SECAI Core · phase 4 of 15

Protected/personal health information

Information that identifies someone as the subject of medical and insurance records, plus associated hospital and laboratory test results.

The Explain card

Plain English
PHI is information that ties a person to their medical or insurance records: diagnoses, prescriptions, lab results, billing codes, and the identifiers that link them back to a patient.
Example
A hospital deploys an AI assistant to summarise discharge notes. Someone pastes a full patient record into a public model to "save time", and the lab results, name and insurer now sit in a third party's logs outside any care agreement.
Why it matters
PHI carries strict legal handling rules, and AI pipelines create new places for it to leak: prompts, vector stores, caches and vendor telemetry. Defenders have to know where health data flows before a model touches it.
Hook
PHI is PII that has been to the doctor, and the law is far stricter about it.

Where it sits in the deck

Phase 4: Data Integrity, Governance, and Provenance

Once you know what data is, learn the principles that keep it trustworthy, traceable, and minimized throughout its lifecycle.