所有文章医疗保健

医疗保健

HIPAA 合规和 PHI 保护

19 文章

医疗保健

HIPAA 病历号检测:无需正则表达式专业知识

每家医院的病历号(MRN)格式各不相同。Memorial 用 MRN:XXXXXXX,St. Mary's 用 PT-YYYYY,University Hospital 用 UHN-XXXXXXXXXX。

June 4, 20266 分钟
医疗保健

HIPAA:医院专属病历号的精准检测

HIPAA安全港要求删除病历号,但MRN格式并无统一标准——Epic、Cerner和Meditech各有不同。通用PII工具会漏掉您机构专属的格式。本指南说明如何通过自定义实体在数小时内消除这一合规漏洞。

May 30, 20267 分钟
医疗保健

HIPAA安全港去标识化的规模化实施

HIPAA安全港要求删除18类特定的PHI标识符。学术医疗中心需要规模化去标识化,但现有工具价格高昂,远超研究经费预算。

May 25, 20269 分钟
医疗保健

ISO 27001 与医疗行业 HIPAA 业务伙伴协议的合规证明

HIPAA 业务伙伴协议要求提供「充分保证」,证明已采取适当的数据保护措施。ISO 27001 与 HIPAA 164 条款的控制要求高度契合,可直接用于满足合规举证需求。

May 13, 20268 分钟
医疗保健

无需编码:HIPAA管道中的自定义MRN检测

医疗记录号因医院而异——每家医疗系统都有自己独特的格式。HIPAA安全港要求移除MRN,而无代码工作流让合规团队无需工程师支持即可完成这项工作。

April 30, 20268 分钟
医疗保健

您的工具遗漏了18项HIPAA标识中的哪些?

