How PII and PHI Apply to Everyday Medical Practice Operations
Medical practices handle identifying information throughout the workday. Patient names, phone numbers, addresses, insurance information, appointment details, medical histories, photographs, account numbers, and payment information move through registration and clinical care. They also move through billing and communication systems.
Some of that information may be personally identifiable information, commonly referred to as PII. Some may qualify as protected health information, or PHI, under HIPAA.
The distinction is important, but it is also easy to oversimplify.
A patient’s phone number does not become PHI simply because phone numbers can identify people. The context in which information is created, received, maintained, or transmitted matters.
When identifying information is associated with an individual’s health, healthcare, or payment for healthcare and is handled by a HIPAA-covered entity or business associate, the information may constitute PHI.
For medical practices, understanding that relationship is more useful than simply memorizing definitions. Staff need to recognize protected information as it moves through everyday workflows so they can handle it appropriately.
Key Takeaways
- PII and PHI overlap, but they are not interchangeable terms.
- An identifier such as a name, phone number, or email address is not automatically PHI; the health information and HIPAA context matter.
- PHI can exist in schedules, reports, emails, printed documents, temporary notes, and other workflows outside the EHR.
- The 18 HIPAA identifiers belong to the Safe Harbor de-identification framework and should not be taught as a universal PHI detection checklist.
- Medical practices should evaluate how PHI moves through registration, clinical care, communication, billing, storage, retention, and disposal.
- Staff training is more useful when employees learn to recognize protected information in realistic workflows rather than simply memorize privacy terminology.
Table of Contents
What Is Personally Identifiable Information?
PII is a broad term generally used for information that can distinguish or trace an individual’s identity, either by itself or when combined with other information that is linked or linkable to that individual.
Some identifiers are more directly identifying than others. Examples include a Social Security number, passport number, or full name.
Other information, including addresses, telephone numbers, email addresses, dates of birth, and identification numbers, may identify an individual by itself or when combined with additional data.
The important point for a medical practice is that identifying information exists throughout the organization, and not every piece of identifying information should automatically be labeled PHI.
PHI has a more specific healthcare context.
What Makes Information PHI?
Protected health information is individually identifiable health information that is transmitted or maintained in specified forms or media by a HIPAA covered entity or business associate, subject to applicable exclusions and circumstances under the HIPAA Privacy Rule.
When an outside vendor creates, receives, maintains, or transmits PHI on behalf of the practice, the practice may also need to determine whether the vendor qualifies as a business associate and whether a business associate agreement is required.
The information may relate to an individual’s past, present, or future physical or mental health or condition, the provision of healthcare to the individual, or past, present, or future payment for that healthcare.
That means PHI extends well beyond diagnoses and clinical notes.
Consider the information generated during an ordinary patient encounter. The practice may collect demographic information during registration and document symptoms and treatment in the medical record. It may obtain insurance information and generate a claim. It may also schedule follow-up care and send the patient a message about the appointment.
PHI can appear throughout that process.
| Information | Why Context Matters |
|---|---|
| Patient name | An identifier that can help make health information individually identifiable |
| Phone or email | May be part of PHI when associated with individually identifiable health information in a HIPAA-covered context |
| Appointment information | Can reveal that an identifiable individual is receiving healthcare |
| Diagnosis or treatment information | Health information that may constitute PHI when individually identifiable and handled in a HIPAA-covered context |
| Insurance information | Can be associated with payment for healthcare |
| Medical record number | Directly connects information to an individual’s healthcare record |
| Patient photograph | May identify the individual when associated with health information |
This context is why staff should not think of PHI as synonymous with the contents of the clinical chart. Patient information can require protection before the provider ever opens the medical record and after the clinical encounter has ended.
Health information is not automatically PHI simply because it concerns a person’s health. HIPAA’s PHI protections depend in part on who creates, receives, maintains, or transmits the information and the circumstances in which it is handled. The same type of information may therefore be subject to different privacy requirements depending on the organization and context involved.
PII and PHI Can Overlap
The relationship between PII and PHI becomes easier to understand when looking at how information is used.
A telephone number in an ordinary contact list may be identifying information without being PHI. When that number is maintained by a HIPAA covered entity as part of information associated with an identifiable patient’s care or payment for healthcare, it may be part of PHI.
Similarly, a person’s name by itself does not tell you anything about their medical condition. A name attached to an appointment for a particular healthcare service can reveal additional information.
