Protected health information (PHI)
Protected health information (PHI) is individually identifiable health information held or transmitted by a HIPAA covered entity or its business associate, in any form. It covers information about a person's health, care, or payment for care that is linked to identifiers such as a name, address, dates, phone number, email, medical record number, or photo.
01why it matters for a business
Whether data counts as PHI decides which rules apply to every system that touches it, including AI systems. A patient's appointment time combined with their name is PHI. So is an email address on a clinic's patient list, a recording of a call about symptoms, or a photo in a dental app. Teams often underestimate how much of their operational data qualifies.
HIPAA defines two ways to de-identify data so it is no longer PHI: the Safe Harbor method, which removes 18 specified types of identifiers, and Expert Determination, in which a qualified expert concludes that the risk of re-identification is very small. De-identified data can be used far more freely, including for analytics and model development, but free-text notes and images make de-identification harder than it looks.
02what it looks like in practice
A dental group wants to analyze which treatment plans patients accept and use AI to improve how plans are explained. The raw data, linking patients to treatments, costs, and appointment notes, is PHI and must stay in systems covered by BAAs with appropriate safeguards. For the analysis, the team produces a de-identified dataset under the Safe Harbor method, removing names, dates more specific than the year, contact details, and the other listed identifiers, and reviews free-text fields carefully before use.
03common mistakes
- Assuming data is not PHI because it lacks a diagnosis. Identifiable data about care or payment for care qualifies.
- Removing names but leaving dates, ZIP codes, or record numbers that still identify people.
- Forgetting unstructured data: notes, call recordings, images, and chat transcripts.
- Copying PHI into test and development environments.
04related terms
- HIPAA and AIHIPAA and AI refers to how the US Health Insurance Portability and Accountability Act applies when AI systems create, receive, store, or transmit protected health information.
- Business associate agreement (BAA)A business associate agreement (BAA) is a contract required by HIPAA between a covered entity, such as a provider or health plan, and a vendor that creates, receives, maintains, or transmits protected health information on its behalf.
- EHR integrationEHR integration is connecting an electronic health record system, such as Epic, Oracle Health, or athenahealth, with other software so patient, scheduling, clinical, and billing data can flow between them.
- Data warehouseA data warehouse is a central database designed for analysis and reporting, where data from many operational systems, such as ERP, CRM, billing, and marketing platforms, is collected, cleaned, and organized so it can be queried together.
05where insomnia club fits
Insomnia Club builds custom software for healthcare, including patient-facing apps with scheduling and patient records, and designs data handling around where PHI lives and who is allowed to see it.
see custom software development →tell us what keeps you up at night.
Scoped by the people who ship it. Priced before we start.
book a call drop your number