Glossary
PHI
Quick answer
Protected health information: health details tied to an identifiable person, such as diagnoses, treatment notes, claims or appointment records.
In the U.S., HIPAA governs PHI held by covered entities (health plans, providers, clearinghouses) and their business associates. It covers 18 identifiers, including names, dates more specific than the year, contact details and record numbers.
Records containing PHI can only be shared for AI work once they are de-identified under HIPAA's Safe Harbor or Expert Determination method, or with patient authorization. SourceX treats any PHI as excluded unless the right method has been documented and the business approves the release.
Related terms
Related resources
- IndustryHealthcare data
- QuestionDo AI labs buy medical data?
- IndustryHealthcare administration data
- GlossarySafe Harbor de-identification
- QuestionDo AI companies buy private business data?
- InsightHIPAA and AI training data
- InsightCan AI models memorize and leak my data?
- InsightHow do I de-identify contracts and legal documents for AI training?
- SolutionData partnerships between businesses and AI developers
- DataInternal knowledge bases
- DataDocument approval records
- GlossaryData processing agreement
See if your company qualifies
A short company assessment. No data uploads are needed.