If you ask most people to name all of the protected patient identifiers necessary for HIPAA compliance, they can probably name a few, such as a person's name, date of birth, and Social Security number. However, they would likely miss the fact that there are 18 HIPAA identifiers which require protection and/or de-identification by organizations for proper compliance with HIPAA regulations.
This article explains the complete HIPAA PHI identifier list, common exceptions to the HIPAA identifier rules, and how to achieve compliance through HIPAA training for data handlers in your organization.
Table of Contents
- What Are the 18 HIPAA Identifiers?
- The Role of Identifiers in PHI vs. Individually Identifiable Health Information (IIHI)
- Why the 18 HIPAA Identifiers Must Be Removed for Safe Harbor De-Identification
- Understanding the 18th Identifier: The HIPAA "Catch-All" Rule
- Common Exceptions to HIPAA Identifier Rules (ZIP Codes and Dates)
- HIPAA Identifiers vs. Clinical Patient Identifiers
- Ensuring Compliance Through HIPAA Training for Data Handlers
What Are the 18 HIPAA Identifiers?
The 18 HIPAA identifiers are the specific categories of information that, when attached to health data, make that data protected health information (PHI) under 45 CFR §164.514(b). They are defined by the Department of Health and Human Services (HHS) as the data points that must be removed before health information can be considered de-identified and therefore exempt from HIPAA's Privacy Rule protections.
Think of the 18 identifiers as a checklist for a data custodian reviewing a health dataset: if any one of these elements is present and can reasonably be used to identify an individual, the entire dataset is PHI and subject to HIPAA's full protections.
The Complete HIPAA Identifiers List
The following list presents all 18 HIPAA patient identifiers as defined under the Safe Harbor de-identification standard. This list is consistent with guidance from Loyola University Chicago and the University of Michigan Medical School.
- Names
- All geographic subdivisions smaller than a state, including street address, city, county, precinct, ZIP code, and equivalent geocodes
- All elements of dates (except birth year) directly related to an individual, including birth date, admission date, discharge date, and date of death
- Telephone numbers
- Fax numbers
- Email addresses
- Social Security numbers
- Medical record numbers
- Health plan beneficiary numbers
- Account numbers
- Certificate/license numbers
- Vehicle identifiers and serial numbers, including license plate numbers
- Device identifiers and serial numbers
- Web URLs
- Internet Protocol (IP) address numbers
- Biometric identifiers, including finger and voice prints
- Full-face photographic images and comparable images
- Any other unique identifying number, characteristic, or code
Why They Matter for PHI
Some of this information may feel trivial and insignificant; yet everything in the HIPAA identifiers list is considered PHI under HIPAA regulations since any of these can be used to identify an individual in a health data set. It is crucial to protect and, when required, de-identify these identifiers for individuals receiving any sort of health service by a covered entity or business associate. Data handlers, IT teams, and privacy officers need to understand the full scope of terms that must be removed to satisfy HIPAA regulations for Safe Harbor de-identification.
The Role of Identifiers in PHI vs. Individually Identifiable Health Information (IIHI)
Identifiers are a key piece of determining whether health information is categorically protected (PHI) or not. Individually Identifiable Health Information (IIHI) is a broader category of any health information that can be used to identify a person. This can be anything from a surgical report to health information collected by a fitness tracker. IIHI does not always fall under HIPAA protections because it does not always qualify as PHI.
So what makes something PHI? Put simply, PHI is IIHI that:
- Contains one of the 18 HIPAA identifiers.
- Is transmitted or maintained by a HIPAA-covered entity (or business associate).
In order to be considered PHI and be governed by HIPAA laws, the health information being held or transmitted must include at least one of the 18 listed identifiers.
Why the 18 HIPAA Identifiers Must Be Removed for Safe Harbor De-Identification
HIPAA recognizes two approved methods for de-identifying protected health information: the Safe Harbor Method and the Expert Determination Method. The Safe Harbor Method is by far the most commonly used because it provides a straightforward checklist that organizations can follow.
Under the Safe Harbor Method, covered entities and business associates must remove all 18 HIPAA identifiers before information is considered de-identified. Once those identifiers are removed—and the organization has no actual knowledge that the remaining information could identify an individual—the data is no longer considered PHI under HIPAA.
This approach allows healthcare organizations to use data for research, quality improvement, public health reporting, and analytics without violating HIPAA's Privacy Rule, provided all Safe Harbor requirements have been met.
