What Are Patient Identifiers Under HIPAA?

Protect Patient Data and Avoid Costly HIPAA Violations

We handle all 18 patient identifiers confidently, so you can focus on patient care.

Patient Identifiers for HIPAA compliance discussed by doctor reviewing patient records with individual in clinic
Table of Contents

Healthcare organizations handle enormous amounts of sensitive personal information every single day. Protecting that information is not just a moral responsibility; it is also a legal one. The Health Insurance Portability and Accountability Act (HIPAA), enacted by the U.S. Congress in 1996, established a national framework for safeguarding patient health information. At the very heart of this framework lies a critical concept: patient identifiers.

Understanding what patient identifiers are, why they matter, and how to handle them correctly can make the difference between a compliant, trustworthy healthcare organization and one that faces serious legal consequences.

What Is HIPAA and Why Does It Matter?

HIPAA means Health Insurance Portability and Accountability Act. The law was designed to accomplish two major goals:

  1. Ensure health insurance portability, allowing workers to keep their insurance when changing jobs.
  2. Protect the privacy and security of patient health information, preventing unauthorized access, use, or disclosure.

The Privacy Rule, which took effect in 2003, is the section of HIPAA that directly governs how Protected Health Information (PHI) must be handled. The Security Rule, finalized in the same year, focuses specifically on electronic PHI (ePHI). Together, these rules apply to what HIPAA calls covered entities, including healthcare providers, health plans, and healthcare clearinghouses, as well as their business associates.

Violations of HIPAA can result in civil monetary penalties ranging from $100 to $50,000 per violation, with annual caps of up to $1.5 million per violation category. Criminal penalties can even include imprisonment in the most severe cases. The stakes are genuinely high, which is exactly why understanding patient identifiers is so important.

Related: Why is HIPAA Important for Medical Billing and Coding

What Is Protected Health Information (PHI)?

Protected Health Information PHI identifiers are the broader category that patient identifiers fall under. HIPAA defines PHI as any information that:

  1. Relates to an individual’s past, present, or future physical or mental health condition
  2. Relates to the provision of healthcare to an individual
  3. Relates to the past, present, or future payment for healthcare services
  4. Identifies or could reasonably be used to identify the individual

That last point is where patient identifiers come in. PHI is only considered “protected” when it contains information that can link the health data back to a specific person. Remove that link, and the information may no longer be protected under HIPAA.

PHI can exist in many forms, such as written records, electronic files, verbal conversations, and even images or videos. As long as identifiable information is attached to health-related data, HIPAA rules apply.

The 18 HIPAA Patient Identifiers

The HIPAA Privacy Rule lists exactly 18 types of patient identifiers that identifies a patient’s information that is subject to HIPAA protections. These examples of patient identifiers are comprehensive and deliberately broad, covering nearly every way someone could be identified from a healthcare record.

Let’s explore HIPAA 18 identifiers in detail:

Infographic for Hipaa 18 Identifiers

1. Names

This identifier covers a patient’s full name, first name, last name, maiden name, or any combination. Names are the most obvious way to identify a person, so HIPAA treats them as a primary identifier. Even a first name paired with health information can be enough to constitute PHI.

2. Geographic Data (Smaller than State Level)

Geographic information that is more specific than a state falls under this category. It includes:

  1. Street addresses
  2. Cities and towns
  3. Counties
  4. Zip codes (with an important exception: the first three digits of a zip code may be retained if the geographic area they cover contains more than 20,000 people)
  5. Equivalent geocodes

The rationale here is straightforward: combining a small town or neighborhood with a health condition can easily point to a specific person, especially in rural areas.

3. Dates (Except Year)

All dates that are directly related to an individual, except for the year, must be removed. It includes:

  1. Birth dates
  2. Admission dates
  3. Discharge dates
  4. Death dates
  5. Treatment dates

There is a special rule for individuals aged 90 years or older: their exact age, birth year, and any date elements that could reveal their precise age must all be removed, since very advanced age itself can be identified in smaller populations.

