Privedge
Dashboard
HIPAA · HITECH · PHI Protection

Analyze health records without exposing protected health data.

Architectural HIPAA compliance. Not a BAA. Not a promise. A technical guarantee that PHI is tokenized before it leaves your network.

For: HIPAA Security Officers · Healthcare IT Teams

The problem

  • A BAA does not prevent PHI exposure.
    Cloud model still processes raw patient data.
  • Cloud provider logs your queries.
    PHI in vendor systems = HIPAA violation.
  • One breach = massive liability.
    OCR fines up to $1.9M per violation category.

The solution

The model never sees PHI. Not once.

PHI tokenized at the edge. The model never sees patient data — not in transit, not in memory. Every request returns pii_matches and routed_to, giving you a complete OCR-ready audit trail from request one.

HIPAAHITECHGDPR Art. 9OCR Audit-Ready

HIPAA § 164.514(b)

"Health information is de-identified when all 18 identifiers are removed and the covered entity has no actual knowledge that the remaining information could be used to identify the individual."

Live interception demo
$ intercept --anonymize

18 HIPAA Safe Harbor identifiers removed. Zero PHI reaches the cloud.

Frequently asked questions

Is Claude HIPAA compliant now that Anthropic offers a BAA?

Anthropic now offers BAA coverage for Claude API under HIPAA-ready configurations — which confirms the sector needs it, but does not make your application compliant. Under that BAA, PHI still travels to Anthropic servers, is retained for 30 days, and is processed in their infrastructure. Privedge operates on a different principle: PHI is tokenized before it leaves your network, so Anthropic (or any provider, BAA or not) never receives identifiable data at all.

Is OpenAI HIPAA compliant?

OpenAI offers a BAA for its API, but a BAA alone does not make your application compliant — you remain responsible for safeguards and minimum-necessary use. Privedge ensures PHI never reaches the provider at all, taking it out of the compliance boundary.

Is tokenized PHI still PHI under HIPAA?

The token is not identifiable as long as the re-identification map stays under your control. That mapping lives in your infrastructure and is never sent to the model, so the provider never holds identifiable data.

Does Privedge meet the HIPAA de-identification standard?

Privedge applies Safe Harbor-style removal of the 18 identifiers (§164.514(b)) before egress. Because tokenization is reversible on your side, treat it as a strong safeguard within your environment — not as irreversible de-identification of your own records.

What about audit logs and the minimum-necessary rule?

Privedge stores only metadata (timestamp, routed_to, pii_matches, latency) and never prompt content — supporting both audit requirements and data minimization.

Architectural HIPAA compliance, not paperwork.

Get started → Talk to us