News
Do I Need a BAA With My Vendor? A Plain-English Guide to Which Vendors Require a Business Associate Agreement · Business AssociatesYour 'Success Story' Program Just Cost This Rehab Facility $182,000: The Cadia Healthcare HIPAA Settlement · OCR EnforcementAn Accounting Firm Just Paid a HIPAA Fine: BST and Co. CPAs and What It Means for Professional Services Firms · OCR Enforcement15 Million Records, a $10,000 Fine, and a Company That No Longer Exists: The MMG Fusion Story · OCR EnforcementOCR Creates Religious Discrimination Units: What the Restructuring Means for HIPAA Enforcement · Rule UpdateOCR Director: The Cost of Doing Nothing Is Very High · Rule UpdateHIPAA Victims May Soon Receive a Share of OCR Fines: What the Proposed Compensation Program Means · Rule UpdateOCR Restructured: Three New Divisions and What It Means for HIPAA Enforcement · Rule UpdateRehab Center Pays $103,000 After Phishing Attack: OCR's 11th Risk Analysis Enforcement Action · OCR EnforcementConcentra Pays $112,500 After Patient Made Six Records Requests Over 13 Months · OCR EnforcementHIPAA Security Rule Final Rule: May Deadline Passes With No Announcement · Rule UpdateDo I Need a BAA With My Vendor? A Plain-English Guide to Which Vendors Require a Business Associate Agreement · Business AssociatesYour 'Success Story' Program Just Cost This Rehab Facility $182,000: The Cadia Healthcare HIPAA Settlement · OCR EnforcementAn Accounting Firm Just Paid a HIPAA Fine: BST and Co. CPAs and What It Means for Professional Services Firms · OCR Enforcement15 Million Records, a $10,000 Fine, and a Company That No Longer Exists: The MMG Fusion Story · OCR EnforcementOCR Creates Religious Discrimination Units: What the Restructuring Means for HIPAA Enforcement · Rule UpdateOCR Director: The Cost of Doing Nothing Is Very High · Rule UpdateHIPAA Victims May Soon Receive a Share of OCR Fines: What the Proposed Compensation Program Means · Rule UpdateOCR Restructured: Three New Divisions and What It Means for HIPAA Enforcement · Rule UpdateRehab Center Pays $103,000 After Phishing Attack: OCR's 11th Risk Analysis Enforcement Action · OCR EnforcementConcentra Pays $112,500 After Patient Made Six Records Requests Over 13 Months · OCR EnforcementHIPAA Security Rule Final Rule: May Deadline Passes With No Announcement · Rule Update
Beginnerfront deskpractice managerprovidervendor

What patient information do we need to protect?

Understand what counts as protected health information in a real office, not just charts, but conversations, schedules, and more.

TL;DR

If information identifies a patient and relates to health, care, or payment for care, treat it as sensitive. That includes names plus diagnoses, appointment lists, insurance details, and much more.

Updated 2026-04-21

When people say protected health information (often shortened to PHI), they mean details that identify someone and connect to their health, treatment, or payment for care.

You do not need to recite a legal checklist at the front desk. You do need a gut sense: If a stranger could figure out who the patient is and learn something about their health or billing, you should protect it.

Everyday examples in a practice

Think about:

  • The schedule with patient names and visit reasons on screen.
  • A lab result left on a printer.
  • Insurance cards copied for billing.
  • Phone messages about test results.
  • Whiteboards with initials and room numbers that still make patients identifiable in context.

Even verbal updates in a hallway, "Mrs. Lee's MRI came back fine", can be a problem if others overhear.

The "identifiers" idea (without memorizing 18 items)

Regulations list many types of identifiers (name, address pieces, dates, phone numbers, and more). In practice, ask: Could someone use this piece of data, plus what we already show in the waiting room, to know exactly who we mean? If yes, slow down and protect it.

What about information with no name on it?

If data is stripped of identifiers using approved methods, it may no longer be PHI. That is a specialized process, do not assume removing a name is enough. Your privacy officer handles formal de-identification.

Paper, voice, and electronics all count

HIPAA is not an "electronic-only" rule. A paper intake form in a basket, a sticky note with a callback number and diagnosis, or a whiteboard in a shared break room can all create risk.

What vendors should remember

If your product stores names, clinical values, insurance IDs, or appointment metadata for a healthcare customer, assume you are handling PHI until counsel says otherwise, and expect BAAs and security controls to be non-negotiable.

Not legal advice. Educational overview only; consult qualified counsel for your situation.