DEFINITION
Protected Health Information (PHI)
Individually identifiable health information held or transmitted by a covered entity, regulated under HIPAA in the United States.
In depth
Protected Health Information (PHI) is the HIPAA term for any health data — diagnosis, treatment, payment, demographics — that can be tied back to an individual when held by a covered entity (provider, plan, clearinghouse) or its business associates. PHI is broader than just clinical records: dates, account numbers, photos, device identifiers, and even ZIP codes can become PHI when linked to a health context. Pasting PHI into a third-party AI tool without a Business Associate Agreement is a HIPAA disclosure event in most analyses.
Examples
- Patient names appearing alongside diagnoses or visit dates.
- Medical record numbers, prescription IDs, DEA numbers.
- Insurance subscriber IDs, claim numbers, billing codes.
- Imaging file names that include patient identifiers.
How Locke handles protected health information (phi)
Locke detects patterns consistent with PHI — MRNs, ICD-10/CPT codes, NPIs, prescription identifiers, demographic combinations — locally, before any text reaches an AI model. Because Sonomos never sees the data itself, no new business associate relationship is created. See the Healthcare page for the regulatory walk-through.
See the productRelated terms
- Personally Identifiable Information (PII)
Any information that can identify a specific person, either directly (name, SSN) or in combination with other data (zip code + birthdate).
- Redaction
Removing or blacking-out sensitive content so it is no longer present in the document or prompt.
- Privacy Layer for AI
A control point between a user and an AI service that detects, transforms, or blocks sensitive data before it reaches the model.