Skip to main content

PHI Detection

Scrub automatically detects Protected Health Information (PHI) in your API requests to help maintain HIPAA compliance.

What is PHI?

Protected Health Information (PHI) is any health-related information that can be used to identify an individual. Under HIPAA, there are 18 types of identifiers that qualify as PHI when combined with health information.

How Detection Works

When you send a request to Scrub:

  1. Content is scanned - All message content is analyzed for PHI patterns
  2. Matches are identified - Any detected PHI is flagged with its type
  3. Action is taken - Based on your settings, PHI is flagged, blocked, redacted, or masked
  4. Request proceeds - Clean content is forwarded to your AI provider
  5. Audit log created - Detection results are logged for compliance

Detection Coverage

Scrub currently detects 20+ PHI patterns including:

  • Social Security Numbers
  • Medical Record Numbers (MRN)
  • Dates of Birth
  • Phone Numbers
  • Email Addresses
  • Physical Addresses
  • Medicare/Medicaid IDs
  • And more...

See PHI Patterns for the complete list.

Handling Modes

You can configure how Scrub handles detected PHI:

ModeDescription
Flag/AuditDetect and log PHI, but allow request to proceed (default)
BlockReject requests containing PHI
RedactRemove PHI from content before forwarding
MaskReplace PHI with placeholder tokens

See Handling Modes for details on each mode.

Configuration

Configure PHI handling in your Dashboard Settings:

  1. Go to Settings
  2. Find PHI Handling Mode
  3. Select your preferred mode
  4. Save changes

Changes take effect immediately for all new requests.