What is Protected Health Information (PHI)?

Governance & Control
Definition

Health information that identifies a person, in any medium, created or received while providing care or payment for it. In an AI system PHI is not a column in a database: it is the prompt, the retrieved context, the artifact, and the trace.

Why It Matters

Teams plan for PHI in the database and then discover it in four other places. A clinician pastes a note into a prompt. A retriever pulls a discharge summary into context. The agent writes the summary into an artifact. The tracing layer records the whole exchange to a vendorโ€™s storage.

Each of those hops is a disclosure with its own permitted purpose, retention rule, and access list. Treating PHI as a storage problem rather than a flow problem is how deployments end up compliant on paper and exposed in practice.

Where It Travels

The path is predictable once you trace it: source system to retriever, retriever to context window, context to model endpoint, model to artifact, and the whole exchange to telemetry. Add the review queue, where a human reads the draft, and the eval store, where the same material becomes a test case.

Controls attach to hops, not to the system as a whole. The retrieval index needs access rules. The model endpoint needs an agreement that covers it. The trace needs redaction or a residency decision. The review queue needs role-based access like any other clinical surface.

Where It Breaks

Redaction at the boundary is the common half-measure. Strip identifiers on the way in and the system still leaks through what it reconstructs: a rare diagnosis plus a date plus a clinic narrows to one person.

The second break is retention by default. Prompts, traces, and eval sets accumulate because nobody decided how long they should live. Health data kept โ€œin case it is usefulโ€ is the finding that turns an incident into a breach report.

The third is training. A vendor agreement that permits the provider to improve its models with your inputs converts every run into a disclosure you did not intend.

How Flytebit Handles It

We map the flow before building anything, then attach a control to each hop: minimum-necessary access at retrieval, an agreement that covers the model endpoint, residency rules on the index and the trace, and role-based access on the review surface. Retention is set per artifact class rather than left at a platform default, and the decision record captures what each run touched. The industry application is on our Healthcare & Life Sciences page.

More info

On flytebit.com

Reviewed by Jayaveer Bhupalam, Founder & CTO Last updated September 28, 2026