HIPAA Security Rule · 45 CFR Part 164 · Healthcare AI Compliance

AI Compliance Firewall for Healthcare

Stop PHI from leaking into ChatGPT, Microsoft Copilot, and Claude. Get the $499 report — and run self-hosted (Mode B) for live PHI.

PHI boundary: the hosted trial runs on Vercel and is for non-PHI evaluation only — it is not covered by a BAA. For live PHI, run HoundShield self-hosted (Mode B, Docker), where prompt content never leaves your network.

$100–$50K
fine per HIPAA violation
$1.9M
annual penalty cap
800K+
healthcare practices using AI
<10ms
HoundShield intercept latency
The Problem

Your team is using AI tools. HIPAA doesn't care.

Every time a clinician pastes patient notes into ChatGPT, your organization faces a potential breach. HIPAA violations don't require intent — they require exposure.

$100–$50,000
per violation

Tier 1–4 penalties under the HITECH Act. Willful neglect without correction = $50K per incident.

$7.42M
avg data breach cost

Average cost of a US healthcare data breach — the highest of any industry (IBM Cost of a Data Breach Report 2025).

89%
involve regulated data

Share of healthcare data policy violations tied to generative AI that involve regulated data, versus 31% across all industries (Netskope Threat Labs Report: Healthcare 2025, 2025-05).

How It Works

Intercept. Classify. Protect.

HoundShield sits between your workforce and every AI tool — scanning for PHI in real-time before it ever leaves your environment.

Real-Time PHI Scanning

Intercept every AI query before it leaves your network. Detect all 18 HIPAA Safe Harbor identifiers in <10ms.

Block Before It Leaks

Automatically quarantine or block prompts containing PHI. AES-256 encrypted quarantine vault for review.

HIPAA Control Mapping

Map your AI security posture to all 18 HIPAA Security Rule controls. Generate audit-ready compliance reports.

Tamper-Evident Audit Trail

SHA-256 hash-chained audit log. Every AI interaction recorded with evidence you can hand to an auditor.

Complete Coverage

All 18 HIPAA Safe Harbor Identifiers

HoundShield detects every PHI category defined in 45 CFR §164.514(b)(2) — the standard for de-identification.

Patient names
Geographic data (street, city, zip)
Dates (DOB, admission, discharge)
Phone & fax numbers
Email addresses
Social Security Numbers
Medical record numbers (MRN)
Health plan beneficiary IDs
Account numbers
Certificate/license numbers
Vehicle identifiers (VIN)
Device identifiers & serials
URLs & IP addresses
Biometric identifiers
Full-face photographs
Medicare/Medicaid IDs
Encounter/visit IDs
Any unique identifying number

Start protecting PHI today

The free in-browser scan checks your prompts for PHI in seconds — no signup, nothing leaves your browser.

Our HIPAA Position

Where HoundShield stands, in plain terms

A Privacy Officer should not have to guess whether a vendor is a business associate. Here is our position, stated once, precisely.

Mode A (hosted trial): evaluation only, no PHI, no BAA

The hosted endpoint at houndshield.com runs on Vercel and exists for evaluating the product with non-PHI data. We do not offer a BAA for it, and you must not send PHI through it. A vendor that receives PHI on your behalf becomes your business associate under 45 CFR 160.103 — which is exactly the relationship Mode A is designed not to create.

Mode B (self-hosted): PHI never reaches us, so no BAA is needed with us

In Mode B the proxy runs as Docker inside your own network. Prompt content — including any PHI a clinician tries to paste — is scanned locally and never transmitted to HoundShield. Because we do not create, receive, maintain, or transmit PHI on your behalf, HoundShield does not act as a business associate in this deployment, and no BAA between you and HoundShield is required. This is the deployment mode for live PHI.

The telemetry that keeps that true

The only data a Mode B deployment sends back to houndshield.com is an enumerated metadata set: the action taken, risk level, pattern name, timestamps, and scan timing. Never prompt text, never the matched content. That contract is enforced by an allowlist in the proxy’s code — fields outside the list are stripped before anything leaves your network — not merely promised in a document. Vendor details are on the sub-processors page.

What stays your responsibility

BAAs with AI vendors you deliberately send PHI to — under your own API keys, at your instruction — remain between you and those vendors. HoundShield’s job is making sure the traffic that should not happen gets blocked before it leaves, and giving you the audit trail that proves it.

This is our good-faith reading of 45 CFR 160.103 as it applies to each deployment mode. It is not legal advice — confirm the analysis with your privacy counsel. All of our legal documents are collected at /legal.

FAQ

HIPAA & AI: frequently asked questions

Still have questions? Talk to a compliance engineer — we respond within 4 business hours.