Practical Ways to Protect Yourself Online and IRL (In Real Life) — Part 1: Understanding PII and Other Sensitive Information


As someone taking care of an elderly parent, I've spent many hours assisting my mother to help her understand what not to do while using the Internet. Admittedly, she frequently gets confused by all the radical changes the Internet and technology in general have gone through in the past few decades, but she tries to understand when I explain things to her. If she is ever uncertain of something, like a suspicious email, my mother will defer to me before doing anything. However, she still hasn't quite grasped the difference between "cable" (both Internet and television) and "streaming," but she's trying.

My mother frequently recalls her college days when Dial-up, BASIC, Pascal, and "DOS" defined computing for everyday people. I remember from high school in the mid-2000s how my mother clung to her Gateway PC running Microsoft Windows 98 SE because it was what she knew despite the hard disk drive (HDD) giving its last dying gasps; some of the drive heads had collapsed and were grinding against the platters, fortunately not enough to prevent Windows from booting, but it sounded awful.

In thinking about just how much computers have transformed life as we know it, some good and some not so good, I wanted to write down a few practical ways people can protect themselves and minimize the damage when their personal information is involved in a data breach. But first, we need to understand what exactly we are trying to safeguard. So, let's begin with a dive into different types of information. As we go through this topic, keep in mind the sources referenced are current at the time of this writing.

One more thing before we dive in: my frame of reference here — personal experience, professional background, and plain old familiarity — is rooted primarily in how personal information is understood and regulated in the United States. I've included a section on GDPR to give readers outside the U.S. a starting point, but this post leans heavily on U.S. law and practice. If you're located elsewhere, treat the U.S.-specifics as a helpful reference point rather than a description of what actually applies to you.

What is PII?

Personally Identifiable Information (PII) are pieces of information that can reveal the identity of an individual. These include:

  • Name
  • Social Security number (SSN; a number frequently used to uniquely identify individuals in the United States)
  • National identification number (outside the United States)
  • Passport number
  • Driver's license/State ID number
  • Biometric information (fingerprints, facial features, voice recording, retina scan information, etc.)
  • Any other piece of information that is directly tied to a person's identity, such as:
    • personal telephone numbers
    • email addresses
    • home address

If we want to consider a more formal definition, we can refer to the U.S. National Institute of Standards and Technology (NIST) publications, specifically NIST Special Publication 800-122, NIST Special Publication 800-53A, and FIPS PUB 201-3:

  • NIST SP 800-122 defines PII in the context of U.S. federal agencies. Specifically, "PII is any information about an individual maintained by an agency, including:

    1. any information that can be used to distinguish or trace an individual's identity, such as name, social security number, date and place of birth, mother's maiden name, or biometric records; and
    2. any other information that is linked or linkable to an individual, such as medical, educational, financial, and employment information."
  • NIST SP 800-53A establishes PII more succinctly since the publication focuses on being a practical guide for auditing security controls protecting this data:

    "Information that can be used to distinguish or trace an individual's identity, either alone or when combined with other information that is linked or linkable to a specific individual."

  • FIPS PUB 201-3 defines PII a bit more descriptively as:

    "Information that can be used to distinguish or trace an individual's identity—such as name, Social Security number, biometric data records—either alone or when combined with other personal or identifying information that is linked or linkable to a specific individual (e.g., date and place of birth, mother's maiden name, etc.). SOURCE: [M-17-12, adapted]"

Each publication mentions "linkable" information. This means PII that might not expose an individual's identity by itself, but when correlated together with other pieces of information can reveal the person's identity (what are called indirect identifiers). Examples of this can include:

  • ZIP codes
  • ethnicity
  • nationality
  • biological sex
  • gender identity
  • sexual orientation
  • marital status
  • any other piece of information that can be correlated with other data to reveal a person's identity, such as:
    • bank account numbers
    • credit/debit cards
    • vaccination records
    • mother's maiden name

What is PHI?

