Patient Protect LLC
HIPAA Shield — PHI Detection for Browsers
Detects Protected Health Information typed into browser forms — especially AI chat tools. 100% client-side. Zero telemetry.
HIPAA Shield warns when Protected Health Information (PHI) is typed or pasted into browser forms — especially consumer AI chat interfaces that do not sign HIPAA Business Associate Agreements at their default tier. When the extension detects PHI in a text field, a warning banner appears immediately above the input, alerting the user before they hit "send." WHY THIS MATTERS Healthcare staff increasingly paste patient information into consumer AI tools to summarize, rewrite, or draft from. Most of those tools don't qualify as HIPAA-eligible at the consumer tier and may use inputs for training. From the practice's standpoint, every paste is a potentially reportable disclosure under HIPAA's Privacy Rule. The intervention has to happen at the moment of the choice, not in retrospect during an audit. WHAT IT DETECTS The extension detects eight categories of PHI in any input field: • Social Security Numbers (with prefix validation) • Date of birth (MM/DD/YYYY 1900–2099) • Credit card numbers (Visa, Mastercard, Amex, Discover — Luhn-validated) • Medical Record Numbers (MRN-prefixed identifiers) • Phone numbers (US formats) • Email addresses • ICD-10 diagnosis codes • Clinical diagnosis terms Each rule is individually toggleable in the extension popup. SSN, date of birth, credit card, MRN, and ICD-10 are enabled by default. Phone, email, and diagnosis terms are off by default to reduce noise during normal browsing. WHERE IT WORKS The extension scans every text input, textarea, and contenteditable field on every page. It is especially useful in: • Consumer AI chat interfaces where staff paste questions about real patients • Webmail composers where attachments and addresses can leak PHI • Customer support and CRM forms used for patient outreach • Vendor portals, ticketing systems, and intake forms • Any web form, textarea, or rich text editor on any site PRIVACY — 100% CLIENT-SIDE The extension makes zero network requests. No telemetry. No analytics. No error reporting. No usage tracking. • Manifest declares zero host_permissions • Source code contains zero fetch or XMLHttpRequest calls • Detection runs entirely in your browser, on your device • Local storage is used only to remember your rule toggles • No remote code injection — all JavaScript and CSS ships in the extension Full privacy policy: https://patient-protect.com/hipaa-shield/privacy Verify the source: https://github.com/patient-protect/hipaa-shield (MIT license, under 250 lines of detection logic) WHAT IT IS NOT This extension catches casual disclosures at the moment of entry. It is not a substitute for: • Workforce HIPAA training • A written AI-use policy • Business Associate Agreements with HIPAA-eligible vendors • Platform-level data loss prevention • Continuous compliance monitoring OPEN SOURCE Released under the MIT license. Pull requests welcome. The project lives at github.com/patient-protect/hipaa-shield. ABOUT PATIENT PROTECT Patient Protect is a security-first HIPAA compliance platform for independent healthcare practices. We publish 20+ free tools and resources at patient-protect.com/free-tools, including a comprehensive risk assessment, breach intelligence dashboard, citable open dataset, and open reference data on GitHub. This extension is one of those free tools. There is no paid tier of the extension itself. We built it because the gap between what HIPAA requires and what staff actually do in a browser is the fastest-growing breach category in independent healthcare — and the browser is where the intervention has to live. QUESTIONS, FEEDBACK, OR ISSUES GitHub issues: https://github.com/patient-protect/hipaa-shield/issues Privacy questions: info@patient-protect.com Patient Protect: https://patient-protect.com
Details
- AddressPatient Protect LLC
411 S Sangamon St Chicago, IL 60607 US - TraderThis developer has identified itself as a trader per the definition from the European Union and committed to only offer products or services that comply with EU laws.
- D-U-N-S057183396