
Protected health information
25
MENTIONS
9
EPISODES
9
PODCASTS
Search complete. 25 mentions across 9 episodes found for "Protected health information".
Oct 6, 2026
Regulatory Landmines in Health Care Litigation: PHI, Kickback, and Corporate Structure Risks
M
2:42Megan Thibert-IndGUEST
And so we try to take that specialized knowledge and apply it to each and every conflict or dispute that we help our clients navigate.
J
2:53Jonathan BrollierHOST
The first topic we're gonna jump off into is handling, uh, PHI and HIPAA matters in the course of discovery and litigation.
J
3:02Jonathan BrollierHOST
Regardless of what the matter may involve, if we have litigation for a participant in the healthcare industry, planning ahead and conducting discovery in a way that takes account of the, that regulatory overlay is critical.
J
3:17Jonathan BrollierHOST
I think we can begin with an inquiry of Charles to describe some of the most basic or, or, or common mistakes that we see when litigators fail to set up proper discovery protocols and protective orders when they deal with health information.
C
3:35Charles WeirGUEST
Sure, yeah.
C
3:35Charles WeirGUEST
I, I think, you know, a lot of folks know, have heard of HIPAA and, and, you know, may have a general understanding that it is designed to protect the privacy of patients and their healthcare information.
C
3:47Charles WeirGUEST
You know, at, at, in a lot of cases we litigate, there is, um, yeah, patient healthcare information prot- re- referred to as PHI, protected health information, that is, that is often produced in litigation, but it has to be produced in a particular way, and it has to be produced subject to very specific protective orders and rules so that you're following along with the, uh, the regulatory landscape.
C
4:10Charles WeirGUEST
It, it isn't...
Hold Off on Muse
C
24:36Cary ParkerHOST
At the time of the writing, the FBI jobs website said, quote, apply.fbijobs.gov and the special agent applicant portal are currently unavailable, unquote.
C
24:46Cary ParkerHOST
Then it goes on to add, quote, all FBI data was compromised, including PII and PHI, which is personally identifiable information and protected health information, on incumbent and former FBI employees and all applicant information.
C
25:01Cary ParkerHOST
We have a lot more than we claim here, unquote.
C
25:04Cary ParkerHOST
The representative said Shiny Hunters said the group used a zero-day exploit in an Oracle product called PeopleSoft.
Keeping Humans in Charge of AI - Ep 580
D
3:14Donna GrindleHOST
You're right.
D
3:14Donna GrindleHOST
That's probably a big explanation for it because it included not only individual identifiers, which you know is kind of key to it being a breach of PHI.
D
3:26Donna GrindleHOST
But financial information, diagnoses, laboratory results, medications, treatment, all of it, all of it.
D
3:37Donna GrindleHOST
You're supposed to say in your letter, I wonder if you could just say all of it, everything.
D
4:34David SimsHOST
Did they find it kind of during the investigation? Was it part of the actual breach?
D
4:41Donna GrindleHOST
Well, we get a clue down here in a minute from Director Stannard.
D
4:46Donna GrindleHOST
Failure to assign unique identifiers for identifying and tracking users in systems containing ePHI.
D
4:59David SimsHOST
Yep.
Turning Behavioral Health Data Into Actionable Evidence
A
10:20Alex VanceGUEST
As you can imagine, we're not moving around things that are very trivial.
A
10:25Alex VanceGUEST
We're talking about patient data and that inevitably involves some access to PHI.
A
10:33Alex VanceGUEST
One of the things that we pride ourselves on is that everything begins with a conversation.
A
10:38Alex VanceGUEST
So we want to understand the organization and why they want to work with us.
A
10:42Alex VanceGUEST
Who are the patients they serve? What's the environment that they work in and what's their data environment? What are their priorities and what they want to get out of a partnership with us and in what period of time? So from there, we walk through, as you can imagine, the appropriate governance and legal and privacy and technical processes.
A
11:00Alex VanceGUEST
There's an important distinction in how we design the model that I think health system leaders should really understand.
A
11:06Alex VanceGUEST
And that is PHI, or personal health information, is never sent to HOMUSC.
A
11:14Alex VanceGUEST
And so our technology does access PHI within the health system to de-identify that data.
