What are the 18 PHI identifiers?

by

The 18 PHI identifiers under HIPAA are names, geographic data smaller than a state, dates (except year), phone numbers, fax numbers, email addresses, Social Security numbers, medical record numbers, health plan beneficiary numbers, account numbers, certificate/license numbers, vehicle identifiers, device identifiers, web URLs, IP addresses, biometric identifiers, full-face photos, and unique codes or characteristics. The 18 specific identifiers are explicitly named as personal data points that must be protected or removed to de-identify information. However, these 18 identifiers are not a comprehensive list; other types of information can also be considered PHI when they are tied to health data. Below is a detailed overview of the 18 identifiers and examples of other types of PHI.

Full List of 18 PHI Identifiers Under HIPAA

  1. Names: Full names, initials, and nicknames associated with an individual.
  2. Geographic Subdivisions: Data smaller than a state, including city, county, street address, and most ZIP codes (unless the ZIP code covers a population of 20,000 or more).
  3. Dates: Birthdates, admission dates, discharge dates, and death dates (except for the year). For individuals over 89, even the year is considered identifiable unless aggregated.
  4. Phone Numbers: Personal, home, mobile, or work phone numbers.
  5. Fax Numbers: Fax numbers that can identify an individual.
  6. Email Addresses: Any email address linked to a specific person.
  7. Social Security Numbers (SSNs): Full or partial Social Security numbers.
  8. Medical Record Numbers: Unique numbers assigned to a patient’s medical records.
  9. Health Plan Beneficiary Numbers: Identifiers linked to health insurance accounts or benefits.
  10. Account Numbers: Bank account details or other financial accounts.
  11. Certificate/License Numbers: Professional, medical, or other licenses associated with the individual.
  12. Vehicle Identifiers: License plate numbers, vehicle registration details, and VINs.
  13. Device Identifiers: Serial numbers or identifiers of medical or personal devices.
  14. Web URLs: Website addresses tied to a specific individual.
  15. IP Addresses: Unique IP addresses of devices used by the individual.
  16. Biometric Identifiers: Fingerprints, voiceprints, retinal scans, and facial geometry.
  17. Full-Face Photographic Images: Photographs that reveal the entire face or comparable visual features.
  18. Unique Codes: Any unique identifying characteristic or code assigned to an individual.

Examples of Other Types of PHI

While HIPAA specifies the 18 identifiers for de-identification, other types of data can also qualify as PHI if combined with health-related information. Below are 30 common examples of data points that may be considered PHI when they are linked to an individual’s healthcare:

  1. Gender combined with a rare disease.
  2. Marital status and healthcare history.
  3. Job title and a diagnosis.
  4. Genetic test results not categorized under biometric identifiers.
  5. Insurance claim history.
  6. Prescription details tied to a patient.
  7. Treatment plans.
  8. Clinical visit summaries.
  9. Emergency contact information.
  10. Caregiver names and roles.
  11. Medication dosages.
  12. Imaging results like X-rays or MRIs.
  13. Pathology slides or reports.
  14. Discharge summaries.
  15. Laboratory test results (e.g., blood work, urine tests).
  16. Mental health therapy notes.
  17. Surgical records.
  18. Allergy information.
  19. Immunization history.
  20. Hospital admission records.
  21. Billing or payment information tied to healthcare.
  22. Rehabilitation progress notes.
  23. Risk assessment scores.
  24. Nutritional consultation details.
  25. Medical appointment calendars.
  26. Patient-reported symptoms.
  27. Ancestry details linked to health conditions.
  28. Family medical histories.
  29. Remote monitoring data from wearable devices.
  30. Data collected from patient satisfaction surveys.

These examples show the breadth of data that can qualify as PHI, even if they do not fall under the formal list of 18 HIPAA identifiers. HIPAA’s strict guidelines ensure that any information capable of identifying a patient is adequately safeguarded. The 18 identifiers provide a foundation for de-identifying health data, but the broader context of healthcare requires vigilance in handling any information tied to an individual’s medical records. By understanding the full scope of PHI, organizations can implement better safeguards, avoid breaches, and ensure compliance with regulatory standards.

James Keogh

James Keogh has been writing about the healthcare sector in the United States for several years and is currently the editor of HIPAAnswers. He has a particular interest in HIPAA and the intersection of healthcare privacy and information technology. He has developed specialized knowledge in HIPAA-related issues, including compliance, patient privacy, and data breaches. You can follow James on Twitter https://x.com/JamesKeoghHIPAA and contact James on LinkedIn https://www.linkedin.com/in/james-keogh-89023681 or email directly at [email protected]