Protected Health Information (Security)

Protected Health Information (Security)

Protected Health Information (Security)

Security obligations for protected health information include risk analysis, workforce training and sanctions, access controls with unique user identification, audit controls, integrity verification, and transmission security.

Requirements apply to covered entities and business associates including law firms.

Alternative Names:

PHI Security, Securing PHI

Why it Matters?

The risk analysis requirement is the foundational obligation and the one most often absent in law firms, since it requires a documented assessment of where protected health information resides and what threats apply. Enforcement actions frequently cite its absence as the underlying failure. For a firm handling medical records across litigation matters, the analysis must cover the review platforms, vendors, and devices where that data actually sits.

Frequently Confused with

Related terms

Frequently asked questions

What is the foundational requirement?

What is the foundational requirement?

A documented risk analysis identifying where protected health information resides and what threats apply, whose absence is frequently cited in enforcement.

Does it apply to law firms?

Does it apply to law firms?

Yes, as business associates handling protected health information, with direct compliance obligations rather than obligations flowing only through the client.