4. Phone Numbers

Both personal and professional phone numbers are protected under HIPAA. It includes landlines, cell phone numbers, fax numbers, and any other telephonic contact information tied to the patient.

5. Fax Numbers

Even though fax technology may seem outdated, many healthcare organizations still use it. Fax numbers are listed separately from phone numbers and must be treated with the same level of care, as they can directly link communications to a patient.

6. Email Addresses

A patient’s email address is a unique identifier in the digital age. Since emails can contain health-related correspondence or be used to retrieve medical records, they are firmly included in the list of protected identifiers.

7. Social Security Numbers (SSNs)

The Social Security Number is one of the most sensitive identifiers on the list. Because SSNs are used across financial, governmental, and healthcare systems, their exposure puts patients at serious risk of identity theft in addition to privacy violations.

8. Medical Record Numbers

Healthcare organizations assign medical record numbers (MRNs) to track a patient’s records internally. Because each MRN links directly to a specific individual within that organization’s system, it qualifies as a protected identifier even though it may seem like an internal administrative number.

9. Health Plan Beneficiary Numbers

Health insurance companies assign beneficiary numbers to plan members for identification and claims processing. These numbers are directly tied to an individual’s identity and insurance coverage, making them a protected identifier under HIPAA.

10. Account Numbers

Bank account numbers, health savings account numbers, and any other financial account numbers associated with a patient are protected. These are included because financial information, when combined with health data, can expose individuals to fraud or discrimination.

11. Certificate and License Numbers

This category covers any professional or personal certificates and licenses tied to the individual, such as a medical professional’s license number if they are also a patient, or a driver’s license number. These numbers serve as unique government-issued identifiers.

12. Vehicle Identifiers and Serial Numbers

License plate numbers, vehicle identification numbers (VINs), and similar vehicle-related data are included because they can be cross-referenced with public records to identify a person, particularly if combined with health or location data.

13. Device Identifiers and Serial Numbers

Serial numbers and unique identifiers from medical devices, computers, or other equipment assigned to a patient can be used to trace back to that individual. As connected health devices become more common, this identifier grows increasingly important.

14. Web URLs

Website addresses or URLs that are specific to a patient, such as a link to a patient portal profile or a personalized healthcare URL, can serve as identifiers and are therefore protected.

15. IP Addresses

An Internet Protocol (IP) address can reveal a user’s approximate geographic location and be traced back to a specific device or household. When IP addresses appear in healthcare system logs or patient records, they must be removed to de-identify data.

16. Biometric Identifiers

This category covers biological measurements that are unique to each individual, including:

  1. Fingerprints
  2. Retinal scans
  3. Voiceprints
  4. Facial geometry data

Biometric data is particularly sensitive because, unlike passwords or account numbers, a person cannot change their biometrics if they are compromised.

17. Full Face Photographs and Comparable Images

Full face photographs, X-rays, MRI scans, or any other image from which an individual’s face or distinctive physical features can be identified are protected. It is especially relevant in the age of facial recognition technology.

18. Any Other Unique Identifying Numbers, Characteristics, or Codes

The final identifier acts as a catch-all provision. Any other unique number, code, or characteristic, whether assigned by a government entity, an employer, a healthcare system, or even a third party, that could be used to identify a patient must also be treated as PHI. It ensures that organizations cannot sidestep HIPAA by inventing new types of identifiers that weren’t anticipated when the law was written.

Why Are These 18 Identifiers So Important?

The inclusion of these specific 18 identifiers serves a very deliberate purpose. The U.S. Department of Health and Human Services (HHS) designed this list to ensure that data cannot be reidentified through creative combinations of seemingly harmless details.

A powerful example of this concern comes from research by Professor Latanya Sweeney, who famously demonstrated that 87% of the U.S. population could be uniquely identified using only three data points: zip code, birth date, and gender. None of those three pieces of information sounds especially sensitive on its own. Yet together, they can pinpoint a specific individual with alarming accuracy. It is precisely why HIPAA takes such a thorough approach to its list of identifiers.

