Stop PHI from leaking into ChatGPT, Microsoft Copilot, and Claude. Get the $499 report — and run self-hosted (Mode B) for live PHI.
PHI boundary: the hosted trial runs on Vercel and is for non-PHI evaluation only — it is not covered by a BAA. For live PHI, run HoundShield self-hosted (Mode B, Docker), where prompt content never leaves your network.
Every time a clinician pastes patient notes into ChatGPT, your organization faces a potential breach. HIPAA violations don't require intent — they require exposure.
Tier 1–4 penalties under the HITECH Act. Willful neglect without correction = $50K per incident.
Average cost of a US healthcare data breach — the highest of any industry (IBM Cost of a Data Breach Report 2025).
Share of healthcare data policy violations tied to generative AI that involve regulated data, versus 31% across all industries (Netskope Threat Labs Report: Healthcare 2025, 2025-05).
HoundShield sits between your workforce and every AI tool — scanning for PHI in real-time before it ever leaves your environment.
Intercept every AI query before it leaves your network. Detect all 18 HIPAA Safe Harbor identifiers in <10ms.
Automatically quarantine or block prompts containing PHI. AES-256 encrypted quarantine vault for review.
Map your AI security posture to all 18 HIPAA Security Rule controls. Generate audit-ready compliance reports.
SHA-256 hash-chained audit log. Every AI interaction recorded with evidence you can hand to an auditor.
HoundShield detects every PHI category defined in 45 CFR §164.514(b)(2) — the standard for de-identification.
The free in-browser scan checks your prompts for PHI in seconds — no signup, nothing leaves your browser.
A Privacy Officer should not have to guess whether a vendor is a business associate. Here is our position, stated once, precisely.
The hosted endpoint at houndshield.com runs on Vercel and exists for evaluating the product with non-PHI data. We do not offer a BAA for it, and you must not send PHI through it. A vendor that receives PHI on your behalf becomes your business associate under 45 CFR 160.103 — which is exactly the relationship Mode A is designed not to create.
In Mode B the proxy runs as Docker inside your own network. Prompt content — including any PHI a clinician tries to paste — is scanned locally and never transmitted to HoundShield. Because we do not create, receive, maintain, or transmit PHI on your behalf, HoundShield does not act as a business associate in this deployment, and no BAA between you and HoundShield is required. This is the deployment mode for live PHI.
The only data a Mode B deployment sends back to houndshield.com is an enumerated metadata set: the action taken, risk level, pattern name, timestamps, and scan timing. Never prompt text, never the matched content. That contract is enforced by an allowlist in the proxy’s code — fields outside the list are stripped before anything leaves your network — not merely promised in a document. Vendor details are on the sub-processors page.
BAAs with AI vendors you deliberately send PHI to — under your own API keys, at your instruction — remain between you and those vendors. HoundShield’s job is making sure the traffic that should not happen gets blocked before it leaves, and giving you the audit trail that proves it.
This is our good-faith reading of 45 CFR 160.103 as it applies to each deployment mode. It is not legal advice — confirm the analysis with your privacy counsel. All of our legal documents are collected at /legal.
FAQ
Still have questions? Talk to a compliance engineer — we respond within 4 business hours.