AI PHI Exposure Scanner
Scan AI prompts and outputs for Protected Health Information (PHI).
Last reviewed by the Radiatus Cloud team
Highlighted Text
Securing AI in production?
We build guardrails, governance & compliance for AI systems.
Scan AI prompts and outputs for health data
Protected Health Information appearing in AI prompts or outputs is a serious compliance concern. This tool scans AI prompts and outputs for PHI patterns, so you can catch health data before it is mishandled.
Why PHI needs special care
Health information is among the most strictly regulated categories of personal data, and its appearance in an AI prompt sent to an external service, or in a model’s output, can breach handling rules and harm the individuals concerned. It is easy to introduce accidentally, pasting a clinical note, an insurance record, a message that mentions a condition. Scanning both prompts and outputs for the patterns of health data catches it on the way in and the way out, which is exactly where an AI system in a healthcare-adjacent context needs a control. This is defensive scanning of your own AI data flows.
Catch health data both ways
The tool runs entirely in your browser, so nothing you paste, prompts, outputs or documents, is uploaded, which matters when the input is sensitive AI data or your own content.
Related tools
- AI Prompt Leakage Analyzer — Paste a system prompt and a hostile user input to see whether the prompt holds secrets and whether the input carries injection patterns. Local, instant.
- LLM Data Exposure Checker — Check if text contains data likely to be memorized or exposed by LLMs.
- AI Usage Policy Generator — Generate an acceptable use policy for AI tools in your company.
- Model Hallucination Estimator — Estimate risk of hallucinations based on task type and temperature.
Frequently Asked Questions
What is PHI?
Protected Health Information: personal health data that is strictly regulated. Its appearance in AI prompts or outputs can breach handling rules and harm individuals.
Why scan both prompts and outputs?
Because health data can enter on the way in, in a prompt sent to a service, or emerge on the way out, in a model’s output. Both need catching.
How does PHI end up in a prompt accidentally?
By pasting a clinical note, insurance record or message that mentions a condition, often without realising it contains protected health data.
Is this for my own system?
Yes. It is defensive scanning of AI data flows you operate, especially in healthcare-adjacent contexts.
Is my data uploaded?
No. The scan runs entirely in your browser.
Privacy & Security
Scanning happens locally.
About This Tool
This tool runs entirely in your browser. No data is sent to any server, ensuring complete privacy. Simply use the interface above to get started — no registration or login required.
Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.
Related Tools
AI Prompt Leakage Analyzer
AI SecurityPaste a system prompt and a hostile user input to see whether the prompt holds secrets and whether the input carries injection patterns. Local, instant.
LLM Data Exposure Checker
AI SecurityCheck if text contains data likely to be memorized or exposed by LLMs.
AI Usage Policy Generator
AI SecurityGenerate an acceptable use policy for AI tools in your company.