Related: How to Maintain Patient Privacy in Healthcare?

The Two Paths to De-Identification Under HIPAA

Organizations that want to use or share health data for research, public health purposes, or other secondary uses have two officially recognized methods to de-identify that data under HIPAA:

Method 1: Expert Determination

The Expert Determination method allows a qualified statistician or expert in data privacy to apply generally accepted statistical and scientific principles to verify that the risk of identifying any individual from the data is very small. The expert must document the methods and results of their analysis.

This approach is more flexible than Safe Harbor and may allow for the retention of some data elements, but it requires formal expertise and thorough documentation.

Method 2: The Safe Harbor Method

Under the Safe Harbor method, an organization must remove all 18 of the patient identifiers listed above from the data set. Additionally, the organization must have no actual knowledge that the remaining information could be used to identify any individual.

This method is straightforward and widely used, though it can sometimes result in the removal of data points that might otherwise be useful for research.

What Happens When PHI Is Not Properly Protected?

When organizations fail to handle patient identifiers and PHI properly, the consequences can be far-reaching:

  1. Financial penalties. The Office for Civil Rights (OCR) within HHS enforces HIPAA and can impose significant fines.
  2. Reputational damage: A data breach involving patient information can permanently damage a healthcare organization’s reputation and patient trust.
  3. Criminal charges. In cases of intentional misuse of PHI, individuals can face criminal prosecution, including imprisonment.
  4. Corrective Action Plans (CAPs) OCR may require organizations to implement comprehensive compliance programs under close federal oversight.

How Organizations Should Handle Patient Identifiers

Building a culture of compliance around patient identifiers requires both technical safeguards and administrative practices. Here are the most effective approaches:

Technical Safeguards

  1. Encryption: All electronic PHI should be encrypted both in transit and at rest using industry-standard protocols.
  2. Access controls: Only authorized personnel should have access to records containing patient identifiers.
  3. Audit logs: Systems should automatically log who accesses PHI, when they access it, and what they do with it.
  4. Automatic logoff: Workstations and applications that contain PHI should log users out after a period of inactivity.

Administrative Safeguards

  1. HIPAA training: Every member of the workforce who handles PHI should receive regular, comprehensive training on the 18 identifiers and proper handling procedures.
  2. Privacy policies: Organizations should maintain clear, written policies that specify how PHI is collected, used, stored, and disclosed.
  3. Business Associate Agreements (BAAs). Any third-party vendor that handles PHI on behalf of a covered entity must sign a BAA, making them contractually responsible for HIPAA compliance.

    4. Risk assessments: Regular security risk assessments help organizations identify vulnerabilities in their handling of PHI before they become breaches.

Physical Safeguards

  1. Secure workstations: Computer screens displaying PHI should not be visible to unauthorized individuals.
  2. Locked filing cabinets: Physical records containing patient identifiers must be stored securely.
  3. Visitor controls: Areas where PHI is handled should have access restrictions for non-staff visitors.

How Organizations Should Handle Patient Identifiers

The rise of telehealth, wearables, health apps, and AI-powered diagnostics has created new challenges for HIPAA compliance. Patient identifiers now appear in more places than ever before:

  1. Wearable health devices collect continuous biometric data, including identifiers like heart rate patterns tied to specific users.
  2. Telehealth platforms transmit video, audio, and text containing PHI across digital channels.
  3. Health apps often collect location data, device identifiers, and personal information that can constitute PHI if linked to health conditions.
  4. AI systems trained on medical records may inadvertently “memorize” patient identifiers during training.

The 21st Century Cures Act and evolving HHS guidance continue to clarify how HIPAA applies in these digital contexts. Healthcare organizations and technology companies alike must stay current with these developments to remain compliant.

One particularly important area is cloud computing. When PHI is stored or processed in the cloud, the cloud service provider typically becomes a business associate and must comply with HIPAA requirements. Organizations must ensure that cloud platforms are configured with appropriate security controls and that proper BAAs are in place.

