Protect patient data at the source.
Piixie detects and anonymizes PHI in clinical notes, lab results, discharge summaries, and insurance claims without uploading a single byte to the cloud.
What Piixie detects in medical records.
Piixie identifies and anonymizes all 18 HIPAA PHI identifiers plus clinical data elements across every record type your facility produces.
Patient identifiers
Full names, medical record numbers, health plan IDs, Social Security numbers, account numbers, and certificate or license numbers.
Clinical details
Diagnosis codes (ICD-10), procedure codes (CPT), medications, dosages, lab values, and vital signs.
Provider information
Physician names, attending and referring doctors, facility names, department codes, and provider license numbers.
Dates and timestamps
Admission dates, discharge dates, surgery dates, dates of service, appointment dates, and dates of death.
Contact and location
Addresses, phone and fax numbers, email addresses, and geographic subdivisions smaller than a state.
Digital and biometric
IP addresses, device serial numbers, biometric identifiers, full-face photos, web URLs, and portal credentials.
Lab report, before and after.
Piixie detects PHI across structured fields, patient demographics, and provider information in medical records.
How Piixie processes medical records.
From ingestion to de-identified output, every step happens on your machine. No data ever crosses a network boundary.
1. Load medical record
Drop a clinical note, lab report, discharge summary, or insurance claim into Piixie. PDF, DOCX, spreadsheets, images, and DICOM metadata are all supported.
2. Detect all 18 PHI categories
The local LLM scans extracted text for patient names, MRNs, dates, provider information, clinical details, contact data, and digital identifiers.
3. Anonymize
Choose your mode: redact with black bars, replace with stable tokens like [PATIENT_1], or synthesize realistic fake data using the local Faker engine.
4. Export de-identified copy
The anonymized document is saved locally. The original is never modified. A full audit trail records every detected entity and the action taken.
Regulatory frameworks Piixie addresses.
Local processing eliminates entire categories of compliance risk across every framework that governs medical data.
- PHI stays entirely on your premises. Piixie never transmits patient data to external servers, cloud APIs, or remote processing environments.
- The minimum necessary standard is enforced automatically: Piixie detects and redacts only the PHI categories present, preserving clinical utility in the output.
- No Business Associate Agreement is required for the anonymization step because no third party ever accesses the PHI.
- De-identified data produced by Piixie falls outside HIPAA's scope and can be shared for research, analytics, or AI training without triggering disclosure rules.
- Redaction before sharing with AI tools or LLMs prevents accidental PHI exposure in prompts, fine-tuning datasets, or model training data.
- Audit trails document exactly which PHI elements were detected and redacted, supporting compliance documentation for OCR audits and IRB reviews.
How medical teams use Piixie.
From research departments to compliance offices, Piixie fits into existing clinical and administrative workflows.
De-identify for clinical research
Share patient data with IRBs, research partners, and academic collaborators. Piixie produces de-identified datasets that fall outside HIPAA's scope, eliminating the need for individual patient consent for each study.
Sanitize for AI/ML training
Feed clinical notes, discharge summaries, and lab reports into ML pipelines without leaking PHI. Train diagnostic models, NLP systems, and clinical decision support tools on safe data.
Inter-facility data exchange
Strip PHI before sharing records across organizations, health information exchanges, or with payers. Maintain clinical utility while eliminating re-identification risk during data exchange.
Compliance audit preparation
Every Piixie run produces a detailed log of what was detected, what category it belongs to, and what action was taken. These logs serve as evidence for OCR audits and accreditation reviews.
De-identify patient records locally.
Start anonymizing medical records in minutes. No cloud account, no BAA required.