What Counts as Protected Health Information
Protected health information is any health data that can be linked back to a person, which is broader than most staff assume. A single name beside an appointment time qualifies. So does a room number on a whiteboard. The minimum necessary standard then limits access to what the task actually requires.
Almost every privacy incident in a clinical setting is a disclosure rather than a breach: a conversation in a corridor, a screen left facing a waiting area, a record opened out of curiosity about a colleague. None of those involves an attacker, and none is prevented by a technical control. What should never reach the published cut is real patient records: identifiers, appointment data, and screenshots of live systems must be replaced with fabricated examples before anything is used in training.
The template covers it in ten scenes: two on what qualifies as identifiable, two on the minimum necessary standard applied to everyday tasks, one on permitted disclosures, one on conversations in shared spaces, one on access logging and why curiosity is detectable, one on what to do after an accidental disclosure, and one on how to report it.