An infographic mentioning Misconceptions About HIPAA Patient Identifiers

A Practical Guide to Checking Your Own Compliance

If you work in a healthcare organization or handle PHI in any capacity, these practical steps can help you assess your current standing with respect to patient identifiers:

  1. Inventory your data. Identify every location where PHI is stored, processed, or transmitted, including paper records, electronic systems, emails, and cloud platforms.
  2. Review your policies. Confirm that your organization’s written policies specifically address all 18 patient identifiers and the conditions under which PHI may be used or disclosed.
  3. Audit access controls. Verify that only the people who genuinely need access to PHI have it, and that access is logged and monitored.
  4. Check your vendor agreements. Make sure Business Associate Agreements are in place with every third party that handles PHI on your behalf.
  5. Train your team. Ensure that all employees who encounter PHI have received recent, documented HIPAA training that includes the 18 identifiers.
  6. Test your de-identification process. If you share data for research or analytics purposes, verify that your de-identification process removes all 18 identifiers and meets HIPAA’s Safe Harbor or Expert Determination standards.

Final Thoughts

Patient identifiers under HIPAA represent far more than just a regulatory checklist. They reflect a fundamental commitment to human dignity, personal privacy, and trust in the health care system. When patients share their most intimate health information with doctors, hospitals, and insurers, they deserve confidence that this information will be handled with the utmost care.

The 18 identifiers defined by HIPAA give healthcare organizations a clear, actionable framework for protecting that trust. By understanding each identifier, implementing strong safeguards, training staff thoroughly, and staying current with evolving regulations and technologies, organizations can not only stay compliant but they can also build the kind of patient-centered culture that truly puts people first.

HIPAA compliance is not a destination; it is an ongoing practice. And that practice starts with knowing exactly what you are protecting.

FAQs

Patient identifiers are pieces of information, like names, dates of birth, addresses, phone numbers, or medical record numbers, that can identify a person. They are protected under HIPAA to keep health information private and secure.

Acceptable patient identifiers include name, date of birth, address, phone number, email, medical record number, and insurance ID. These are used to accurately identify patients while ensuring compliance with privacy laws and safeguarding sensitive health information.

EZ MD Solutions protects patient identifiers through encryption, secure servers, strict access controls, and staff training. These measures ensure only authorized users can access sensitive data and help prevent breaches, unauthorized disclosure, or misuse of patient information.

Patient identifiers are any data elements that can identify an individual, such as name, Social Security number, address, phone number, email, medical record number, or biometric data. Even combinations of indirect data can reveal a patient’s identity.

PHI, or Protected Health Information, refers to any information about a patient’s health condition, treatment, or payment that can be linked to an identifiable individual. It includes medical records, billing details, and personal identifiers in any form.

HIPAA covers PHI in all formats, including electronic records, paper files, and oral communications. Whether information is stored digitally, written in documents, or discussed verbally, it must be protected under HIPAA regulations.

Yes, this is considered PHI because the individual’s name and phone number are linked to seeking healthcare services. Even basic contact details become protected when associated with medical care or appointment scheduling.

Yes, a medical record number is considered PHI because it uniquely identifies a patient within a healthcare system. When associated with health information, it directly links data to an individual and must be securely protected.

Any information that identifies an individual and relates to their health condition, treatment, or payment is considered PHI. This includes demographic details when combined with medical data, regardless of whether it is stored electronically, physically, or shared verbally.

HIPAA specifies 18 patient identifiers that are used to determine whether information is considered Protected Health Information (PHI). When de-identifying data using the Safe Harbor method, all 18 identifiers must be removed to ensure the information cannot be linked back to an individual.

Spread The Knowledge
Written by
Related Blogs
Contact Us
Stop PHI Breaches Before They Happen

We ensure your billing is secure and compliant, so patient data stays safe.

Need Help Manage Your
Practice Needs?

Complete the form, and our expert team will reach out to understand your unique needs and provide tailored solutions to drive your practice’s success.

Let’s discuss together.

💼 Looking for a Job?

Apply Now →