Skip to main content

The 18 HIPAA Identifiers: What Counts as PHI in 2026

By Joseph Abear ·
HIPAA 18 Identifiers

Last updated: August 14, 2026

Protected health information (PHI) is health information tied to something that identifies a person. The "something" is defined by law: the 18 HIPAA identifiers listed in the Safe Harbor rule (45 CFR § 164.514(b)(2)). Most lists stop there. Here is the part that matters for anyone who runs a healthcare website. Two of the 18 HIPAA identifiers are URLs and IP addresses. Your website collects both automatically, on every visit. They sit in server logs and analytics tools you may never look at. This guide gives you the full list with plain examples. It covers the exceptions people get wrong, the two items your site logs on its own, and what to do about them.

TL;DR: Quick answer

  • Health information becomes PHI when it connects to any of the 18 HIPAA identifiers: names, dates, contact details, ID numbers, biometrics, photos, URLs, and IP addresses among them.

  • The list comes from the Safe Harbor rule (45 CFR § 164.514(b)(2)). Remove all 18 and the data is no longer PHI.

  • Identifiers 14 and 15 are URLs and IP addresses. Websites log both by default. That is how ad pixels on patient pages became a national enforcement issue.

  • Context decides. A name alone is not PHI. A name on a therapy practice's booking page is, because the page itself supplies the health context.

  • The list only binds covered entities and business associates. The same data in a consumer wellness app usually sits outside HIPAA entirely.

What is PHI, in plain terms

HIPAA 18 Identifiers what is PHI

Start with the legal frame. PHI is individually identifiable health information held or transmitted by a covered entity or its business associate, in any form (45 CFR § 160.103). Three pieces have to be present. Health information: something about a condition, care, or payment, past, present, or future. An identifier: something that ties it to a person. And the HIPAA context: a covered entity or business associate handling it. Strip any of the three and it is not PHI. That is why the myth "PHI means medical records" runs so wrong. An appointment reminder, a billing entry, an intake form, a voicemail, and a server log can all be PHI. The record format never decides. The three pieces do.

The 18 HIPAA identifiers, with everyday examples

HIPAA 18 Identifiers The List

The Safe Harbor rule lists the 18 HIPAA identifiers as the things you must remove to strip data of identity. Read the other way, it is the official list of what ties health data to a person.

#

Identifier

Everyday example

1

Names

Full names, initials, aliases

2

Geography smaller than a state

Street, city, county, zip code (see the zip exception below)

3

Dates (except year)

Birth, admission, discharge, death dates; all ages over 89

4

Telephone numbers

Any phone number on file

5

Fax numbers

Practice or patient fax lines

6

Email addresses

Personal or work email

7

Social Security numbers

Full or partial SSN

8

Medical record numbers

Chart and MRN numbers

9

Health plan beneficiary numbers

Insurance member IDs

10

Account numbers

Billing and patient account IDs

11

Certificate or license numbers

Driver's license, professional licenses

12

Vehicle identifiers

VINs and license plates

13

Device identifiers and serials

Implant serials, monitor device IDs

14

Web URLs

Portal links, tokenized file links

15

IP addresses

Logged by every website visit and telehealth session

16

Biometric identifiers

Fingerprints, voice prints

17

Full-face photos

And any comparable images

18

Any other unique identifier

Any number, characteristic, or code that points to one person

Two exceptions trip people up. Zip codes: the first three digits may stay in stripped data when that zip area holds more than 20,000 people. Smaller areas become 000. And ages: everything over 89 identifies, so stripped data groups those people as "90 or older." Precision like that is why guessing at the 18 HIPAA identifiers from memory goes badly.

The two identifiers your website collects automatically

HIPAA 18 Identifiers Two Automatic

Look at numbers 14 and 15 again. URLs and IP addresses. Now look at how a website works. Every visit writes the visitor's IP address into the server log. Every form submission records it. Analytics tools capture the URL of every page viewed. On an ordinary business site, that is routine plumbing. On a healthcare site, the context changes everything. An IP address logged on a therapy practice's booking page ties a real visitor to care-seeking. That pairing is exactly what OCR's tracking guidance addresses. It is how ad pixels on patient pages produced eight-figure settlements. The full story is in HIPAA tracking technologies. The practical rule: the 18 HIPAA identifiers do not live only in your charts. Two of them live in your web stack, collected by default. The systems logging them need the same protection as the chart. That is the standard our HIPAA compliant website guide maps requirement by requirement.

