Protected Health Information Examples Your Staff Miss
Your front desk prints tomorrow's schedule at 4:45 p.m. and leaves it face-up on the counter next to the copier. That single sheet holds at least four protected health information examples: patient names, appointment dates, phone numbers, and — because it's your practice printing it — the implicit fact that each person is receiving care from you. If a delivery driver photographs it, you have an impermissible disclosure to assess, document, and possibly report.
This article is a working inventory of what counts as PHI inside a real clinic, who owns each category, and what evidence you keep to prove you identified it. It is written for the person who signs vendor contracts and answers the records request, not for the patient.
What Are Examples of Protected Health Information?
Protected health information is individually identifiable health information created, received, maintained, or transmitted by a covered entity or business associate, in any form — paper, electronic, or spoken. Common protected health information examples include:
- A patient's name paired with an appointment date
- Medical record numbers, account numbers, and health plan beneficiary numbers
- Dates of admission, discharge, service, birth, and death
- Home address, ZIP code, email address, and phone or fax number
- Full-face photographs and comparable images, including wound photos with identifying features
- Diagnoses, medication lists, lab results, and clinical notes
- Billing records, superbills, EOBs, and payment history tied to a person
- IP addresses, device identifiers, and biometric identifiers such as fingerprints or voiceprints
- Social Security numbers, license numbers, and vehicle identifiers
- Voicemails, appointment reminder texts, and recorded phone calls that name a patient
The identifiers alone are not automatically PHI. A phone number in your payroll file is employment data. The same phone number in your recall list is PHI, because your possession of it links a person to care.
The 18 Identifiers, Translated Into Things on Your Floor
The 18-identifier list comes from the Safe Harbor method in the de-identification standard at 45 CFR 164.514(b). HHS publishes the full de-identification guidance, and your privacy officer should have it bookmarked. Here is how the categories show up in a practice.
Names and near-names
Full names, initials on a whiteboard, nicknames used in a group text, and relatives' names in a note. "Mrs. J in room 3" is still identifying if anyone in earshot can connect it. Names of employers and relatives are separately listed identifiers.
Geography smaller than a state
Street address, city, county, precinct, and ZIP code. Under Safe Harbor, the first three ZIP digits may sometimes remain, but only when the population rule is satisfied. Practically: do not treat a partial address as anonymized without running the analysis and writing it down.
Dates
All date elements except year — birth date, admission and discharge dates, date of service, date of death. Ages over 89 must be aggregated into a 90-plus category. Your quality dashboards and your marketing exports both break this rule routinely.
Numbers and codes
Phone, fax, email, SSN, MRN, health plan number, account number, certificate or license number, VIN and license plate, device serial numbers, URLs, IP addresses, biometric identifiers, and full-face images. The list closes with a catch-all: any other unique identifying number, characteristic, or code. That catch-all is why a rare diagnosis in a small town can identify someone even after you strip the obvious fields.
Protected Health Information Examples Practices Routinely Misclassify
The 18 identifiers are easy. These are the items that generate actual breach analyses.
The fact that someone is your patient
Existence of the treatment relationship is PHI. A sign-in sheet with names only, a lobby whiteboard, a callback list at the front desk, and a "no-show" report all disclose it. Sign-in sheets are permitted as incidental disclosures when you apply reasonable safeguards — one line visible at a time, no reason-for-visit column, sheet shredded daily.
Voicemails, texts, and the reminder queue
A message left on a household answering machine naming your gastroenterology practice discloses a condition category. Your reminder scripts should be written, approved, and retained. If a patient requests confidential communications by an alternate channel, you must accommodate reasonable requests — and your scheduling system needs a field to record that preference so the next staff member honors it.
Photographs and video
Clinical photos on a personal phone are ePHI on an unmanaged device. So is the security camera footage in your waiting room, and the training video someone shot in the treatment bay. Set the rule: practice-owned capture device, immediate upload to the chart, verified deletion from local storage, logged by the clinical lead.
IP addresses and website analytics
Tracking pixels and analytics scripts on authenticated portal pages transmit identifiers alongside health-related context. OCR's guidance on online tracking technologies was partially vacated by a federal district court in 2024 as applied to unauthenticated public pages, but nothing in that ruling touched the patient portal, the appointment-booking flow, or any page behind a login. Treat portal-side analytics as a disclosure requiring a business associate agreement or an authorization.
