Protect Patient Data and Avoid Costly HIPAA Violations
We handle all 18 patient identifiers confidently, so you can focus on patient care.
Healthcare organizations handle enormous amounts of sensitive personal information every single day. Protecting that information is not just a moral responsibility; it is also a legal one. The Health Insurance Portability and Accountability Act (HIPAA), enacted by the U.S. Congress in 1996, established a national framework for safeguarding patient health information. At the very heart of this framework lies a critical concept: patient identifiers.
Understanding what patient identifiers are, why they matter, and how to handle them correctly can make the difference between a compliant, trustworthy healthcare organization and one that faces serious legal consequences.
HIPAA means Health Insurance Portability and Accountability Act. The law was designed to accomplish two major goals:
The Privacy Rule, which took effect in 2003, is the section of HIPAA that directly governs how Protected Health Information (PHI) must be handled. The Security Rule, finalized in the same year, focuses specifically on electronic PHI (ePHI). Together, these rules apply to what HIPAA calls covered entities, including healthcare providers, health plans, and healthcare clearinghouses, as well as their business associates.
Violations of HIPAA can result in civil monetary penalties ranging from $100 to $50,000 per violation, with annual caps of up to $1.5 million per violation category. Criminal penalties can even include imprisonment in the most severe cases. The stakes are genuinely high, which is exactly why understanding patient identifiers is so important.
Related: Why is HIPAA Important for Medical Billing and Coding
Protected Health Information PHI identifiers are the broader category that patient identifiers fall under. HIPAA defines PHI as any information that:
That last point is where patient identifiers come in. PHI is only considered “protected” when it contains information that can link the health data back to a specific person. Remove that link, and the information may no longer be protected under HIPAA.
PHI can exist in many forms, such as written records, electronic files, verbal conversations, and even images or videos. As long as identifiable information is attached to health-related data, HIPAA rules apply.
The HIPAA Privacy Rule lists exactly 18 types of patient identifiers that identifies a patient’s information that is subject to HIPAA protections. These examples of patient identifiers are comprehensive and deliberately broad, covering nearly every way someone could be identified from a healthcare record.
Let’s explore HIPAA 18 identifiers in detail:
This identifier covers a patient’s full name, first name, last name, maiden name, or any combination. Names are the most obvious way to identify a person, so HIPAA treats them as a primary identifier. Even a first name paired with health information can be enough to constitute PHI.
Geographic information that is more specific than a state falls under this category. It includes:
The rationale here is straightforward: combining a small town or neighborhood with a health condition can easily point to a specific person, especially in rural areas.
All dates that are directly related to an individual, except for the year, must be removed. It includes:
There is a special rule for individuals aged 90 years or older: their exact age, birth year, and any date elements that could reveal their precise age must all be removed, since very advanced age itself can be identified in smaller populations.
Both personal and professional phone numbers are protected under HIPAA. It includes landlines, cell phone numbers, fax numbers, and any other telephonic contact information tied to the patient.
Even though fax technology may seem outdated, many healthcare organizations still use it. Fax numbers are listed separately from phone numbers and must be treated with the same level of care, as they can directly link communications to a patient.
A patient’s email address is a unique identifier in the digital age. Since emails can contain health-related correspondence or be used to retrieve medical records, they are firmly included in the list of protected identifiers.
The Social Security Number is one of the most sensitive identifiers on the list. Because SSNs are used across financial, governmental, and healthcare systems, their exposure puts patients at serious risk of identity theft in addition to privacy violations.
Healthcare organizations assign medical record numbers (MRNs) to track a patient’s records internally. Because each MRN links directly to a specific individual within that organization’s system, it qualifies as a protected identifier even though it may seem like an internal administrative number.
Health insurance companies assign beneficiary numbers to plan members for identification and claims processing. These numbers are directly tied to an individual’s identity and insurance coverage, making them a protected identifier under HIPAA.
Bank account numbers, health savings account numbers, and any other financial account numbers associated with a patient are protected. These are included because financial information, when combined with health data, can expose individuals to fraud or discrimination.
This category covers any professional or personal certificates and licenses tied to the individual, such as a medical professional’s license number if they are also a patient, or a driver’s license number. These numbers serve as unique government-issued identifiers.
License plate numbers, vehicle identification numbers (VINs), and similar vehicle-related data are included because they can be cross-referenced with public records to identify a person, particularly if combined with health or location data.
Serial numbers and unique identifiers from medical devices, computers, or other equipment assigned to a patient can be used to trace back to that individual. As connected health devices become more common, this identifier grows increasingly important.
Website addresses or URLs that are specific to a patient, such as a link to a patient portal profile or a personalized healthcare URL, can serve as identifiers and are therefore protected.
An Internet Protocol (IP) address can reveal a user’s approximate geographic location and be traced back to a specific device or household. When IP addresses appear in healthcare system logs or patient records, they must be removed to de-identify data.
This category covers biological measurements that are unique to each individual, including:
Biometric data is particularly sensitive because, unlike passwords or account numbers, a person cannot change their biometrics if they are compromised.
Full face photographs, X-rays, MRI scans, or any other image from which an individual’s face or distinctive physical features can be identified are protected. It is especially relevant in the age of facial recognition technology.
The final identifier acts as a catch-all provision. Any other unique number, code, or characteristic, whether assigned by a government entity, an employer, a healthcare system, or even a third party, that could be used to identify a patient must also be treated as PHI. It ensures that organizations cannot sidestep HIPAA by inventing new types of identifiers that weren’t anticipated when the law was written.
