Definition

PHI (protected health information) is individually identifiable health information, including demographic data, that a HIPAA covered entity or business associate creates, receives, maintains, or transmits in any form.

PHI covers information about a person's health condition, care, or payment for care that identifies the person or could reasonably be used to. HIPAA's de-identification safe harbor lists 18 identifiers, among them names, phone numbers, dates such as discharge dates, and medical record numbers. Electronic PHI (ePHI) is additionally governed by the Security Rule.

In outreach, PHI appears in the call list itself, in what the agent says, in the patient's answers, and in recordings and transcripts. Even confirming that someone is a patient of a specific clinic can disclose PHI, which is why identity verification has to come before protected details and why the data each system component sees should be limited to what it needs.

How Consig handles it

Consig gives each AI component only what it needs, keeps sensitive data behind conversational context firewalls, and requires a signed Business Associate Agreement before healthcare customers share PHI.