The same principle applies to email.
An email address may identify a person without necessarily being PHI. In a HIPAA-covered context, an email that connects an identifiable individual with appointment information, treatment, test results, payment information, or other protected health information may contain PHI.
The distinction is therefore not simply about the individual data element. Staff need to consider what the information reveals and the context in which the practice is handling it.
Operational Snapshot
Privacy decisions cannot reliably be made from the data field alone. Practices need workflows that account for what information is connected to an identifier and why it is being handled. They also need to account for the environment in which it appears before staff decides how it should be protected.
Recognizing PHI Across Medical Practice Workflows
PHI Is Not Limited to the Medical Record
One of the most important operational lessons is that PHI exists in many places outside the EHR.
Practices frequently create temporary or secondary information while doing routine work. A receptionist writes down a patient’s name and phone number while returning a call. A medical assistant prints a schedule. A billing employee generates a report containing patient account information. A provider sends a patient-related message to another member of the care team.
All of those workflows can involve PHI.
Staff should be trained to recognize common forms of protected information, including:
- patient demographic information associated with care
- clinical information, diagnoses, treatment plans, and prescriptions
- appointment and scheduling information tied to identifiable patients
- insurance, account, and payment information associated with healthcare
- patient communications containing identifiable health information
- photographs, medical record numbers, and other identifiers connected to care
This broader understanding matters because employees may protect the EHR carefully while treating a printed schedule, handwritten note, or email as less sensitive.
The format alone does not determine whether information constitutes PHI or what safeguards are appropriate.
Compliance Alert
Safeguards focused primarily on the EHR can leave secondary workflows exposed. Privacy reviews should account for the places staff temporarily reproduce, export, print, write down, or communicate PHI. HIPAA protections can continue to apply even when the information exists outside the primary system or only briefly.
The 18 HIPAA Identifiers Need Context
HIPAA’s de-identification standard identifies 18 categories of identifiers that are relevant when determining whether health information has been de-identified under the Safe Harbor method.
Those categories include names, certain geographic information, certain dates, telephone and fax numbers, email addresses, Social Security numbers, medical record numbers, health plan beneficiary numbers, and account numbers.
They also include certificate or license numbers, vehicle and device identifiers, URLs, IP addresses, biometric identifiers, full-face photographs and comparable images, and other unique identifying numbers or characteristics.
This list is useful, but practices should be careful about how it is taught. Employees may otherwise assume that every instance of one of these identifiers is automatically PHI. The presence of a Safe Harbor identifier does not, by itself, determine whether information is PHI; the broader HIPAA context still matters.
Teaching the identifiers alongside realistic practice scenarios helps staff understand what they are actually protecting rather than simply memorizing a list.
Technical Deep Dive
The 18-identifier list serves a specific role in HIPAA’s Safe Harbor de-identification method; it is not a universal PHI detection checklist. Training that separates de-identification rules from day-to-day information classification can reduce false assumptions about when an identifier, by itself, carries a particular HIPAA status.
Applying PII and PHI Concepts Across Daily Workflows
Why the Distinction Matters in Daily Operations
The practical value of understanding PHI becomes apparent when employees have to make routine decisions about information.
Can this document be placed in regular recycling? Should this email be sent through this communication method? Can this information remain visible at the workstation? Does this employee need access to this part of the system? Is it appropriate to discuss this patient information where others may hear it?
Those decisions happen constantly.
A practice can have strong HIPAA policies and still create exposure if employees do not recognize that the information in front of them is protected.
This is also why information handling should be considered across the entire practice rather than assigned only to clinical staff. Registration, scheduling, billing, administrative, and management employees may handle PHI even when they never document a diagnosis or participate directly in treatment.
Protect the Information Throughout Its Lifecycle
Once the practice recognizes where PHI exists, the next question is how that information moves through the organization.
The practice should consider how PHI is collected or received, accessed, used, disclosed, communicated, stored, retained, and eventually disposed of throughout its lifecycle.
Operational Snapshot
Privacy controls are strongest when mapped to information flows rather than job titles or departments. Following patient information from intake through communication, billing, retention, and disposal can reveal handoffs and temporary storage points that a system-by-system review may overlook.
Access to PHI should be appropriate to each workforce member’s responsibilities and the practice’s applicable access-control procedures. Electronic information should be handled through approved systems and safeguards. Printed information should not remain unnecessarily exposed.
