HealthAIdir logoHealthAIdir

PHI

Protected health information is identifiable health information handled by HIPAA covered entities or business associates.

industryPublished 2026/06/06Last verified 2026/07/17

Healthcare compliance context

This definition is for general healthcare technology research and is not legal or compliance advice. Verify PHI handling requirements with qualified counsel and compliance teams.

PHI means protected health information. In HIPAA contexts, it generally refers to individually identifiable health information created, received, maintained, or transmitted by covered entities or business associates.

AI tools that receive, store, summarize, or transmit PHI require careful review of data access, retention, training use, logging, subcontractors, security safeguards, and contractual terms.

Application scenario: In care setting review, this term helps teams connect a vendor claim to the clinical, administrative, compliance, or patient-facing workflow where it applies. Procurement impact: Buyers should evaluate evidence, implementation effort, integration needs, security, privacy, pricing assumptions, support, and compliance responsibilities before shortlisting or contracting for a tool that depends on this capability.

Sources and review notes

These links support definition-level research and do not establish the regulatory status, safety, or suitability of any product.

HHS explains that the HIPAA Privacy Rule protects most individually identifiable health information held or transmitted by covered entities or business associates in electronic, paper, or oral form, while identifying information alone or health information outside the relevant HIPAA roles and context is not automatically PHI. HHS's de-identification guidance describes Expert Determination and Safe Harbor as the two Privacy Rule methods and notes that residual re-identification risk is not necessarily zero. The current federal text of 45 CFR Part 160 supplies the controlling definitions and scope. These sources do not classify every health-related data point or product workflow, certify a vendor as HIPAA compliant, or make a BAA, encryption claim, or de-identification label sufficient on its own. Organizations must map entity and business-associate roles, data provenance and context, identifiers and free text, permitted purposes and disclosures, minimum-necessary rules where applicable, individual rights, safeguards, retention, subprocessors, model-training use, de-identification or limited-data-set methods, re-identification risk, incidents, breach duties, and other applicable federal or state law with qualified privacy, security, legal, and compliance reviewers.

FAQs

Why is PHI important when evaluating AI tools?
PHI handling determines whether HIPAA, contractual, security, retention, and governance requirements may apply to a tool or workflow.

Related research

Use related glossary terms and healthcare AI tool profiles to connect terminology checks with vendor due diligence.