Protected Health Information (PHI) is a distinct subset of PII associated with the detailed health history of an individual. When in digital (non-physical) form, this is referred to as electronic Protected Health Information (ePHI). This information can be extraordinarily sensitive to the privacy of a person as they may have health concerns or conditions they would be extremely embarrassed by if it were to become public. Additionally, revelation of this information could result in compromise of the person's safety and well-being, such as their living situation or their employment.

For a formal definition, we can refer to NIST SP 800-66 which contains a few related but distinct definitions of a person's health information:

Health information — Any information, including genetic information, whether oral or recorded in any form or medium, that:

  1. Is created or received by a healthcare provider, health plan, public health authority, employer, life insurer, school or university, or healthcare clearinghouse; and
  2. Relates to the past, present, or future physical or mental health or condition of an individual; the provision of healthcare to an individual; or the past, present, or future payment for the provision of healthcare to an individual. [Sec. Rule, §160.103]

Individually Identifiable Health Information (IIHI) — Information that is a subset of health information, including demographic information collected from an individual, and:

  1. Is created or received by a healthcare provider, health plan, employer, or healthcare clearinghouse; and
  2. Relates to the past, present, or future physical or mental health or condition of an individual; the provision of healthcare to an individual; or the past, present, or future payment for the provision of healthcare to an individual; and
    1. That identifies the individual; or
    2. With respect to which there is a reasonable basis to believe the information can be used to identify the individual. [Sec. Rule, §160.103]

Protected Health Information (PHI) — Individually identifiable health information:

  1. Except as provided in paragraph (2) of this definition, that is:
    1. Transmitted by electronic media;
    2. Maintained in electronic media; or
    3. Transmitted or maintained in any other form or medium.
  2. Protected health information excludes individually identifiable health information:
    1. In education records covered by the Family Educational Rights and Privacy Act, as amended, 20 U.S.C. 1232g;
    2. In records described at 20 U.S.C. 1232g(a)(4)(B)(iv);
    3. In employment records held by a covered entity in its role as employer; and
    4. Regarding a person who has been deceased for more than 50 years. [Sec. Rule, §160.103]

In the United States, PHI is federally protected under the Health Insurance Portability and Accountability Act of 1996 (HIPAA). Both NIST and HIPAA definitions of PHI are based on or are in reference to the United States Code of Federal Regulations (45 C.F.R. §160.103). HIPAA was enhanced by the passage of the Health Information Technology for Economic and Clinical Health Act of 2009 (HITECH), pushing for the migration from paper-based recordkeeping to Electronic Health Records (EHRs). Among other things, HITECH expanded the Office for Civil Rights' (OCR) authority to enforce HIPAA, enhancing the OCR's ability to investigate violations, and established breach notification requirements if a person's health records were compromised.

Breach of PHI and related records goes beyond the risk of embarrassment or safety. Speaking from personal experience, I received notification of a data breach that affected a 3rd party contractor of the health insurance provider at a previous employer that included my own personal information, risking my identity as a result and underscoring the importance of protecting your identity and your information in all its forms. This is no longer something optional in today's world.

What is Genetic Information?

Genetic information is closely related to PHI. In scientific terms, genetic information pertains to the details of an individual's genetic code contained in their DNA (their genome), including chromosomal information, potential markers for disease, and other insights from this data. But in legal terms, genetic information is defined by the U.S. Equal Employment Opportunity Commission (EEOC) as any of the following:

  • Information about an individual's genetic tests;
  • Information about the genetic test of a family member;
  • Family medical history;
  • Requests for and receipt of genetic services by an individual or a family member; and
  • Genetic information about a fetus carried by an individual or family member or of an embryo legally held by an individual or family member using assisted reproductive technology.

In the United States, the Genetic Information Nondiscrimination Act of 2008 (GINA) regulates the protection and usage of individuals' genetic information and is split into Title I and Title II:

  • Title I: Health Insurance

    • Protects you against being discriminated against regarding health insurance eligibility, premiums, and coverage.
  • Title II: Employment

    • Protects you against being discriminated against in employment decisions, including hiring, termination, pay, and promotion, without exceptions.
    • Generally, prohibits employers or potential employers from requesting, requiring, or purchasing genetic information with very narrow exceptions to this requirement, such as employee wellness program participation or accidental acquisition.

