What is protected health information?
- PHI
- Protected health information is health information that identifies an individual and is created or held by a covered entity or its business associates under HIPAA.
What PHI means in practice
Two things have to be true. The information relates to health, care or payment for care, and it identifies somebody.
The identifying part is broader than a name. Dates, contact details and record numbers all count, which is why de-identification is genuinely difficult.
A phone call to a practice can create it in one sentence. A caller saying who they are and why they need an appointment has done both halves.
The rules attach to covered entities and to the vendors handling information on their behalf, under a written agreement.
What people get wrong
The same voicemail, with and without health details
Say a caller leaves this for your physical therapy office: "Hi, it's Maria Gomez, 555 0188. I need to move my Tuesday appointment." You now hold a name and a number tied to a booking at a named practice. That's already sensitive, since it shows she's a patient there.
Now the longer version: "It's Maria Gomez. My knee is still swelling after the ACL surgery and the pain pills aren't doing much, so can I come in sooner?" In 25 words she has linked her identity to a surgery, a symptom and a medication. Whatever system stored that message now holds exactly what HIPAA was written to protect. So does every service the audio passed through on its way to your inbox. Callers don't know where your scope ends, and they'll tell a machine whatever they'd tell a front desk.
Keeping a phone assistant on the scheduling side of the line
You can shape what callers volunteer. A greeting that asks "Are you calling to book or change a visit?" gets shorter answers than "How can I help you today?" Some callers will start describing symptoms anyway. Your assistant's line should stop them kindly and route them on: "I can't take medical details, so let me get you to the clinical team."
Review a sample of summaries each week, and look for clinical words that got through. If they keep appearing, tighten the opening question or shorten how long those records live.
Here's what getting it wrong costs. HIPAA's breach rules can require your practice to notify every affected patient, and for larger breaches the federal regulator and local media as well. That's before any fine. Identity under the law is broad, too. Its de-identification standard lists 18 kinds of identifier, including phone numbers and any date more exact than a year. A callback number beside a symptom is enough.
How GreetKeeper handles it
GreetKeeper makes no HIPAA claim and holds no business associate agreement. That is a limitation, stated plainly, and it should be part of your decision.
Practices that use it keep the assistant scoped to inquiries and scheduling, with clinical detail staying in their own system.
Utah requires a verbal disclosure at the start for licensed occupations, including medicine, so switch the AI notice on if you are one.
Health information questions
Can a dental practice use an AI receptionist?
Many do, for booking and general inquiries. The scope of what it handles is the decision, and your own counsel should be part of making it.
Is an appointment time health information?
Tied to a named person and a specific practice, it can be. That is why scheduling data is treated carefully even when no diagnosis is mentioned.
What should I ask a vendor?
Which layers they hold signed agreements with. Carrier, transcription, language model, voice. The specificity of the answer tells you most of what you need.
Hear it take one of your calls
Two minutes, your own scenario, no card.