This document discusses patient health information (PHI) and the importance of protecting it. PHI includes names, medical records, social security numbers, and any other identifiable health data. The HIPAA Privacy Rule was enacted in 2003 to protect PHI and sets regulations for covered entities like healthcare organizations. Some key aspects of the Privacy Rule are that it covers paper, electronic, and verbal PHI and restricts unauthorized access. Violations can result in fines or criminal charges. An example is provided of over 120 UCLA hospital employees improperly accessing celebrity medical records between 2004-2006. Confidentiality training is effective for educating staff on protecting PHI and consequences of breaches.