Under GINA, genetic information must be kept confidential and is only allowed to be disclosed in certain defined situations. Note that while GINA protects against discrimination in health insurance coverage and employment matters, it is not involved in regulating eligibility in life insurance, long-term care insurance, or disability insurance. Furthermore, and perhaps more relatable to everyday folks, neither GINA nor HIPAA/HITECH covers direct-to-consumer (DTC) genetic testing services.

Implications of this data not being handled properly can be just as embarrassing and devastating as PHI disclosure. Anyone who was affected by the 2023 data breach of 23andMe understands this firsthand. For those unfamiliar, the genetic testing services company had millions of their users' data compromised due to the use of weak and reused passwords by their customers, lack of enforced Multifactor Authentication (MFA), and poor systems monitoring.

This is not to dissuade you from using these services, especially if you have an interest in genealogy research or family medical history when you're lacking other sources of this important information. Rather, this is a reminder to be cautious about which organizations you entrust with your genetic and medical information, minimize the amount of information you share, and protect your account access as best as you can.

What is Payment Card Data?

The Payment Card Industry (PCI) refers to the ecosystem of banks, merchants, and card networks. The specific data this ecosystem handles is called Payment Card Data. This data is associated with a person's payment card issued by a bank or a payment brand network (think Visa, MasterCard, American Express (AMEX), JCB International, and so on). Standards that define this data and the requirements to protect it are determined by the Payment Card Industry Security Standards Council (PCI SSC). Among their many published standards, the council is largely known for their publicly available Data Security Standard (PCI DSS). Be aware that to gain access to the publications in the council's Document Library, you must register and agree to their license agreement and privacy statement.

It's worth noting that the PCI DSS is not a legal regulation or requirement; it is enforced through contractual agreements and stringent, recurring audits between the entities involved in handling payment card data.

Without getting into the minutiae of the technical details the PCI council defines, as an individual you should aim to protect the information tied to your payment cards, which includes:

  • Cardholder name
  • Card number
  • Card verification number
  • Personal Identification Number (PIN; typically used with debit cards and cash advances on credit cards)
  • Expiration date

Additionally, a business should never ask to keep your card's verification information or your PIN on file (physically or electronically) after a purchase. This data is explicitly prohibited from being saved after a transaction; not even encrypting this information permits its storage. If you are ever asked to do this in any form, do not agree to this.

What is Personally Identifiable Financial Information (PIFI)?

Stepping back from the payment card discussion, Personally Identifiable Financial Information (PIFI) encompasses the data involved in financial agreements or transactions between consumers and "financial institutions":

  • Banks
  • Credit unions
  • Mortgage brokers
  • Tax preparers
  • Check cashers
  • Retailers with their own branded store cards
  • Any other institution that you can have a financial relationship with

More specifically, PIFI is any data related to financial products and services. PIFI is a subset of Nonpublic Personal Information (NPI) defined under the Financial Services Modernization Act of 1999 (a.k.a., the Gramm-Leach-Bliley Act (GLBA)), which includes, but is not limited to:

  • Information provided on applications for financial products or services:
    • Loans
    • Credit cards
    • Credit union membership
    • Checking, savings, and investment accounts
  • Account balances
  • Payment history
  • Overdraft history
  • Credit/debit card purchase information
  • Income information
  • Debt collection
  • Loan servicing
  • Data collected using Internet "cookies"
  • Credit report information

If you have ever received a privacy practice notice from a bank, credit union, or other institution where you have a financial relationship, the GLBA is what mandates this communication. Additionally, the GLBA requires data breach notification to the U.S. Federal Trade Commission (FTC) for FTC-regulated institutions, such as tax preparers. Many states also have their own laws that mandate breach notification to consumers overlapping with GLBA's breach notification requirement to the FTC.

GLBA's information security program requirements place much of the burden of responsibility on the financial institutions themselves. That being said, as a consumer you can take steps to ensure your information is secure, such as reviewing the privacy notice you are entitled to, being mindful of your account balances and history, regularly checking your credit report for discrepancies, and opting out of sharing NPI with non-affiliated 3rd parties when possible.

