Docs / HIPAA / PHI

HIPAA / PHI

A workspace pack on the same core masking engine — not a second SDK. When entitled, hipaa_phi is merged into enabled_packs and force-enables email, phone, nationalId, and passport for Shield, SDK, and CLI --key scans.

On this page+

What it does

  • Force-on via pack merge into enabled_packs — same resolution order as PCI / Financial and Secrets Guard.
  • Uses the existing email, phone, national ID, and passport detectors — no separate PHI engine in this soft launch.
  • Related toggles remain visible under Policies → Contact, Identity, and Travel; with the pack enabled they stay active at runtime even if those toggles are off.

What it is not

  • Not a HIPAA / HITECH certification or BA attestation.
  • Not dedicated MRN, NPI, ICD, or clinical-note detectors (roadmap).
  • Not network DLP — masking runs on-device / in-process before the model call.

Entitlement

  • Industry pack — $49/mo on Startup+ from Dashboard → Add-ons. Never plan-included (including Business+).
  • Developer must upgrade to Startup before Subscribe is available.
  • Ops can still grant via enterprise_grant for partners; when Active the pack appears in enabled_packs.
  • See also limitations and on-device architecture.