Patient communications should follow the practice’s established privacy and security procedures. When PHI has reached the end of its applicable retention period and is appropriate for disposal, the practice should follow its established disposal procedures and use methods that reasonably protect the information from unauthorized access, consistent with HHS guidance on PHI disposal.
These controls are more effective when employees understand why they exist.
Telling someone to lock a screen is a rule. Helping them understand that an open patient schedule can expose identifiable healthcare information explains the risk the rule is designed to control.
Train Staff to Recognize Information, Not Just Acronyms
PII and PHI can easily become compliance vocabulary employees hear during training and rarely think about afterward.
The better approach is to connect those concepts to the information employees actually see.
Show front-office employees what PHI looks like at registration. Show clinical staff how temporary notes and patient communications should be handled. Help billing employees recognize protected information in reports and claims-related workflows. Include examples involving email, printers, workstations, patient portals, and telephone messages.
When employees understand the context, they are better equipped to recognize protected information even when it appears somewhere unexpected.
Operational Snapshot
A useful test of privacy training is whether employees can classify unfamiliar situations, not merely recall definitions. Scenario-based instruction gives staff a framework for recognizing risk when protected information appears in a new communication channel, report, device, or workflow that was never shown in the original training.
PII and PHI FAQs for Medical Practices
What is the difference between PII and PHI?
PII is a broad term for information that can identify or help identify an individual. PHI is individually identifiable health information protected under HIPAA in applicable covered-entity or business-associate contexts. The terms can overlap, but they are not interchangeable.
Is a patient’s name, phone number, or email address automatically PHI?
No. An identifier such as a name, phone number, or email address is not automatically PHI by itself. Whether it is PHI depends on the information associated with the identifier and the context in which a HIPAA covered entity or business associate handles it.
Is all health information considered PHI under HIPAA?
No. Information does not automatically become PHI simply because it concerns someone’s health. HIPAA’s PHI protections depend on factors including whether the information is individually identifiable and who creates, receives, maintains, or transmits it.
Can PHI exist outside a patient’s medical record?
Yes. PHI can appear in appointment schedules, emails, billing reports, printed documents, telephone messages, temporary notes, patient communications, and other workflows. Medical practices should consider how PHI moves through the entire organization rather than focusing only on the EHR.
What are the 18 HIPAA identifiers?
The 18 identifier categories are part of HIPAA’s Safe Harbor method for de-identifying health information. They include categories such as names, certain dates and geographic information, telephone numbers, email addresses, Social Security numbers, medical record numbers, and other identifying information. Their presence alone is not a universal test for determining whether information is PHI.
How should medical practices train employees to recognize PHI?
Training should connect HIPAA concepts to the information employees encounter during actual work. Examples involving registration, scheduling, email, printed documents, billing reports, patient portals, workstations, and telephone messages can help staff recognize protected information and follow the practice’s procedures for handling it.
Recognizing PHI Is the First Step Toward Protecting It
Understanding the distinction between PII and PHI gives medical practices a practical foundation for protecting patient information. The objective is not for staff to become experts in privacy terminology. It is for them to recognize when the information they are handling may be protected and understand the practice’s procedures for handling it. They should also know when to escalate questions rather than making assumptions.
PHI does not live exclusively inside the medical record. It follows patient information through the workflows surrounding care. Practices that understand where that information appears—and train staff accordingly—are in a much stronger position to protect it consistently.
About the Author
Jennifer Blevens-Smith is the founder and principal consultant of Integral Clinic Solutions. With more than two decades of experience supporting independent medical practices, she helps physicians, practice administrators, and healthcare leaders strengthen credentialing, payer contracting, revenue cycle operations, compliance workflows, and practice management. Her work focuses on translating complex healthcare requirements into practical operational processes. These processes improve consistency, reduce administrative burden, and support long-term practice success.
Need Help Strengthening Your Medical Practice Operations?
Integral Clinic Solutions provides practical support for medical practices navigating credentialing, contracting, revenue cycle operations, compliance workflows, front-office systems, and practice management challenges.
Explore more operational guidance, compliance insights, and healthcare business resources on the Integral Clinic Solutions blog. New articles and updates are added regularly for practice owners, administrators, and healthcare teams.
Disclaimer: This content is for informational and educational purposes only and does not constitute legal, coding, billing, compliance, financial, or medical advice. Healthcare practices must verify all operational requirements with applicable payers, regulators, and qualified professionals. Read our full Legal & Compliance Disclaimer.