What is CPNI?

Customer Proprietary Network Information (CPNI) pertains to technical information of a person's usage of a telecommunication service (think traditional phone providers, cellular networks, and Voice-over-IP (VoIP) providers). CPNI is defined by 47 U.S. Code § 222 - Privacy of customer information as:

A. information that relates to the quantity, technical configuration, type, destination, location, and amount of use of a telecommunications service subscribed to by any customer of a telecommunications carrier, and that is made available to the carrier by the customer solely by virtue of the carrier-customer relationship; and

B. information contained in the bills pertaining to telephone exchange service or telephone toll service received by a customer of a carrier; except that such term does not include subscriber list information.

To keep it simple, CPNI includes, but is not limited to:

  • call logs (who you called and how long you were on the call)
  • geolocation data
  • service type
  • billing and usage records

Generally, telecommunications providers are prohibited from sharing or disclosing CPNI aside from a few notable exceptions, such as fraud prevention, allowing for the dispatching of emergency services, and bill collection.

This might not sound like something you'd consider a risk to your identity, but like with any other service, it can be correlated with other data points that make up your PII. Not only that, CPNI relates to your overall privacy. There are a few steps you can take to help protect this information and other PII you entrust to your telecommunications provider when using their service. Setting up an account password or PIN goes a long way to securing CPNI and your subscriber account.

What are Student Education Records?

Student Education Records are a type of sensitive information related to education history, including transcripts of classes taken (passed/failed), credits earned, Grade Point Averages (GPAs), and PII that may be contained within educational records. In the United States, this information is protected by the Family Educational Rights and Privacy Act of 1974 (FERPA). Under FERPA, students and parents have certain rights to review and request amendment of educational records, be notified of certain disclosures, and opt-out of certain disclosures. FERPA applies to all public schools from kindergarten through the 12th grade, certain private schools that receive federal funds, and most postsecondary institutions.

One important thing to know: these rights don't stay with parents forever. Once a student turns 18, or enrolls in any postsecondary institution at any age, FERPA rights transfer from the parent to the student, who becomes what the law calls an "eligible student." From that point on, it's generally the student, not the parent, who controls access to their own education records.

Common PII found in education records can include:

  • Name
  • Birthdate
  • Birthplace
  • Attendance dates
  • Extracurricular activities (sports, band, clubs, etc.)
  • Financial records (tuition, fees, awarded financial aid, etc.)

One item to note: some of the above PII are defined by FERPA as "directory information" — information that "would not generally be considered harmful or an invasion of privacy if disclosed." Schools can generally release this type of information without consent, though parents and eligible students have the right to opt out of having it shared.

It's also worth knowing that postsecondary institutions are permitted to disclose a student's alcohol or controlled substance violation to their parents without the student's consent, but only if the student is under 21 at the time of the disclosure — a specific exception FERPA has allowed since a 1998 amendment.

What is CJI?

Criminal Justice Information (CJI) is defined in the United States by the Federal Bureau of Investigation (FBI) and applies to law enforcement agencies at all levels as well as any other public or private entity that handles CJI, including 3rd parties. It can be considered a superset of PII as CJI can encompass many different types of information, including biometrics, identity, property records, behavioral traits and assessments, case details, conviction information, and more.

The formal definition is found in the FBI's publicly available Criminal Justice Information Services (CJIS) Policy. CJIS outlines two related but distinct definitions:

Criminal Justice Information — The term used to refer to all the FBI CJIS provided data necessary for law enforcement and civil agencies to perform their missions including, but not limited to biometric, identity history, biographic, property, and case/incident history data. The following categories of CJI describe the various data sets housed by the FBI CJIS architecture:

  1. Biometric Data — data derived from one or more intrinsic physical or behavioral traits of humans typically for the purpose of uniquely identifying individuals from within a population. Used to identify individuals, to include: fingerprints, palm prints, iris scans, and facial recognition data.
  2. Identity History Data — textual data that corresponds with an individual's biometric data, providing a history of criminal and/or civil events for the identified individual.
  3. Biographic Data — information about individuals associated with a unique case, and not necessarily connected to identity data. Biographic data does not provide a history of an individual, only information related to a unique case.
  4. Property Data — information about vehicles and property associated with crime when accompanied by any personally identifiable information (PII).
  5. Case/Incident History — information about the history of criminal incidents.

