Data classification
Protected Health Information (PHI)
PHI is any individually identifiable health information created, received, or transmitted by a covered entity or business associate under HIPAA. It is one of the most regulated data classes and requires a Business Associate Agreement with any vendor who handles it.
Risk profile
PHI breaches carry significant HIPAA enforcement risk (up to $1.9M per violation category per year), reputational harm, and potential civil liability. Vendors handling PHI must provide a signed BAA, maintain HIPAA-compliant controls, and notify you of breaches within 60 days.
Applicable frameworks
Example vendors
Epic SystemsVeeva SystemsSalesforce Health CloudZoom (with HIPAA BAA)
Common questions
Does every vendor who handles patient names require a BAA?
Yes, if the vendor has access to PHI on your behalf. Even a vendor providing only email delivery — if those emails may contain PHI — is a business associate and requires a BAA.
What is the difference between PHI and PII?
PII is any information that can identify an individual. PHI is a subset of PII that relates to health status, provision of healthcare, or payment for healthcare. Not all PII is PHI, but all PHI is PII.
Which of your vendors handle Protected Health Information (PHI)?
TrustVendor tracks data class exposure across your entire vendor portfolio and computes residual risk per relationship.
Book a demo