What is protected health information (PHI)?
Protected health information (PHI) is individually identifiable health information covered by HIPAA. The HIPAA Security Rule requires administrative, physical, and technical safeguards to protect the confidentiality, integrity, and availability of electronic PHI. Examples include risk analysis, access controls, audit logs, and encryption.
What the buyer is really asking
This maps to the HIPAA Security Rule: administrative, physical, and technical safeguards for PHI. Point to controls you already describe elsewhere (encryption, access control, audit logs, backups) and show how they apply to PHI. A HIPAA risk analysis is the document buyers most want to see.
Other ways buyers ask it
Every one of these wants the same answer:
- “How do you ensure the confidentiality, integrity, and availability of PHI?”
- “What HIPAA Security Rule safeguards do you have in place?”
- “Have you completed a HIPAA security risk analysis?”
Evidence to have ready
- A HIPAA security risk analysis
- A mapping of your controls to the HIPAA Security Rule
- A third-party HIPAA assessment, if you have one
How Tyrvar answers this
Tyrvar treats every wording above as one question. You write the answer once, attach the evidence, and revisit it when your setup changes. Each buyer gets that approved answer no matter how their questionnaire words it. If you have not answered it yet, Tyrvar flags the question for you and does not make something up. Try it on your own questionnaire.