Map PHI before tools

Can You Use AI With PHI? Start With the Data Flow

A compliance-aware PHI data-flow assessment covering purpose, minimum fields, BAAs, vendors, subprocessors, storage, logs, safeguards, and human approval.

By WhichAI. Published 2026-07-12. Updated 2026-07-12.

Methodology: Editorial synthesis of workflow design patterns and implementation constraints. Public control references provide context, not proof of a deployment or legal advice. Where a versioned evidence pack appears, its evidence class, method, and limitations govern what the artifact can support. Read the full method. Report a correction.

Built for

Healthcare privacy, security, operations, and clinical or administrative owners

The decision

Decide whether a bounded AI-assisted workflow has a documented and approved PHI path.

Answer first

A vendor feature is not the workflow review. Map every PHI field and copy, verify BAA and vendor-chain requirements, conduct organizational risk review, assess safeguards, and keep accountable human approval.

WhichAI Solutions diagnostic

Bring this operating problem to the diagnostic

Use WhichAI Solutions whenever PHI may enter the workflow, because BAA verification, data-flow mapping, organizational risk review, safeguards, and human ownership must be resolved locally.

Open the diagnostic

The capacity leak

What the team is doing before anyone calls it a systems problem

Headcount pressure rarely starts with one giant task. It starts when ordinary work is split across inboxes, tabs, handoffs, and undocumented judgment calls. These are the signals to map first.

SIGNAL 01

Teams know the primary application but not every prompt, log, cache, support, or subprocessor path.

SIGNAL 02

A vendor BAA is discussed without matching it to the service and configuration used.

SIGNAL 03

The minimum PHI needed for the workflow is not separated from convenient context.

SIGNAL 04

Clinical or administrative approval occurs after data design rather than defining it.

The implementation

The system should prepare the decision, not pretend the decision disappeared

A complete implementation connects the intake, context, transformation, review, and record. The output of one stage becomes the controlled input to the next. A human owns the exceptions and the final consequence.

StageCurrent dragSystem responsibilityHuman responsibilityEvidence kept
1. Purpose and minimum dataThe use case begins with all available records.Define the exact preparation purpose and the minimum PHI fields required for representative cases.Privacy and workflow owners approve purpose, fields, exclusions, and reviewer.Purpose statement, field list, examples, approvers, and date.
2. End-to-end data flowOnly the first vendor receives attention.Map collection, transmission, processing, storage, logs, support access, subprocessors, return, deletion, and downstream systems.Security and system owners validate each boundary.Flow diagram, field-level transfers, owners, regions, and retention questions.
3. Contract and safeguards reviewA marketing label substitutes for organizational review.Match each PHI-handling party to BAA status, permitted use, security responsibility, availability, backup, return, and deletion requirements.Privacy, legal, security, and contracting owners resolve gaps.BAAs, terms, safeguard review, gaps, decisions, and dates.
4. Controlled review workflowPrepared output can move forward without a clear human boundary.Present source-linked output, missing evidence, uncertainty, and permitted reviewer actions without autonomous clinical or consequential administrative action.Authorized people approve, correct, reject, or escalate.Source map, reviewer identity, action, rationale, and downstream reference.
5. Risk and lifecycle decisionApproval is treated as permanent after setup.Document organizational risk findings, pilot scope, incidents, access review, change triggers, vendor recheck, rollback, and termination path.The organization authorizes, limits, pauses, or rejects the pilot.Risk record, pilot decision, runbook, review schedule, and exit evidence.

What the human keeps

The goal is not zero humans. It is zero avoidable preparation around the judgment only a responsible owner should make.

  • Privacy, security, and contracting owners verify the PHI path, BAA needs, safeguards, and open risk.
  • Clinical or administrative owners define minimum data and retain consequential judgment.
  • The organization authorizes the bounded pilot and every material change to data, vendor, purpose, or action.

Controls before volume

A workflow is not ready because the happy path worked once. It is ready when access, review, fallback, and evidence are explicit.

  • Do not send PHI until the complete data flow, BAA status, organizational risk review, and safeguards are approved.
  • Use the minimum PHI required for the approved purpose and restrict access by role.
  • Preserve source evidence and block unreviewed consequential clinical or administrative action.
  • Reassess vendors, subprocessors, retention, data location, configuration, and risk after material change.

The scorecard

Measure capacity, not activity

A system can produce more messages and still make the operation worse. Measure movement through the workflow, the quality of review, and the load that still reaches a person.

PHI path coverage

Approved fields and every system, log, vendor, and subprocessor boundary documented.

Contract closure

PHI-handling parties with resolved BAA and permitted-use review.

Access and data exceptions

Unauthorized, excess-field, wrong-matter, or unsupported transfer events.

Human review integrity

Consequential outputs with source-linked authorized approval before action.

What a fake implementation looks like here

These patterns create an AI demo while leaving the labor, risk, and accountability in the same place.

  • Sending PHI because a vendor advertises a healthcare feature.
  • Reviewing the primary vendor but not subprocessors, logs, or support access.
  • Using more PHI than the bounded task requires.
  • Letting a prepared output become an unreviewed clinical or consequential administrative decision.

Two ways to act

Use the path that matches the decision

Questions

What operators ask before they build

Does signing a BAA finish the review?

No. The organization still needs the full data flow, permitted purpose, minimum data, safeguards, risk analysis, access, review, incident, retention, and lifecycle design.

Does HHS certify AI tools?

HHS guidance does not provide a product endorsement shortcut. The organization must evaluate the actual service, contracts, configuration, and risks.

What can self-serve safely provide?

A compliance-aware planning checklist and open questions. It should not claim that the resulting workflow is HIPAA compliant or approved for PHI use.

Primary references

Controls should come from the specific operating environment

These are broad public control references, not article-specific evidence, vendor endorsements, or legal advice. Validate the current rules, contracts, system configuration, and organization-specific risk before deployment.

Keep mapping

Related implementation guides