Healthcare

The task is legitimate. The destination is the problem.

Your staff summarise long notes, rewrite discharge instructions in plainer language, and draft prior-authorisation appeals. Itzal finds the PHI in that text on the clinician's own device and stops it before it is sent — without PHI ever reaching us.

CLINICAL NOTE NAME DOB MRN HEALTH CONTEXT IDENTIFIER + CONTEXT = PHI
A phone number in a signature is not PHI. The same number beside a discharge summary is.
Built for Health systems Provider groups Payers Business associates Digital health

What’s specific here

Four things general-purpose DLP gets wrong.

Clinical language is not like other corporate text. A tool tuned for finance will either flood your privacy office with noise or miss the disclosure that actually matters.

Context decides what is PHI

A phone number in a signature block is not PHI. The same number beside “discharge summary” and a date of birth is. Itzal fires HIPAA severity only when an identifier co-occurs with health context terms — and that term list is yours to edit, because a hospital directory would otherwise generate constant noise.

Stripping the name is not de-identification

Safe Harbor requires removing all eighteen identifier categories, including dates more specific than year and geography below state level. Staff who believe they de-identified a note usually have not.

A vendor holding PHI is a second breach surface

Cloud-inspection DLP makes your security tool a recipient of the very data you are protecting — a second BAA and a second place to be breached. Itzal’s servers cannot hold PHI, because they never receive it.

Clinicians will not tolerate latency

Anything that adds perceptible delay to documentation gets escalated out of the environment within a week, and an uninstalled agent protects nothing. Itzal hard-releases the submit rather than making anyone wait.

De-identification

This note has had the name removed.

It is still PHI. Three of the eighteen Safe Harbor identifiers are present, and every one of them would survive a find-and-replace on the patient’s name.

62-year-old male, admitted 3 March, MRN 4471102, resident of Bellevue, presenting with…

A date more specific than year, a medical record number, and a geographic subdivision below state level. Invented data.

The eighteen Safe Harbor identifiers

  • Names
  • Geography below state
  • Dates except year
  • Phone
  • Fax
  • Email
  • SSN
  • Medical record number
  • Health plan beneficiary number
  • Account numbers
  • Certificate & licence numbers
  • Vehicle identifiers
  • Device identifiers & serials
  • URLs
  • IP addresses
  • Biometric identifiers
  • Full-face photographs
  • Any other unique code

What counts as PHI in a prompt

Deployment

A rollout that survives contact with a clinical floor.

Enforcement before tuning is how a DLP deployment gets reversed. Each stage below exists to earn the right to the next one.

  1. 01

    Sanction a tool

    An enterprise tenant under a BAA, and good enough that people actually prefer it. Prohibition without an alternative reliably produces unmonitored use on personal phones.

  2. 02

    Log-only pilot

    One department, two to four weeks. Nothing is blocked. The point is to measure false positives against real clinical language rather than against a test corpus.

  3. 03

    Tune

    Health context terms, plus exception lists for test data, training material and the sample records that live in every training environment.

  4. 04

    Warn

    Watch the dismissal rate. High click-through means precision needs work — it does not mean the warning needs to be louder.

  5. 05

    Block on unsanctioned destinations

    HIPAA findings are blocked to anything without a BAA, while the sanctioned tool stays the path of least resistance.

On speed. Itzal budgets a p99 of 15 ms on the pattern path, and is designed to hard-release the submit at 250 ms whatever the detector is doing. Clinical staff have the least tolerance in any organisation for a tool that slows them down, and the rate of those released events is a health metric in your console rather than something hidden.

Before you size other controls

What Itzal does not see here.

These gaps matter disproportionately in healthcare, because a screenshot of a patient list and an attached census export are both ordinary workflows rather than edge cases.

Read the full coverage matrix

Not currently inspected

  • File attachments — including a census export or a scanned record.
  • Pasted screenshots, such as an image of a patient list or an EHR screen.
  • AI assistants built into productivity suites, which have no composer to hook.
  • Mobile devices.

Straight answers

Does Itzal itself need a BAA?

Itzal’s servers never receive PHI, because detection and redaction happen on the device. Many healthcare customers still execute a BAA as a matter of policy, and that is straightforward — but the architecture is designed so that a breach of Itzal’s infrastructure could not expose PHI.

Will it flag every phone number in the organisation as PHI?

No. HIPAA severity fires only when an identifier co-occurs with health context terms, and that term list is editable per organisation. Without it, a hospital’s own directory would generate constant false positives.

Can clinicians still use AI tools?

Yes — that is the intended outcome. Sanction a tool under a BAA, then use policy to make the sanctioned destination the path of least resistance while blocking PHI to everything else.

Not legal advice. Whether a particular disclosure is reportable is a determination for your privacy officer and counsel, not for a vendor.

Bring your own clinical language.

The useful demo is the one run against notes that read like yours. Bring a de-identified sample and the AI tools your staff already use.