Skip to main content
Protected health information

Protected health information

Search complete. 25 mentions across 9 episodes found for "Protected health information".

Oct 6, 2026

Megan Thibert-IndGUEST
2:42
And so we try to take that specialized knowledge and apply it to each and every conflict or dispute that we help our clients navigate.
Jonathan BrollierHOST
2:53
The first topic we're gonna jump off into is handling, uh, PHI and HIPAA matters in the course of discovery and litigation.
Jonathan BrollierHOST
3:02
Regardless of what the matter may involve, if we have litigation for a participant in the healthcare industry, planning ahead and conducting discovery in a way that takes account of the, that regulatory overlay is critical.
Jonathan BrollierHOST
3:17
I think we can begin with an inquiry of Charles to describe some of the most basic or, or, or common mistakes that we see when litigators fail to set up proper discovery protocols and protective orders when they deal with health information.
Charles WeirGUEST
3:35
Sure, yeah.
Charles WeirGUEST
3:35
I, I think, you know, a lot of folks know, have heard of HIPAA and, and, you know, may have a general understanding that it is designed to protect the privacy of patients and their healthcare information.
Charles WeirGUEST
3:47
You know, at, at, in a lot of cases we litigate, there is, um, yeah, patient healthcare information prot- re- referred to as PHI, protected health information, that is, that is often produced in litigation, but it has to be produced in a particular way, and it has to be produced subject to very specific protective orders and rules so that you're following along with the, uh, the regulatory landscape.
Charles WeirGUEST
4:10
It, it isn't...
Cary ParkerHOST
24:36
At the time of the writing, the FBI jobs website said, quote, apply.fbijobs.gov and the special agent applicant portal are currently unavailable, unquote.
Cary ParkerHOST
24:46
Then it goes on to add, quote, all FBI data was compromised, including PII and PHI, which is personally identifiable information and protected health information, on incumbent and former FBI employees and all applicant information.
Cary ParkerHOST
25:01
We have a lot more than we claim here, unquote.
Cary ParkerHOST
25:04
The representative said Shiny Hunters said the group used a zero-day exploit in an Oracle product called PeopleSoft.
Donna GrindleHOST
3:14
You're right.
Donna GrindleHOST
3:14
That's probably a big explanation for it because it included not only individual identifiers, which you know is kind of key to it being a breach of PHI.
Donna GrindleHOST
3:26
But financial information, diagnoses, laboratory results, medications, treatment, all of it, all of it.
Donna GrindleHOST
3:37
You're supposed to say in your letter, I wonder if you could just say all of it, everything.
David SimsHOST
4:34
Did they find it kind of during the investigation? Was it part of the actual breach?
Donna GrindleHOST
4:41
Well, we get a clue down here in a minute from Director Stannard.
Donna GrindleHOST
4:46
Failure to assign unique identifiers for identifying and tracking users in systems containing ePHI.
David SimsHOST
4:59
Yep.
Alex VanceGUEST
10:20
As you can imagine, we're not moving around things that are very trivial.
Alex VanceGUEST
10:25
We're talking about patient data and that inevitably involves some access to PHI.
Alex VanceGUEST
10:33
One of the things that we pride ourselves on is that everything begins with a conversation.
Alex VanceGUEST
10:38
So we want to understand the organization and why they want to work with us.
Alex VanceGUEST
10:42
Who are the patients they serve? What's the environment that they work in and what's their data environment? What are their priorities and what they want to get out of a partnership with us and in what period of time? So from there, we walk through, as you can imagine, the appropriate governance and legal and privacy and technical processes.
Alex VanceGUEST
11:00
There's an important distinction in how we design the model that I think health system leaders should really understand.
Alex VanceGUEST
11:06
And that is PHI, or personal health information, is never sent to HOMUSC.
Alex VanceGUEST
11:14
And so our technology does access PHI within the health system to de-identify that data.
Dan ThompsonGUEST
22:50
they have the rights to all identified personal information for the purposes of procuring health care.
Dan ThompsonGUEST
22:57
And it's not about discrimination, right? There's a very big difference between discriminating in PHI and HIPAA and then utilizing information to help people.
Dan ThompsonGUEST
23:06
So if you know that part of your population has diabetes, or you know that most of your population, welcome to 2026, is on GLP drugs, you've gotta create access to care for those issues versus just letting it all live at the health insurance carrier because if the PBMs, we talked about those, they own the carriers.
Dan ThompsonGUEST
23:26
So if they know that there's a lot of drugs, What's going to be expensive? The drugs.
Andy McCabeHOST
24:07
At the time of writing, the FBI jobs website, quote, apply FBI jobs dot gov and the special agent applicant portal are currently unavailable.
Andy McCabeHOST
24:18
The defacement adds, quote, all FBI data was compromised, including PII and PHI, that's personally identifiable information and protected health information, on incumbent and former FBI employees.
Andy McCabeHOST
24:32
Uh-oh.
Andy McCabeHOST
24:33
And all applicant information.
Allison GillHOST
26:23
Huh.
Allison GillHOST
26:25
And a little bit extra here from the BBC, they updated the story saying that cyber criminals who hacked the FBI say they have extremely sensitive medical data.
Allison GillHOST
26:33
That's the PHI for thousands of its agents.
Allison GillHOST
26:36
BBC News has seen samples of the stolen fitness for work medical exams, which contain information like blood and urine test results and doctor's notes mentioning conditions such as shellfish and banana allergies.
NivathanGUEST
11:55
Like, okay, there, there is alerts, but how that vendor is getting used That can help us to answer that question, what we need to do when an alert pops in.
NivathanGUEST
12:06
Like if the vendor is, uh, purely, uh, for marketing, there is no PII involved or PHI involved, no sensitive data, okay.
NivathanGUEST
12:15
That's, uh, we can deprioritize that.
NivathanGUEST
12:17
And then there is PII involved or PHI involved, and a highly critical vendor can't go down or like it's, uh, the, uh, availability should be all nines, then yeah, then it's super critical.
NivathanGUEST
12:31
Like we have to take action on that immediately.
NivathanGUEST
12:33
The priority goes up.