Safe Harbor vs. Expert Determination
While Safe Harbor requires removal of the 18 identifiers, the Expert Determination Method allows a qualified expert to certify that the risk of re-identification is very small, even if some identifiers remain. This method is typically used for research projects or large datasets where removing every identifier would significantly reduce the usefulness of the information.
Most organizations rely on Safe Harbor because it is easier to apply consistently and provides clear regulatory guidance.
Understanding the 18th Identifier: The HIPAA "Catch-All" Rule
The eighteenth identifier is often the most misunderstood because it is intentionally broad:
"Any other unique identifying number, characteristic, or code."
This provision exists because technology changes faster than regulations. Rather than trying to predict every possible identifier that could exist in the future, HIPAA includes a catch-all provision to cover anything that could reasonably identify an individual.
Examples might include:
- Unique employee identification numbers
- Custom patient tracking codes
- Internal database identifiers that can be linked back to an individual
- Unique research participant codes when a re-identification key exists
If a value can reasonably be used to identify someone, directly or indirectly, it should generally be treated as protected unless an approved de-identification method has been applied.
Common Exceptions to HIPAA Identifier Rules (ZIP Codes and Dates)
Although the Safe Harbor rules appear straightforward, two identifiers have important exceptions that organizations frequently overlook.
ZIP Code Exception
HIPAA does not require every ZIP code to be removed completely.
The first three digits of a ZIP code may remain if the geographic area formed by those first three digits contains more than 20,000 people. If the population is 20,000 or fewer, those first three digits must be changed to "000."
Date Exception
Dates receive similar treatment.
All elements of dates directly related to an individual must be removed except the year. For example:
- Birth year may remain.
- Birth month and day must be removed.
- Admission and discharge years may remain.
- Admission and discharge month and day must be removed.
Ages over 89 require additional protection. Individuals age 90 and older must generally be grouped into a single category of "90 or older" to reduce the risk of identification.
HIPAA Identifiers vs. Clinical Patient Identifiers
Healthcare professionals sometimes confuse HIPAA identifiers with clinical patient identifiers used inside electronic health record (EHR) systems.
Clinical identifiers—such as medical record numbers, encounter numbers, or patient account numbers—help healthcare providers distinguish one patient from another during treatment. Some of these are included in HIPAA's list of identifiers, but many clinical identifiers exist solely for operational purposes.
The important distinction is that HIPAA focuses on whether information can identify an individual outside the treatment context. Even seemingly harmless internal identifiers may become PHI if they can be linked back to a specific patient.
Ensuring Compliance Through HIPAA Training for Data Handlers
Understanding the 18 HIPAA identifiers is only one part of maintaining compliance. Employees who create, access, store, transmit, or dispose of protected health information should receive regular HIPAA training so they understand how to recognize PHI, safeguard sensitive information, and respond appropriately when handling patient data.
Effective HIPAA training helps organizations reduce the risk of unauthorized disclosures, improve day-to-day compliance practices, and ensure employees understand their responsibilities under the HIPAA Privacy, Security, and Breach Notification Rules.
Whether you're onboarding new staff or providing annual refresher training, educating your workforce is one of the most effective ways to reduce compliance risks and protect patient privacy.
If your organization needs compliant, self-paced online education, HIPAA Exams' online HIPAA training courses provide an easy way for employees to build and maintain HIPAA knowledge.
Protect Patient Data With HIPAA Training
The HIPAA identifiers list serves as the foundation for determining whether health information qualifies as protected health information under HIPAA. Understanding all 18 identifiers—and the limited exceptions that apply—is essential for anyone responsible for handling patient information.
By combining a strong understanding of HIPAA requirements with ongoing employee education, organizations can better safeguard patient privacy while reducing compliance risks.
Explore HIPAA training from HIPAA Exams to help your team stay current on HIPAA requirements and best practices.
Resources
U.S. Department of Health & Human Services. Guidance Regarding Methods for De-identification of Protected Health Information in Accordance with the HIPAA Privacy Rule.
https://www.hhs.gov/hipaa/for-professionals/privacy/special-topics/de-identification/
Loyola University Chicago. The 18 HIPAA Identifiers.
https://www.luc.edu/its/aboutus/itspoliciesguidelines/hipaainformation/the18hipaaidentifiers/
University of Michigan Medical School. HIPAA Identifiers.
https://az.research.umich.edu/medschool/glossary/hipaa-identifiers/