"We Don't Store PHI" Is Not Your Differentiator

A CEO interrupted our governance committee meeting last month with one question.

"Does this tool have prevention controls?"

We were evaluating an AI vendor for adoption.

The product was solid.

Pricing made sense.

But the CEO cared about something most vendors don't prepare for.

Whether the tool would stop her workforce from putting PHI somewhere it shouldn't be.

That's the moment the conversation shifted from product evaluation to risk evaluation.

The CEO's question wasn't unusual.

Storing PHI and allowing PHI to be submitted are two different controls.

The Question Buyers Are Now Asking Twice

For years, "we don't store PHI" was a great answer.

It signaled the vendor had thought about data protection.

It satisfied the procurement team.

It moved the deal forward.

Not anymore.

Healthcare buyers have realized that storage is only half the question.

The other half is prevention.

They're now asking:

"What happens to PHI stored in your system?" (retention)

And:

"What stops PHI from entering your system?" (prevention)

Same topic.

Two different controls.

Most vendors only have one of them.

๐Ÿ‘‰ If you're fielding security questionnaires and seeing these questions, the Security Review Playbook breaks down what buyers are looking for and how to respond. Request it here.

Retention vs. Prevention: The Difference That's Costing Deals

Retention is what happens after data lands in your system.

Prevention is what stops it from landing in the first place.

A vendor with strong retention controls might delete PHI on a 30-day cycle.

A vendor with strong prevention controls makes sure PHI couldn't be submitted to begin with.

Both matter.

But only one protects against the damage that's already done.

Because the damage isn't always in the storage.

It's in the submission.

The moment a clinician types a patient's name into your tool...

The moment a staff member uploads a record...

The moment someone copies a care plan into your chat interface...

That's when the breach happens.

Whether you store it for 30 seconds or 30 years doesn't change the fact that PHI left the building.

The Operational Reality Vendors Miss

A vendor can delete PHI the moment it hits their system and still be a liability.

The BAA doesn't fix unauthorized submission.

The deletion policy doesn't fix unauthorized submission.

Only active prevention does.

This is the gap healthcare governance committees are now scrutinizing.

They've watched their own staff bypass policy to get work done faster.

They've updated their enforcement protocols.

And they're carrying that same scrutiny into every vendor review.

If your product allows free-form input where PHI could land, you need to answer for both questions.

Not just one.

๐Ÿ‘‰ If your product involves any system where staff can input or upload data, the Health Tech AI Readiness Self-Assessment maps your prevention controls against what healthcare buyers are evaluating. Know your gaps before your buyer finds them. Get your score here.

What Active Prevention Looks Like

Prevention isn't a single control.

It's a combination of policy, technology, and enforcement working together.

Policy: Documented rules about what data can and can't be entered into your system. Clear guidance for end-users on what's allowed.

Technology: Input validation. Content filtering. Role-based access controls. PHI detection at the point of entry. Audit trails of what was attempted, not just what was submitted.

Enforcement: Active monitoring of how your system is being used. Workforce training that's reinforced, not just delivered once. Consequences for misuse documented and applied consistently.

These are the prevention standards health systems are implementing and every AI product must have the technology controls.

Health systems own the policy.

Health systems own the enforcement.

But the technology has to come from the vendor.

No technology, no deal.

Why This Will Become the Standard

Healthcare buyers are asking these questions because they've been burned before.

They've watched their own workforce bypass policy.

They've seen vendors with clear retention answers become liabilities.

They've updated their enforcement protocols internally.

And they're carrying that same scrutiny into every vendor review they conduct.

The vendors who pass these reviews build for prevention first.

The vendors who don't are still saying "we don't store PHI" and wondering why deals stall.

What This Means for Your Next Security Review

Audit your current PHI controls against both questions.

What happens to PHI inside your system? (Retention)

What stops PHI from entering your system in the first place? (Prevention)

Document the difference before they ask.

Build the controls before they're required.

Position your compliance program as the answer to both questions, not just one.

๐Ÿ‘‰ If you're building toward enterprise health system deals and want to know exactly what buyers are evaluating before they ask, the Security Review Playbook lays out the 5 things they score in every vendor review. Request it here.

L Trotter II

As Founder and CEO of Inherent Security, Larry Trotter II is responsible for defining the mission and vision of the company, ensuring execution aligns with the business purpose. Larry has transformed Inherent Security from a consultancy to a cybersecurity company through partnerships and expert acquisitions. Today the company leverages its healthcare and government expertise to accelerate compliance operation for clients.

Larry has provided services for 12 years across the private industry developing security strategies and managing security operations for Fortune 500 companies and healthcare organizations. He is influential business leader who can demonstrate the value proposition of security and its direct link to customers.

Larry graduated from Old Dominion University with a bachelorโ€™s degree in Business Administration with a focus on IT and Networking. Larry has accumulated certifications such as the CISM, ISO27001 Lead Implementer, GCIA and others. He serves on the Board of Directors for the MIT Enterprise Forum DC and Baltimore.

https://www.inherentsecurity.com
Previous
Previous

What Does HIPAA Compliant AI Look Like for Health Tech?

Next
Next

The AI Questions Healthcare Buyers Are Asking: Inside a Governance Committee