There is no upload endpoint — your files are processed in this browser tab. Open your network tab and check. See how it stays private.
How to check data for HIPAA Safe Harbor identifiers
- Add a file. Drop the dataset you plan to de-identify.
- Scan for identifiers. Columns are mapped to the 18 Safe Harbor identifier categories with masked samples.
- Review. Confirm which columns hold PHI and how they should be handled.
- Scrub. Apply the Safe Harbor preset to mask or remove the flagged fields.
De-identifying health data under Safe Harbor means accounting for 18 specific identifier types — easy to miss one by eye. This checklist maps your columns against those categories and shows masked samples so you can verify what each column actually contains.
The one-click preset then scrubs the flagged fields. Treat it as a careful first pass, not a compliance guarantee: it's not legal advice, and an expert determination may still be required. For general identifiers, use the PII scrubber.
Frequently asked questions
What are the 18 Safe Harbor identifiers?
HIPAA's Safe Harbor method lists 18 identifier types — names, geographic subdivisions, dates, contact details, SSNs, record numbers, and more — that must be removed to de-identify data.
Does passing this make my data HIPAA-compliant?
No. This is a pre-flight helper that flags likely PHI columns; it is not legal advice and doesn't certify compliance. Confirm with a qualified expert before releasing data.
Is my data uploaded to check it?
No. The scan and any scrub run entirely in your browser, which is essential for health data that must not leave controlled systems.