PrepSolution
PHRHigh-YieldTotal Rewards 15%
PHI rules + group health plan obligations

HIPAA Privacy and Security

1996

Year

Updated 2013 HITECH

18

PHI Identifiers

From name to biometrics

60

Days

Breach notification deadline

eighteen identifiers, one rule

The 18 PHI Identifiers

Combined with health information, any one of these makes the data PHI. Removing one identifier alone does NOT de-identify — Safe Harbor requires removing all 18.

01

Name

02

Address

03

Dates

04

Phone

05

Fax

06

Email

07

SSN

08

Med Record #

09

Health Plan #

10

Account #

11

License #

12

Vehicle ID

13

Device ID

14

URL

15

IP Address

16

Biometric

17

Full-face Photo

18

Other Unique

de-identification methods

Safe Harbor — remove all 18 identifiers. Expert Determination — qualified statistician verifies very small re-identification risk. Either method makes the data no longer PHI.

Two Rules + Breach Notification

privacy rule · 2003

Use and disclosure of PHI

Standards for who can see PHI and under what conditions. Minimum necessary applies.

security rule · 2005

Safeguarding ePHI

Administrative, physical, and technical safeguards for electronic PHI.

breach notification (HITECH 2009)

  • › Notify affected individuals within 60 days of discovery
  • › Notify HHS within 60 days for breaches of 500+ individuals
  • Media notification for breaches of 500+ in a single state
  • › Smaller breaches reported to HHS annually

Exam Traps

HIPAA does not gag the employer

It restricts the group HEALTH PLAN. The employer-as-employer is not a covered entity. Asking why someone was absent is not by itself a HIPAA violation.

"Minimum necessary" applies INSIDE HR too

Even within HR, only the minimum PHI required for the task can be accessed. Need-to-know controls.

Business Associate Agreements are required

Any vendor handling PHI on behalf of a covered entity needs a BAA. No BAA = the covered entity is liable for the vendor's breach.

State law can be stricter

HIPAA preempts LESS-stringent state law. More-stringent state privacy laws survive preemption. The strictest applicable rule controls.

Plan, not employer

HIPAA covers the group health plan. Not the employer-as-employer. The firewall matters.

BAA before access

No vendor touches PHI without a Business Associate Agreement signed first. Skipping the BAA is the breach.

1
The plan is the doctors office

Patient files (PHI) belong to the office. The office is a HIPAA covered entity.

2
The employer is the patients neighbor

Friendly, but does not work at the office. Asking how the patient is doing is not a HIPAA matter.

3
The office cannot share files with the neighbor

Without permission, no files cross the boundary. That is the firewall HIPAA enforces.

4
The billing service needs a contract

If the office hires a billing vendor, the office gets a Business Associate Agreement signed first. Now the vendor is bound by the same rules.

PHI is the file. Covered Entity is the office. BAA is the contract. Minimum Necessary is the rule.
reading is not enough, you gotta practice

Ready to test your PHR knowledge?

1,700+ practice questions written by certified professionals.

Start Practicing PHR
Reviewed by Sarah L., PrepSolution Content Editor, HR
Sources verified against HRCI 2026 standards
Updated May 2026