The Direct Primary Care Revolution with Special Guest Dan Thompson
D
22:50Dan ThompsonGUEST
they have the rights to all identified personal information for the purposes of procuring health care.
D
22:57Dan ThompsonGUEST
And it's not about discrimination, right? There's a very big difference between discriminating in PHI and HIPAA and then utilizing information to help people.
D
23:06Dan ThompsonGUEST
So if you know that part of your population has diabetes, or you know that most of your population, welcome to 2026, is on GLP drugs, you've gotta create access to care for those issues versus just letting it all live at the health insurance carrier because if the PBMs, we talked about those, they own the carriers.
D
23:26Dan ThompsonGUEST
So if they know that there's a lot of drugs, What's going to be expensive? The drugs.
Volume II Catch-22
A
24:07Andy McCabeHOST
At the time of writing, the FBI jobs website, quote, apply FBI jobs dot gov and the special agent applicant portal are currently unavailable.
A
24:18Andy McCabeHOST
The defacement adds, quote, all FBI data was compromised, including PII and PHI, that's personally identifiable information and protected health information, on incumbent and former FBI employees.
A
24:32Andy McCabeHOST
Uh-oh.
A
24:33Andy McCabeHOST
And all applicant information.
A
26:23Allison GillHOST
Huh.
A
26:25Allison GillHOST
And a little bit extra here from the BBC, they updated the story saying that cyber criminals who hacked the FBI say they have extremely sensitive medical data.
A
26:33Allison GillHOST
That's the PHI for thousands of its agents.
A
26:36Allison GillHOST
BBC News has seen samples of the stolen fitness for work medical exams, which contain information like blood and urine test results and doctor's notes mentioning conditions such as shellfish and banana allergies.
Beyond SOC 2: Real Vendor Risk with Nivathan of SecureOS
N
11:55NivathanGUEST
Like, okay, there, there is alerts, but how that vendor is getting used That can help us to answer that question, what we need to do when an alert pops in.
N
12:06NivathanGUEST
Like if the vendor is, uh, purely, uh, for marketing, there is no PII involved or PHI involved, no sensitive data, okay.
N
12:15NivathanGUEST
That's, uh, we can deprioritize that.
N
12:17NivathanGUEST
And then there is PII involved or PHI involved, and a highly critical vendor can't go down or like it's, uh, the, uh, availability should be all nines, then yeah, then it's super critical.
N
12:31NivathanGUEST
Like we have to take action on that immediately.
N
12:33NivathanGUEST
The priority goes up.
5 MINS LATER
N
17:43NivathanGUEST
I think like what, what happens today is they, they, they have basically, uh, given approval for that vendor.
N
17:50NivathanGUEST
But what changes after that, when they were doing assessment, the internal use case is to just use it to, let's say like a marketing e-email was sent over that email provider.
The Data Problem Holding Back Healthcare AI with Arun Rangamani | EXL
A
8:21Arun RangamaniGUEST
We can flip it.
A
8:22Arun RangamaniGUEST
Because what can be a possible impediment to data integration because of privacy and usability also means it is a very structured framework how PHI data and how exclusivity and privacy is being considered.
A
8:35Arun RangamaniGUEST
It is not a random thing.
A
8:36Arun RangamaniGUEST
There are three clear HIPAA rules on how data should be considered, how data should be consolidated, how it should be aggregated.
Getting Ahead of the Curve: How Hospice Providers Can Build Smart AI Practices, Part 1
T
13:27Taylor CrossleyGUEST
Yeah, like you, like you mentioned, this is a real, uh, topic and has been a big topic of discussion in the industry over the past year that AI has really started to get integrated.
T
13:37Taylor CrossleyGUEST
So, you know, if you take, for example, a hospice nurse who uses ChatGPT to draft a visit note using a patient's name and clinical details, um, that's a situation where PHI has been sent to a third party with potentially no business associate agreement, and that's potentially a HIPAA breach.
T
13:55Taylor CrossleyGUEST
So that's the kind of example that we wanna be thinking about, um, when we're talking about this shadow AI problem in hospice.
T
14:02Taylor CrossleyGUEST
Um, and in fact, we've seen recent OCR guidance.