Protected health information (PHI) / HIPAA
In one sentence
Health data protected by the HIPAA law, relevant to medical practices and any business handling patient information.
PHI is individually identifiable health information. Businesses that handle it (providers, and their 'business associates') must meet the HIPAA Security Rule's safeguards. Cyber applications ask about HIPAA when your industry touches health data.
Why it's on your cyber insurance application
Healthcare-adjacent applicants get extra scrutiny; HIPAA documentation overlaps with cyber readiness.
The written evidence carriers accept
A “yes” on the application needs a document behind it. In the Readiness Pack, that document is:
Related terms
Would you pass this question today?
The free Readiness Check scores you across the ten control domains carriers probe, in five minutes, no email required for the score.