Billing and payment data
An EOB, a collections file, and a lockbox deposit report are PHI. So is the spreadsheet your biller emails to a contractor each Friday. The payment context does not strip the health context.
Staff who are also patients
When your medical assistant is treated at your own practice, that record is PHI and the access rules apply to her coworkers. Employment records you hold as an employer are not PHI — but the moment you treat her, a second file exists under a different rule set. Run an access audit on staff-patient charts quarterly; it is one of the most common snooping findings in the wild.
What Is Not PHI
Knowing the boundary saves you from over-restricting operations.
- Employment records held in your employer capacity — I-9s, performance reviews, workers' comp files you maintain as an employer.
- De-identified data under Safe Harbor or expert determination. Keep the determination documentation; without it you have an assertion, not a defense.
- Aggregate counts large enough that no individual is identifiable — "312 flu shots in November" is fine.
- Consumer health data your practice never touches — a patient's fitness tracker data sitting with the app vendor is outside HIPAA, though it may fall under the FTC's Health Breach Notification Rule. If your practice ingests that data, it becomes PHI in your hands.
- Records of a person deceased more than 50 years.
The Vendor List Is Where Examples Become Contractual Obligations
Every category above maps to at least one outside company. Your answering service hears voicemail PHI. Your shredding vendor holds paper PHI. Your IT contractor can reach ePHI at rest. Your billing clearinghouse, your cloud backup provider, your transcription service, your appointment-reminder platform, your e-fax provider — each one requires a signed business associate agreement before the first disclosure, not after the first incident.
Build the list this way: take your PHI inventory, and for each row write the name of every organization that can see, store, or transmit that data. The rows without a signed BAA are your open exposure. If you're closing those gaps this quarter, you can generate a signature-ready business associate agreement through a six-step wizard and export it as PDF or DOCX — one-time purchase, no subscription, which matters when you need eleven agreements out the door by Friday.
Two details operators get wrong. First, a conduit — the postal service, a telecom carrier moving encrypted traffic without persistent access — is not a business associate. Second, cloud storage vendors are business associates even if the data is encrypted and they claim they cannot read it. HHS has been explicit on that point.
Build the PHI Inventory Your Surveyor Will Ask For
The documented evidence is a data map. One row per data flow, with these columns:
- Data element — "appointment schedule," "clinical photos," "remittance files"
- Format — paper, ePHI, verbal
- System or physical location — EHR module, network share, filing cabinet in room 4
- Internal owner — named person, not a department
- External recipients — vendor names
- BAA status and execution date
- Safeguards applied — encryption at rest, badge access, auto-logoff interval
- Retention and disposal method
- Last verified date and by whom
This map is the input to your Security Rule risk analysis, not a substitute for it. The Security Rule NPRM published in January 2025 would, if finalized, explicitly require a written technology asset inventory and network map on an annual cadence. It is a proposal, not law, as of December 2025 — but every practice that already maintains the map will absorb that change in an afternoon. Tools that automate the risk analysis and policy set pull directly from an inventory like this one.
Who Does What, By When
Privacy officer, within 30 days: complete the inventory rows for paper and verbal PHI. Walk the building. Open the drawers. Photograph the fax machine's output tray.
Security officer or IT lead, within 45 days: complete the ePHI rows. Include shadow systems — the shared inbox, the personal Dropbox someone set up in 2021, the scanner that emails PDFs unencrypted.
Practice manager, within 60 days: reconcile the vendor column against signed BAAs. Escalate every gap in writing with a deadline.
All staff, at hire and annually: training that uses your own protected health information examples — your sign-in sheet, your reminder script, your fax cover page. Generic slide decks do not change behavior. Retain attendance records with dates and signatures.
Everyone, ongoing: report suspected impermissible disclosures within one business day so the privacy officer can run the four-factor risk assessment. Breach notification to affected individuals is due without unreasonable delay and no later than 60 days from discovery. You can review what other organizations have reported on the OCR breach portal — the recurring patterns are email, lost devices, and vendors.
The Fifteen-Minute Version
Walk your practice at 5:15 p.m. after the last patient leaves. Look at every surface, screen, tray, and bin. Write down each item that could identify a person and connect them to care. That list is your first draft of protected health information examples specific to your operation, and it will be more useful than any generic checklist because it names your rooms and your systems.
Then match each item to a vendor. Where the vendor has no signed agreement on file, draft and execute a business associate agreement before the next disclosure. That single reconciliation closes more real exposure than any policy you could write this month.