5 MINS LATER

NivathanGUEST
17:43
I think like what, what happens today is they, they, they have basically, uh, given approval for that vendor.
NivathanGUEST
17:50
But what changes after that, when they were doing assessment, the internal use case is to just use it to, let's say like a marketing e-email was sent over that email provider.
Arun RangamaniGUEST
8:21
We can flip it.
Arun RangamaniGUEST
8:22
Because what can be a possible impediment to data integration because of privacy and usability also means it is a very structured framework how PHI data and how exclusivity and privacy is being considered.
Arun RangamaniGUEST
8:35
It is not a random thing.
Arun RangamaniGUEST
8:36
There are three clear HIPAA rules on how data should be considered, how data should be consolidated, how it should be aggregated.
Taylor CrossleyGUEST
13:27
Yeah, like you, like you mentioned, this is a real, uh, topic and has been a big topic of discussion in the industry over the past year that AI has really started to get integrated.
Taylor CrossleyGUEST
13:37
So, you know, if you take, for example, a hospice nurse who uses ChatGPT to draft a visit note using a patient's name and clinical details, um, that's a situation where PHI has been sent to a third party with potentially no business associate agreement, and that's potentially a HIPAA breach.
Taylor CrossleyGUEST
13:55
So that's the kind of example that we wanna be thinking about, um, when we're talking about this shadow AI problem in hospice.
Taylor CrossleyGUEST
14:02
Um, and in fact, we've seen recent OCR guidance.

We value your privacy

We use cookies to understand how you use our platform and to improve your experience. Click “Accept All” to consent, or “Decline non-essential” to opt out of non-essential cookies. Read our Privacy Policy.