SECAI Core · phase 4 of 15
Protected/personal health information
Information that identifies someone as the subject of medical and insurance records, plus associated hospital and laboratory test results.
The Explain card
- Plain English
- PHI is information that ties a person to their medical or insurance records: diagnoses, prescriptions, lab results, billing codes, and the identifiers that link them back to a patient.
- Example
- A hospital deploys an AI assistant to summarise discharge notes. Someone pastes a full patient record into a public model to "save time", and the lab results, name and insurer now sit in a third party's logs outside any care agreement.
- Why it matters
- PHI carries strict legal handling rules, and AI pipelines create new places for it to leak: prompts, vector stores, caches and vendor telemetry. Defenders have to know where health data flows before a model touches it.
- Hook
- PHI is PII that has been to the doctor, and the law is far stricter about it.
Where it sits in the deck
Phase 4: Data Integrity, Governance, and Provenance
Once you know what data is, learn the principles that keep it trustworthy, traceable, and minimized throughout its lifecycle.