What protected health information is
PHI is defined in HIPAA at 45 CFR 160.103. Information is PHI when it relates to a person's past, present, or future health, care, or payment for care. It must also identify the person or give a reasonable basis to identify them. It must also be held or handled by a covered entity or a business associate.
Names, addresses, dates of service, phone numbers, medical record numbers, and health plan IDs all make health data identifiable. A patient list with diagnoses is PHI. So is a recorded call about a refill. Health data a person keeps in their own consumer app is usually not PHI, because no covered entity holds it. Employment records a covered entity keeps as an employer are also excluded.
Any software that handles PHI for a practice, pharmacy, or plan is a business associate and needs a signed BAA. AI tools are no exception. Pasting a patient list into a consumer chatbot with no BAA is a disclosure HIPAA does not permit. Rivvi is a HIPAA-compliant AI workspace with a BAA included on the free plan, and PHI access is logged.