HIPAA列出了18类受保护健康信息(PHI)标识,而大多数匿名化工具只能检测其中约6类。各医院的医疗记录号格式各不相同,美国也没有统一的国家标准。

April 28, 20269 分钟
医疗保健

研究中的可逆加密重新识别协议

你无法联系「Patient_001」进行随访。IRB 现在要求记录在案的重新识别协议——证明你在符合伦理条件时「能够」重新识别。

April 26, 20268 分钟
医疗保健

临床研究中的可逆去标识化

当研究在 5,000 名受试者中发现 47 人存在意外的生物标志物风险时,研究人员需要联系真实患者。然而仅有 23% 的匿名化工具支持这一功能。

April 21, 20269 分钟
医疗保健

HIPAA 合规的 ChatGPT:浏览器端 PHI 防护

77% 的员工每周至少向 AI 工具分享一次敏感工作信息。实时浏览器 PHI 拦截可将泄露事件减少 94%。

April 20, 20268 分钟
医疗保健

本地批量处理5万份临床记录:HIPAA合规指南

2026年2月南纽约联邦地区法院裁定,未经匿名化处理便通过AI处理的文件将丧失律师-委托人特权。

April 11, 20268 分钟
医疗保健

大型语言模型遗漏了 50% 的临床 PHI

2025 年一项研究发现,在多语言文档中,LLM 工具遗漏了超过 50% 的临床受保护健康信息(PHI)。34.8% 的 ChatGPT 输入内容包含敏感数据。

April 2, 20269 分钟
医疗保健

可解释的文件遮蔽:HIPAA审计合规指南

HIPAA专家认定方法要求记录在案的方法论。法律电子取证要求每项遮蔽的依据。34%的数据保护官报告现有工具不足以满足自动匿名化合规文档的要求。

March 27, 20268 分钟
医疗保健

云端HIPAA:PHI的零知识保护

业务伙伴协议无法在您的云端AI供应商以明文处理PHI时防止HIPAA违规。了解零知识架构能做什么。

March 10, 20269 分钟
医疗保健

CISO拒绝云端PHI处理的内幕

2024年725起医疗行业数据泄露影响2.75亿条记录。面对平均1022万美元的泄露成本——行业最高——医疗机构CISO正在重新审视云端AI工具。

March 7, 20269 分钟
医疗保健

HHS 2025:AI 临床记录必须拦截 PHI

AI 转录系统可能在无意间将 A 患者的 PHI 写入 B 患者的病历。实时 PHI 检测在 EHR 写入前进行拦截,是关闭这一合规漏洞的关键控制措施。

March 6, 20269 分钟
医疗保健

手写表单 OCR 与 PII 检测:医疗保险行业实践

某中型医院每年处理 5 万份手写入院表单,按此规模人工脱敏 PII 需要 0.5 个全职人力。

March 6, 20267 分钟
医疗保健

HIPAA OCR:2024年725起数据泄露,2.75亿条记录受影响

HHS OCR报告显示,2024年共发生725起HIPAA数据泄露事件,涉及2.75亿条患者记录,创历史最高纪录。医疗数据泄露平均损失高达1022万美元。

March 6, 202610 分钟
医疗保健

PHI检测:Snow Labs 96%对比GPT-4o

并非所有去标识化工具的效果都相同。ECIR 2025基准测试显示F1分数从79%到96%不等。了解准确性为何重要以及如何评估工具。

February 24, 20267 分钟
医疗保健

742万美元:医疗行业数据泄露成本居首

医疗行业连续14年位列数据泄露成本最高的行业。了解为什么PHI如此珍贵以及如何加以保护。

February 20, 20269 分钟

今天就开始保护您的数据

285+ 种实体类型,48 种语言,企业级安全,初创公司定价。

About this page

We update this page when our platform or the law changes.

Read our founder note for how we work.

Each change shows up in the timestamp at the top.

We follow these rules

  • GDPR (EU 2016/679).
  • ISO/IEC 27001:2022.
  • NIS2 (EU 2022/2555).
  • HIPAA safe harbor under 45 CFR § 164.514(b)(2).

Our promise

We do not sell your data.

We do not train models on your text.

We store your files in Germany.

You can delete your account at any time.

You own your work.

Where we run

Our company HQ is in Saarbrücken, Germany. Our servers run in Hetzner's Falkenstein datacenter.

Hetzner holds ISO 27001 certification.

All data stays in the EU.

Backups run every day.

Need help?

Email support@anonym.legal.

We reply within one business day.

How we test

We run a full check suite on every release.

Each surface gets its own sweep script and report.

Human reviewers spot-check the output each week.

We track recall and precision on a labelled set.

Bad runs block the deploy.

What we never do

  • We never sell your information to third parties.
  • We never train models on what you upload.
  • We never keep your work after you delete it.
  • We never share keys with any outside firm.
  • We never run ads inside the product.

Plans in plain words

We sell credits, not seats.

One credit covers one short job.

Long jobs use a few credits each.

You can top up at any time.

Unused credits roll over each month.

Read the plans page for current rates.

Who built this

A small team of engineers and lawyers built this.

We ship from Europe and work in the open.

Our founder note spells out why we started.

Where to start

How the parts fit

A browser add-on cleans text inside Chrome.

A Word plug-in handles drafts in Office.

A small desktop tool works on whole folders.

An agent protocol link feeds large models safely.

All four share one core engine and one rule set.

Words from our team

We started this work after a lunch about cookies.

One friend kept getting odd ads on her phone.

We asked why a court file leaked through a draft.

We sketched the first build on a napkin that week.

By month three we had a tiny demo for a friend.

She used it on her first case the next day.

Common questions we hear

Can the tool read scanned PDFs? Yes, with OCR.

Does it work on long files? Yes, in small chunks.

Can I roll my own rule set? Yes, save it as a preset.

Does it run offline? The desktop build runs offline.

Do you keep my files? No, the cloud build wipes after each run.

Will it learn from my work? No, we never train on inputs.

A short tour of the workflow

Upload a file or paste a snippet of prose.

Pick the entities you want gone from the draft.

Choose a method: replace, mask, hash, encrypt, or redact.

Press run and watch the side panel show each hit.

Skim the result and tweak any rule that misfired.

Save the cleaned file or send it to a teammate.