The PHI Use Risk Analyzer helps teams map where protected health information may enter a healthcare AI workflow. It is a review worksheet, not a legal opinion or security certification.
Review prompts
- What data types enter the tool, and who initiates the transfer?
- Does the vendor store PHI, process it transiently, or send it to subprocessors?
- Is PHI used for product improvement, model training, support, logging, or analytics?
- Can the organization disable retention, secondary use, or human review of PHI?
- Are audit logs, access controls, deletion timelines, and breach notification terms documented?
Suggested use
Create a row for each workflow step. Mark the data involved, vendor role, contract evidence, unresolved questions, and owner for follow-up. Pair this worksheet with a BAA review and security assessment before production use.