Healthcare has held the highest breach cost of any industry for 14 consecutive years. The average healthcare breach costs significantly more than any other sector, driven by regulatory penalties and long detection times.
Names, dates, SSNs, medical record numbers, IP addresses, biometric data, and more. Any one of these in a prompt creates a compliance exposure if it reaches an external AI model.
Because Shield runs locally on your infrastructure, it never stores, transmits, or processes PHI on Purfect Labs servers. No BAA required — your compliance scope doesn't expand.
HIPAA penalties escalate fast
HIPAA civil money penalties are tiered by culpability. Even a single PHI exposure caused by an employee pasting patient data into an AI tool can trigger an OCR investigation. The Department of Health and Human Services has issued resolution agreements totaling millions of dollars against healthcare organizations. Shield eliminates this vector entirely — PHI can't leak through AI prompts because it never leaves your network in the first place.
Interactive Demo
What PHI Looks Like in AI Prompts
Three real-world scenarios where healthcare staff send PHI to AI models. Click each tab to see the raw prompt with identifiable patient data — and how Shield redacts it before it leaves your network.
Compliance
How Shield Maps to HIPAA Security Rule
The HIPAA Security Rule establishes national standards for protecting electronic protected health information. Shield's local proxy architecture satisfies multiple Security Rule requirements without adding cloud dependencies to your compliance scope.
| HIPAA Security Rule | Ref | Requirement | How Shield Satisfies It |
|---|---|---|---|
| Access Control | §164.312(a)(1) | Implement technical policies and procedures for electronic information systems that maintain PHI to allow access only to authorized persons or software programs. | Shield runs locally with OS-level access controls. Only authorized users on the host machine can start or configure the proxy. No remote access to redaction engine. |
| Audit Controls | §164.312(b) | Implement hardware, software, and/or procedural mechanisms that record and examine activity in information systems that contain or use PHI. | Shield's tamper-evident audit trail records every prompt sanitization event with cryptographic hashing. Every redaction — what was caught, when, by which filter pack — is logged with a verifiable chain of custody. |
| Integrity | §164.312(c)(1) | Implement policies and procedures to protect PHI from improper alteration or destruction. | Shield's redaction is non-destructive — the original prompt is never modified in-place. Redacted values are replaced with placeholders, and the mapping stays on your machine. Audit logs track every transformation. |
| Person or Entity Authentication | §164.312(d) | Implement procedures to verify that a person or entity seeking access to PHI is the one claimed. | Shield integrates with your existing SSO and identity provider. Only authenticated users can configure filter packs, view audit logs, or modify redaction policies. |
| Transmission Security | §164.312(e)(1) | Implement technical security measures to guard against unauthorized access to PHI being transmitted over an electronic communications network. | Shield redacts PHI before transmission. The data that leaves your network contains no identifiable patient information — only placeholders. Even if the transmission were intercepted, no PHI is exposed. |
Architecture
PHI Never Leaves Your Network
Shield runs as a local proxy on your hospital's machines. When a clinician, biller, or administrator sends a prompt to an AI model, Shield intercepts it — redacts all PHI — and only then forwards the clean prompt to the external LLM. The redaction mapping stays on your machine.
Local Installation
Install Shield on any Mac, Windows, or Linux machine. No cloud infrastructure, no vendor data access, no data leaves your network.
One Environment Variable
Set SHIELD_PROXY_URL and every AI call from that machine flows through Shield automatically. Zero code changes to your existing tools.
Full Audit Trail
Every redaction event is logged with a cryptographic hash. Prove to auditors exactly what PHI was caught and when — with tamper-evident integrity.
Configurable Policies
Choose which PHI categories to redact. Add custom patterns for your facility's internal coding systems. Run in audit-only mode to validate coverage first.
Ready to Protect Patient Data in AI Workflows?
Shield runs on your hospital's existing infrastructure. No cloud. No BAA. No PHI leaves your network. Deploy in under an hour and give your clinical teams the AI tools they need — safely.