HIPAA PHI Detector
Scan a PDF for likely PHI (protected health information) — SSNs, dates of birth, phone numbers, email addresses, and MRN-shaped strings — with page numbers and remediation suggestions.
1. Upload your file
How does the HIPAA PHI Detector work?
Scan a PDF for shapes that look like Protected Health Information (PHI) — SSNs, dates of birth, phone numbers, emails, MRN-style identifiers, member/policy IDs — and add any patient surnames or specific terms you supply. The result is a per-page list of findings with surrounding context, ranked so you can see exactly what to redact. This is a deterministic regex-based detector, not an LLM — it will catch shaped data (the format of an SSN) but cannot identify a free-text patient name without you supplying it. Once you have the list, use Permanent Redaction (true content removal) or Redact PDF (visual blackout) to actually remove the data from the file.
🔒 Security & Privacy
All processing happens on your device. Your files never leave your browser, never touch our servers, and are not stored anywhere. Close the tab and the file is gone.
📱 Use it on any device
Works in any modern browser — Mac, Windows, Linux, iPhone, Android, and tablets. No installation, no app to download. Just open the page and start.
⚡ Quick & easy
Drag, drop, click. Most files process in seconds, not minutes. No watermarks added to your output, no per-day limits, and the tool always shows the result before asking you to download.
🎁 Always free, no signup
Free to use, every time. No account creation, no email required, no “trial” that converts to a paid plan. We make money from ads so you don’t have to pay.
Frequently asked
Related PDF tools
More tools you might like
Hand-picked tools that pair well with this one — same audience, same intent.
Find text and cover it with black rectangles — visual redaction. For full text-stream removal, use a paid pro tool.
Genuinely remove sensitive content by rasterising the affected pages and burning black rectangles into the bitmap — the underlying text is gone, not just hidden.
Pull every filled-in form value out of a PDF and write a tidy CSV — one column per field, one row of values.
Heuristic accessibility audit — checks document language, title metadata, tagged-structure flags, bookmarks, form-field labels, and more.
Scan a PDF for SSNs, credit-card numbers, email addresses, and phone numbers — report locations with redaction-ready coordinates so you can target a redaction pass.
Stamp a configurable confidentiality marker (header band + footer band, with optional date and recipient) onto every page of a PDF.
Provide a regex; every match is rasterised over with a black box on each page. Catch SSNs, internal codes, names, anything that follows a stable pattern.
Full HIPAA-compliant authorization (45 CFR 164.508) for use or disclosure of PHI — including marketing, research, and psychotherapy notes when applicable.