Real-time PHI detection for every healthcare AI workflow.
KorGuard scans outbound prompts, emails, and document uploads for Protected Health Information before data leaves the browser, on-device and without external transmission.
Healthcare teams are using AI faster than compliance can keep up. KorGuard closes the gap at the point of input with local classification, identifier and diagnosis correlation, and configurable enforcement that turns policy into behavior.
Detection Surface
18+
PHI identifier classes including MRN, DOB, NPI, ICD, claim, and free-text clinical context.
Latency
<40ms
Local inference on the active text buffer. No round-trip to a cloud scanner.
Data Residency
Device
Raw PHI is never transmitted, stored, or logged by KorGuard.
The PHI Exposure Surface
Clinicians are pasting patient charts into AI tools your BAAs never covered.
Industry telemetry · 2024–2026
$24M
Average healthcare AI breach
Healthcare carries the highest per-incident cost of any sector — roughly 3× the cross-industry average and climbing year over year.
93%
Use unsanctioned LLMs
Staff routinely paste clinical notes, MRNs, and imaging summaries into consumer ChatGPT, Gemini, and Claude accounts outside any BAA.
1 in 2
Employees leak PHI weekly
Roughly half of healthcare employees admit to entering sensitive patient or operational data into AI assistants in a typical week.
60 days
HIPAA breach notification window
Once PHI lands in a third-party model, the disclosure clock starts — and the underlying training data is unrecoverable.
0%
BAA coverage on consumer AI
Public LLM endpoints are not covered entities, cannot sign BAAs, and may retain prompts for model improvement.
18
HIPAA identifiers at risk
Names, MRNs, dates, geographic detail, biometrics, and free-text clinical context all qualify — and rarely appear alone.
Capabilities
Detection, scoring, and enforcement at the point of input.
Identifier + Context Detection
Recognizes the 18 HIPAA identifiers plus correlated clinical context such as diagnosis pairs, treatment timelines, and provider-patient combinations that re-identify individuals.
Risk Scoring
Multi-stage risk model assigns green, amber, or red severity to each prompt based on identifier density, clinical context, and destination platform.
Configurable Enforcement
Block, warn, or de-identify based on policy. Suggested redactions allow workflows to continue without exposing PHI to unapproved AI surfaces.
Document De-Identification
Local analysis of PDFs and screenshots produces a sanitized version of the file with PHI replaced, ready for safe AI use.
Email & Chat Coverage
Same detection pipeline applies to email composers, messaging fields, and clinical documentation tools, not just LLM prompts.
Admin Visibility
Aggregate risk telemetry without raw PHI. Compliance teams see what is being attempted, not what was written.
99% PHI detection accuracy. Nothing leaves the device.
The KorGuard shield runs an on-device classifier tuned on de-identified clinical corpora. Every prompt, attachment, and email field is scored locally before submit — no PHI ever reaches our servers, our models, or a third-party API.
99%
PHI Detection Accuracy
Validated against curated clinical and adversarial-prompt benchmarks across 18 HIPAA identifier classes.
0
PHI Bytes Transmitted
Inference, scoring, and de-identification execute entirely inside the user's browser runtime.
<40ms
Pre-Submit Latency
Verdict returns before the user can press send. Workflow stays uninterrupted.
100%
Sanitized Audit Trail
Compliance teams see severity, identifier classes, and destination — never the underlying chart content.
Workflow
What happens between keystroke and submit.
01 / Capture
Local intercept
KorGuard observes the text buffer in supported AI platforms, email, and browser fields before submit.
02 / Classify
Identifier model
On-device classifier flags HIPAA identifiers and correlated clinical signals.
03 / Score
Risk decision
Multi-factor risk score weighs identifier density, context, and destination.
04 / Enforce
Block, warn, redact
Policy decides whether to block submission, surface a warning, or substitute a de-identified version.
Outcomes
What changes for your team.
- Stop accidental PHI submission to consumer AI accounts before it leaves the device.
- Make BAA boundaries enforceable in the user's actual workflow, not just on paper.
- Reduce breach notification exposure by eliminating the most common prompt-leakage path.
- Give compliance teams operational visibility without storing or reviewing raw patient content.
- Allow clinicians and operations staff to keep using AI tools safely instead of banning them.
Why KorGuard
Built differently from cloud DLP and prompt firewalls.
Local-first, not cloud-DLP
Traditional DLP needs to see your data to scan it. KorGuard inspects PHI on the device, so the regulated content stays inside your trust boundary.
Built for clinical context
Generic PII tools miss clinical re-identification — diagnosis pairs, treatment timelines, provider-patient combinations. We catch the context, not just the identifier.
Workflow-preserving enforcement
Hard blocks teach avoidance. Inline de-identification lets clinicians keep using AI safely with a sanitized version of the prompt.
Make HIPAA enforceable at the prompt.
See how KorGuard runs locally inside the browsers and AI surfaces your team already uses.
Schedule a Call