HIPAA 病历号检测:无需正则表达式专业知识
每家医院的病历号(MRN)格式各不相同。Memorial 用 MRN:XXXXXXX,St. Mary's 用 PT-YYYYY,University Hospital 用 UHN-XXXXXXXXXX。
HIPAA:医院专属病历号的精准检测
HIPAA安全港要求删除病历号,但MRN格式并无统一标准——Epic、Cerner和Meditech各有不同。通用PII工具会漏掉您机构专属的格式。本指南说明如何通过自定义实体在数小时内消除这一合规漏洞。
HIPAA安全港去标识化的规模化实施
HIPAA安全港要求删除18类特定的PHI标识符。学术医疗中心需要规模化去标识化,但现有工具价格高昂,远超研究经费预算。
ISO 27001 与医疗行业 HIPAA 业务伙伴协议的合规证明
HIPAA 业务伙伴协议要求提供「充分保证」,证明已采取适当的数据保护措施。ISO 27001 与 HIPAA 164 条款的控制要求高度契合,可直接用于满足合规举证需求。
无需编码:HIPAA管道中的自定义MRN检测
医疗记录号因医院而异——每家医疗系统都有自己独特的格式。HIPAA安全港要求移除MRN,而无代码工作流让合规团队无需工程师支持即可完成这项工作。
您的工具遗漏了18项HIPAA标识中的哪些?
HIPAA列出了18类受保护健康信息(PHI)标识,而大多数匿名化工具只能检测其中约6类。各医院的医疗记录号格式各不相同,美国也没有统一的国家标准。
研究中的可逆加密重新识别协议
你无法联系「Patient_001」进行随访。IRB 现在要求记录在案的重新识别协议——证明你在符合伦理条件时「能够」重新识别。
临床研究中的可逆去标识化
当研究在 5,000 名受试者中发现 47 人存在意外的生物标志物风险时,研究人员需要联系真实患者。然而仅有 23% 的匿名化工具支持这一功能。
HIPAA 合规的 ChatGPT:浏览器端 PHI 防护
77% 的员工每周至少向 AI 工具分享一次敏感工作信息。实时浏览器 PHI 拦截可将泄露事件减少 94%。
本地批量处理5万份临床记录:HIPAA合规指南
2026年2月南纽约联邦地区法院裁定,未经匿名化处理便通过AI处理的文件将丧失律师-委托人特权。
大型语言模型遗漏了 50% 的临床 PHI
2025 年一项研究发现,在多语言文档中,LLM 工具遗漏了超过 50% 的临床受保护健康信息(PHI)。34.8% 的 ChatGPT 输入内容包含敏感数据。
可解释的文件遮蔽:HIPAA审计合规指南
HIPAA专家认定方法要求记录在案的方法论。法律电子取证要求每项遮蔽的依据。34%的数据保护官报告现有工具不足以满足自动匿名化合规文档的要求。
云端HIPAA:PHI的零知识保护
业务伙伴协议无法在您的云端AI供应商以明文处理PHI时防止HIPAA违规。了解零知识架构能做什么。
CISO拒绝云端PHI处理的内幕
2024年725起医疗行业数据泄露影响2.75亿条记录。面对平均1022万美元的泄露成本——行业最高——医疗机构CISO正在重新审视云端AI工具。
HHS 2025:AI 临床记录必须拦截 PHI
AI 转录系统可能在无意间将 A 患者的 PHI 写入 B 患者的病历。实时 PHI 检测在 EHR 写入前进行拦截,是关闭这一合规漏洞的关键控制措施。
手写表单 OCR 与 PII 检测:医疗保险行业实践
某中型医院每年处理 5 万份手写入院表单,按此规模人工脱敏 PII 需要 0.5 个全职人力。
HIPAA OCR:2024年725起数据泄露,2.75亿条记录受影响
HHS OCR报告显示,2024年共发生725起HIPAA数据泄露事件,涉及2.75亿条患者记录,创历史最高纪录。医疗数据泄露平均损失高达1022万美元。
PHI检测:Snow Labs 96%对比GPT-4o
并非所有去标识化工具的效果都相同。ECIR 2025基准测试显示F1分数从79%到96%不等。了解准确性为何重要以及如何评估工具。
742万美元:医疗行业数据泄露成本居首
医疗行业连续14年位列数据泄露成本最高的行业。了解为什么PHI如此珍贵以及如何加以保护。
About this page
We update this page when our platform or the law changes.
Read our founder note for how we work.
Each change shows up in the timestamp at the top.
Related reading
We follow these rules
- GDPR (EU 2016/679).
- ISO/IEC 27001:2022.
- NIS2 (EU 2022/2555).
- HIPAA safe harbor under 45 CFR § 164.514(b)(2).
Our promise
We do not sell your data.
We do not train models on your text.
We store your files in Germany.
You can delete your account at any time.
You own your work.
Where we run
Our company HQ is in Saarbrücken, Germany. Our servers run in Hetzner's Falkenstein datacenter.
Hetzner holds ISO 27001 certification.
All data stays in the EU.
Backups run every day.
Need help?
Email support@anonym.legal.
We reply within one business day.
How we test
We run a full check suite on every release.
Each surface gets its own sweep script and report.
Human reviewers spot-check the output each week.
We track recall and precision on a labelled set.
Bad runs block the deploy.
What we never do
- We never sell your information to third parties.
- We never train models on what you upload.
- We never keep your work after you delete it.
- We never share keys with any outside firm.
- We never run ads inside the product.
Plans in plain words
We sell credits, not seats.
One credit covers one short job.
Long jobs use a few credits each.
You can top up at any time.
Unused credits roll over each month.
Read the plans page for current rates.
Who built this
A small team of engineers and lawyers built this.
We ship from Europe and work in the open.
Our founder note spells out why we started.
Where to start
- Open the web app and try a sample file.
- Learn how credits get counted.
- See current plans and limits.
- Meet the team behind the product.
How the parts fit
A browser add-on cleans text inside Chrome.
A Word plug-in handles drafts in Office.
A small desktop tool works on whole folders.
An agent protocol link feeds large models safely.
All four share one core engine and one rule set.
Words from our team
We started this work after a lunch about cookies.
One friend kept getting odd ads on her phone.
We asked why a court file leaked through a draft.
We sketched the first build on a napkin that week.
By month three we had a tiny demo for a friend.
She used it on her first case the next day.
Common questions we hear
Can the tool read scanned PDFs? Yes, with OCR.
Does it work on long files? Yes, in small chunks.
Can I roll my own rule set? Yes, save it as a preset.
Does it run offline? The desktop build runs offline.
Do you keep my files? No, the cloud build wipes after each run.
Will it learn from my work? No, we never train on inputs.
A short tour of the workflow
Upload a file or paste a snippet of prose.
Pick the entities you want gone from the draft.
Choose a method: replace, mask, hash, encrypt, or redact.
Press run and watch the side panel show each hit.
Skim the result and tweak any rule that misfired.
Save the cleaned file or send it to a teammate.