Criminal History Record Information (CHRI) — is a highly sensitive subset of CJI and is stored in the FBI's National Crime Information Center (NCIC) database. This system is heavily restricted with no public access allowed. According to CJIS, CHRI includes:

  1. Gang Files
  2. Threat Screening Center Files
  3. Supervised Release Files
  4. National Sex Offender Registry Files
  5. Historical Protection Order Files of the NCIC
  6. Identity Theft Files
  7. Protective Interest Files
  8. Person With Information (PWI) data in the Missing Person Files
  9. Violent Person File
  10. NICS Denied Transactions File

For people with documented criminal histories, there isn't much they can do since the responsibility for protecting this information largely falls to the entities that handle it, such as the court system and law enforcement agencies. However, the information that is within the individual's control, such as SSN and driver's license number, can still be reasonably protected.

A Quick Note on GDPR

Unlike the United States' patchwork of state and federal laws for different buckets of data, the European Union's approach is a singular regulation that all member states must adhere to, called the General Data Protection Regulation of 2016 (GDPR). Note that GDPR enforcement took effect in May 2018.

We've discussed the United States' concept of PII. But under GDPR, "personal data" is defined in GDPR Article 4(1) as:

"Any information relating to an identified or identifiable natural person ('data subject'); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person."

This definition alone does not address personal information of a sensitive nature. These "special categories" of personal data are addressed in GDPR Article 9, which states:

"Personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, and the processing of genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health or data concerning a natural person's sex life or sexual orientation."

To put it simply, GDPR's definition of what we understand in the United States as PII is broader. Article 9's definition explicitly prohibits processing these certain types and special categories of personal data by default unless a specific exception applies, such as the "data subject" (person) giving explicit consent.

GDPR affords considerable privacy-focused data subject rights to individuals located in the EU, including:

  • Right of access — request a copy of what data an organization holds on you
  • Right to rectification — correct inaccurate data
  • Right to erasure (a.k.a. the "right to be forgotten") — request deletion, with some limits
  • Right to restrict processing
  • Right to data portability — get your data in a usable format to move to another provider or organization
  • Right to object — opt out of certain processing, including direct marketing
  • Right to protections around automated decision-making — you can't be subjected to purely automated decisions with legal/significant effects (e.g., automated loan denial) without recourse

Personal Information Summarized

So here we are, several acronyms and two continents later. This discussion was a high-level overview of a few different types of personal information along with relevant but broad regulations that apply to them; this was by no means an exhaustive discussion. Here's the throughline: almost everything about you — your SSN, your health records, your DNA, your call logs — is information someone is legally required to protect, and that protection has limits worth knowing before you need it. Some laws have real teeth, like HIPAA/HITECH, GLBA, or GINA, but there are real limitations and gaps. Some of it — like your data sitting with a DTC genetic testing company — isn't as well regulated and potentially not as rigorously safeguarded, which is exactly why understanding these categories matters as much as any antivirus tool or password manager.

This first part was about understanding what you're protecting. Next time, I'll begin discussing how to take steps to safeguard your personal information: the settings, habits, and red flags that make this knowledge useful. Until then, take stock of where your information lives and ask questions before you provide it, and remember what I keep telling my mother: technology isn't something to fear — it's something to understand well enough to use on your own terms, understand what sensitive information you're handing over, and protect yourself from the risk of it being compromised.


References

PII

PHI

Payment Card Data

NPI / PIFI

Genetic Information

CPNI

Student Education Records

CJI

GDPR

  • Regulation (EU) 2016/679 (General Data Protection Regulation), Articles 4 and 9 — https://gdpr-info.eu/