AI Security

AI PHI Exposure Scanner

Scan AI prompts and outputs for Protected Health Information (PHI).

Last reviewed by the Radiatus Cloud team

ℹ️ What is PHI? Protected Health Information includes names, dates, phone numbers, email addresses, medical record numbers, SSNs, and any health-related data that can identify an individual.

Securing AI in production?

We build guardrails, governance & compliance for AI systems.

Talk to an AI advisor

Scan AI prompts and outputs for health data

Protected Health Information appearing in AI prompts or outputs is a serious compliance concern. This tool scans AI prompts and outputs for PHI patterns, so you can catch health data before it is mishandled.

Why PHI needs special care

Health information is among the most strictly regulated categories of personal data, and its appearance in an AI prompt sent to an external service, or in a model’s output, can breach handling rules and harm the individuals concerned. It is easy to introduce accidentally, pasting a clinical note, an insurance record, a message that mentions a condition. Scanning both prompts and outputs for the patterns of health data catches it on the way in and the way out, which is exactly where an AI system in a healthcare-adjacent context needs a control. This is defensive scanning of your own AI data flows.

Catch health data both ways

The tool runs entirely in your browser, so nothing you paste, prompts, outputs or documents, is uploaded, which matters when the input is sensitive AI data or your own content.

Related tools

Frequently Asked Questions

What is PHI?

Protected Health Information: personal health data that is strictly regulated. Its appearance in AI prompts or outputs can breach handling rules and harm individuals.

Why scan both prompts and outputs?

Because health data can enter on the way in, in a prompt sent to a service, or emerge on the way out, in a model’s output. Both need catching.

How does PHI end up in a prompt accidentally?

By pasting a clinical note, insurance record or message that mentions a condition, often without realising it contains protected health data.

Is this for my own system?

Yes. It is defensive scanning of AI data flows you operate, especially in healthcare-adjacent contexts.

Is my data uploaded?

No. The scan runs entirely in your browser.

Privacy & Security

Scanning happens locally.

Data: None
Client-side-Side
Active
v1.0

About This Tool

This tool runs entirely in your browser. No data is sent to any server, ensuring complete privacy. Simply use the interface above to get started — no registration or login required.

Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.