The inclusion of these specific 18 identifiers serves a very deliberate purpose. The U.S. Department of Health and Human Services (HHS) designed this list to ensure that data cannot be reidentified through creative combinations of seemingly harmless details.
A powerful example of this concern comes from research by Professor Latanya Sweeney, who famously demonstrated that 87% of the U.S. population could be uniquely identified using only three data points: zip code, birth date, and gender. None of those three pieces of information sounds especially sensitive on its own. Yet together, they can pinpoint a specific individual with alarming accuracy. It is precisely why HIPAA takes such a thorough approach to its list of identifiers.
Organizations that want to use or share health data for research, public health purposes, or other secondary uses have two officially recognized methods to de-identify that data under HIPAA:
The Expert Determination method allows a qualified statistician or expert in data privacy to apply generally accepted statistical and scientific principles to verify that the risk of identifying any individual from the data is very small. The expert must document the methods and results of their analysis.
This approach is more flexible than Safe Harbor and may allow for the retention of some data elements, but it requires formal expertise and thorough documentation.
Under the Safe Harbor method, an organization must remove all 18 of the patient identifiers listed above from the data set. Additionally, the organization must have no actual knowledge that the remaining information could be used to identify any individual.
This method is straightforward and widely used, though it can sometimes result in the removal of data points that might otherwise be useful for research.
When organizations fail to handle patient identifiers and PHI properly, the consequences can be far-reaching:
Building a culture of compliance around patient identifiers requires both technical safeguards and administrative practices. Here are the most effective approaches:
4. Risk assessments: Regular security risk assessments help organizations identify vulnerabilities in their handling of PHI before they become breaches.
The rise of telehealth, wearables, health apps, and AI-powered diagnostics has created new challenges for HIPAA compliance. Patient identifiers now appear in more places than ever before:
The 21st Century Cures Act and evolving HHS guidance continue to clarify how HIPAA applies in these digital contexts. Healthcare organizations and technology companies alike must stay current with these developments to remain compliant.
One particularly important area is cloud computing. When PHI is stored or processed in the cloud, the cloud service provider typically becomes a business associate and must comply with HIPAA requirements. Organizations must ensure that cloud platforms are configured with appropriate security controls and that proper BAAs are in place.
If you work in a healthcare organization or handle PHI in any capacity, these practical steps can help you assess your current standing with respect to patient identifiers:
Patient identifiers under HIPAA represent far more than just a regulatory checklist. They reflect a fundamental commitment to human dignity, personal privacy, and trust in the health care system. When patients share their most intimate health information with doctors, hospitals, and insurers, they deserve confidence that this information will be handled with the utmost care.
The 18 identifiers defined by HIPAA give healthcare organizations a clear, actionable framework for protecting that trust. By understanding each identifier, implementing strong safeguards, training staff thoroughly, and staying current with evolving regulations and technologies, organizations can not only stay compliant but they can also build the kind of patient-centered culture that truly puts people first.
HIPAA compliance is not a destination; it is an ongoing practice. And that practice starts with knowing exactly what you are protecting.
Patient identifiers are pieces of information, like names, dates of birth, addresses, phone numbers, or medical record numbers, that can identify a person. They are protected under HIPAA to keep health information private and secure.
Acceptable patient identifiers include name, date of birth, address, phone number, email, medical record number, and insurance ID. These are used to accurately identify patients while ensuring compliance with privacy laws and safeguarding sensitive health information.
EZ MD Solutions protects patient identifiers through encryption, secure servers, strict access controls, and staff training. These measures ensure only authorized users can access sensitive data and help prevent breaches, unauthorized disclosure, or misuse of patient information.
Patient identifiers are any data elements that can identify an individual, such as name, Social Security number, address, phone number, email, medical record number, or biometric data. Even combinations of indirect data can reveal a patient’s identity.
PHI, or Protected Health Information, refers to any information about a patient’s health condition, treatment, or payment that can be linked to an identifiable individual. It includes medical records, billing details, and personal identifiers in any form.
HIPAA covers PHI in all formats, including electronic records, paper files, and oral communications. Whether information is stored digitally, written in documents, or discussed verbally, it must be protected under HIPAA regulations.
Yes, this is considered PHI because the individual’s name and phone number are linked to seeking healthcare services. Even basic contact details become protected when associated with medical care or appointment scheduling.
Yes, a medical record number is considered PHI because it uniquely identifies a patient within a healthcare system. When associated with health information, it directly links data to an individual and must be securely protected.
Any information that identifies an individual and relates to their health condition, treatment, or payment is considered PHI. This includes demographic details when combined with medical data, regardless of whether it is stored electronically, physically, or shared verbally.
HIPAA specifies 18 patient identifiers that are used to determine whether information is considered Protected Health Information (PHI). When de-identifying data using the Safe Harbor method, all 18 identifiers must be removed to ensure the information cannot be linked back to an individual.
We ensure your billing is secure and compliant, so patient data stays safe.
EZ MD Solutions, LLC supports 75+ active US healthcare practices with a team of 200+ across the US, Latin America, and Asia.
sales@ezmdsolutions.com
Copyright © 2026. EZ MD Solutions. All Rights Reserved.| Privacy Policy | Terms of Service
Complete the form, and our expert team will reach out to understand your unique needs and provide tailored solutions to drive your practice’s success.
Let’s discuss together.