When identified health data is not PHI

HIPAA 18 Identifiers when not PHI

The list only matters inside HIPAA's reach. Three big carve-outs. First, the handler: HIPAA binds covered entities and business associates. The same symptom diary in a consumer wellness app usually sits outside HIPAA, a boundary we walk through in does HIPAA apply to coaches. Second, employment records: your employer's sick-leave file is not PHI, even though it names you and mentions health. Third, properly stripped data: remove all 18 and HIPAA no longer applies to it.

De-identification: the two legal paths

The law gives two routes to de-identification. The Safe Harbor method removes all 18 items and needs no statistician. That is why the list exists. The Expert Determination method lets a qualified expert certify that the risk of re-identifying people is very small. That path keeps more data for research. For most practices, Safe Harbor is the practical one, and the 18 HIPAA identifiers are its checklist.

Why the list is worth knowing cold

Because every HIPAA duty keys off it. Whether a message is PHI decides whether it needed encryption. Whether a log entry is PHI decides whether a vendor needed a BAA. Whether a spreadsheet is PHI decides whether losing the laptop was a reportable breach. The costs of getting it wrong are documented in our healthcare data breach statistics: the record years, the settlement amounts, and the 2026 penalty tiers from $145 to $2,190,294 per violation. Teams that can name the 18 HIPAA identifiers spot PHI in unexpected places. Teams that cannot end up learning it from an audit.

Where identifiers hide on your website, and the fix

HIPAA 18 Identifiers where they hide

Here is the honest pain point. Practices secure the chart system and forget the website. The website quietly collects the list all day. IPs in server logs. Emails and names in form submissions. Tokenized URLs in portal links. Appointment dates in booking confirmations. If those systems sit on a host with no BAA, every entry is exposure. We solve exactly that layer, so weigh this as a disclosure. Our client-side compliance review maps which of the 18 HIPAA identifiers your site actually collects, page by page, script by script. Our healthcare hosting puts the systems that log them under a BAA with encryption, access controls, and audit logs. Plans run from $79 per month self-managed to $229 per month managed, migration included. Ask us what your site collects and you will get a specific answer, not a scare.

Frequently asked questions

What are the 18 HIPAA identifiers?

They are the elements listed in the Safe Harbor rule at 45 CFR § 164.514(b)(2): names, sub-state geography, dates, phone, fax, email, SSN, medical record numbers, health plan numbers, account numbers, license numbers, vehicle identifiers, device identifiers, URLs, IP addresses, biometrics, full-face photos, and any other unique identifying code.

Is a name by itself PHI?

No. A name with no health context is just a name. It becomes PHI when it connects to health information, and context can supply that connection: a name on a treatment provider's intake list carries health meaning by itself.

Is an IP address really PHI?

It is one of the 18 HIPAA identifiers. So yes, when it pairs with health context inside a covered entity's or business associate's systems. An IP logged on a patient booking page is the standard example, and it is central to OCR's tracking-technology guidance.

What is the zip code exception?

De-identified data may keep the first three zip digits when that three-digit area contains more than 20,000 people. Areas at or below 20,000 must show 000 instead. Full five-digit zips are always identifiers.

Is de-identified data still protected by HIPAA?

No. Data de-identified under Safe Harbor or Expert Determination sits outside HIPAA. The catch is doing it properly. Miss one item, like a tokenized URL or an age of 91, and the data was never stripped at all.

Recap: the 18 HIPAA identifiers

To recap, PHI is health information plus any of the 18 HIPAA identifiers, handled by a covered entity or business associate. The list runs from names and dates through account numbers to biometrics, and it includes two web-native entries, URLs and IP addresses, that your website collects by default. Know the zip and age exceptions, remember that context can supply the health meaning, and treat the systems that log identifiers, your site included, like the PHI systems they are.

This article is general information, not legal advice. The identifier list reflects 45 CFR § 164.514(b)(2) as of August 2026; de-identification for research and edge cases deserves qualified counsel. Base your safeguards on a written risk analysis. We sell HIPAA compliant hosting and compliance reviews. Reviewed August 2026.

Sources