it created compliance exposure.

Automating Access Governance to Protect PHI

Manual access management does not scale in healthcare IT. When a nurse changes roles, a vendor contract ends, or a contractor finishes an engagement, the window between that event and the revocation of PHI access is where exposure builds up. Automated workflows close that window systematically.

Continuous Access Reviews

Josys runs policy-driven access reviews across every connected SaaS application and surfaces accounts with excessive permissions, dormant credentials, or mismatched roles. What used to take an IT administrator hours of spreadsheet reconciliation resolves in minutes. Rehab for JAPAN reported that account issuance and termination tasks that previously took hours were completed in a fraction of the time after automating with Josys.

Policy-Based Provisioning

Provisioning from role definitions, instead of individual requests, prevents permission creep. When a new nurse joins, their access profile is generated from a template tied to their job function. Fewer manual entries means fewer typos, fewer mismatched permissions, and fewer unintended PHI exposures.

License and Account Hygiene

Every active SaaS account with PHI access is a potential vector for credential theft and lateral movement. Josys identifies unused and underutilized accounts across the SaaS portfolio so IT teams can deactivate dormant credentials before they become breach vectors, while also reclaiming license spend.

Conclusion

PHI protection is an operational discipline that spans every SaaS application, user account, and access policy in your environment. From correctly identifying all 18 HIPAA identifiers to automating access governance, the organizations that avoid breach fines and reputational damage treat PHI security as a continuous process, not a one-time audit.

Josys gives IT and compliance teams the visibility, automation, and control to manage PHI-adjacent SaaS access at scale: enforcing least privilege, detecting shadow IT, and streamlining offboarding before dormant accounts become breach vectors. Book a demo with Josys to see how your team can build an audit-ready access governance framework without the manual overhead.

FAQs About PHI Compliance

Is a patient's initials PHI?

Yes. Initials are derived from a patient's name, so they cannot be used as a de-identification code and remain PHI when attached to health information. (HIPAA PHI: Definition of PHI and List of 18 Identifiers)

Does HIPAA permit PHI to be stored on servers located outside the United States?

HIPAA does not explicitly prohibit storing PHI on servers located outside the U.S. Covered entities and business associates remain fully liable for HIPAA compliance regardless of where data is physically stored. Any cloud vendor storing PHI internationally must sign a Business Associate Agreement and demonstrate equivalent technical safeguards. Most healthcare legal teams treat offshore PHI storage as high-risk without airtight contractual controls.

How long must covered entities retain PHI records?

HIPAA's Privacy Rule requires covered entities to retain the documentation required by the rule (not necessarily the PHI itself) for six years from the date of creation or the date it was last in effect, whichever is later. State medical record retention requirements vary and may exceed six years; some states mandate up to ten years for adult records and longer for minors.

Questions? Answers.

No items found.