Protected health information (PHI)
Protected health information (PHI) is individually identifiable health information maintained or transmitted by a HIPAA covered entity or business associate in a covered form or context.
PHI connects information about a person's health, care, or payment for care with information that identifies the person or could reasonably do so. The identifying element can be direct, such as a name, or contextual, such as a combination of details that points to one individual. Whether information is PHI depends both on its content and on who holds it; not every piece of health-related data is automatically governed by HIPAA.
PHI is also not interchangeable with personally identifiable information. A phone number may be PII in many settings, but it becomes PHI under HIPAA only when the required health-information and covered-entity or business-associate context exists. Conversely, a clinical detail can remain sensitive even if a person's name is not placed beside it, because other details may make the person identifiable.
PHI in an AI phone call
Voice calls can create several copies or representations of the same information. A caller might state a name, date of birth, appointment reason, medication, insurance detail, or account balance. That information can then appear in audio, a transcript, a summary, structured fields, tool requests, webhook payloads, or a downstream system. A PHI inventory should follow the entire flow rather than treating the recording as the only sensitive artifact.
The practical question is not simply whether an agent “uses PHI.” Teams need to define which data elements are necessary for each call purpose, when identity verification is required, where the data is sent, who can retrieve it, and when it is deleted. Integrations and human transfers should be included because they can expose information outside the original conversation path.
Controls should follow the approved workflow: minimize unnecessary collection, restrict access, protect data in transit and at rest, log appropriate administrative activity, and establish retention and incident procedures. Redaction can reduce exposure, but it must be evaluated against every artifact and destination. Removing a name from a transcript does not necessarily de-identify the remaining content.
Organizations handling PHI should determine their role under HIPAA, confirm required agreements with relevant service providers, and have qualified privacy and security professionals review the full call system.