PHI Guard

The model never sees a real patient

Every one of the 18 HIPAA identifiers gets replaced with a token before a request reaches a model, and restored only in the response, inside your own account. Not encryption in transit, not a policy promise: the identifying data itself never arrives.

Why this needs its own explanation

'HIPAA compliant' usually just means a signed BAA

Encrypted storage and a signed agreement are the baseline every vendor claims. PHI Guard is a different, more specific claim: the AI model itself is never shown the real identifying data in the first place, which is what an actual security review will ask to see proof of.

A diagram showing patient data becoming a token before reaching a model, then resolving back inside the account
01

The 18 HIPAA identifiers get tokenized

Name, date of birth, medical record number, and the rest of the identifiers HIPAA defines as PHI are replaced with tokens before a request leaves your account.

02

The model reasons over tokens

Whatever model is handling the request, GPT, Claude, or another, it only ever sees the de-identified version.

03

The response is restored, inside your account

Tokens resolve back to real patient data only when the answer comes back to you, inside your own encrypted account.

Trusted by independent clinicians

HIPAA CompliantBAA on paid plans18 HIPAA identifiers tokenized

“This is the one thing our security review actually dug into. 'HIPAA compliant' gets said a lot, this is the part that explains what it means here specifically.”

Dr. R. Kapoor

Internal medicine

“As a therapist, this is the one page I actually printed out for my own compliance file.”

J. Liu, LCSW

Behavioral health

Read the full security brief, or talk to our team about your review.

Talk to our team