I'm rather in a tricky situation. Here's the scenario : Can I host multitenant PHI data in one database? Let me explain. I've a customer (in this case for me this is a hospital) and they have their own patient records, and we have programmed in a way that only our customer (again, this this case for me this is a hospital) can see only their patient records. We have multiple customers who are linked to the patient records. So, is this a good design or what's HIPAA's recommendation? Your help would be great.

