Product safety
Last reviewed: 2026-09-26
Masking changes what a recipient can read. It does not check the accuracy of a clinical record or the advice produced by an AI service. The person using the information remains responsible for the decision to share it and the work that follows.
Automatic detection has limits
Detection can miss identifying information. Handwriting is read on a best-effort basis, and a record can identify someone through context even after direct identifiers are covered.
Review the masked copy for the intended recipient and task. A completed masking step is not an assurance that the remaining copy is anonymous.
Choose between masking and redaction
Reversible placeholders let the person using PHI Mask restore values locally. A recipient who can access the recovery information may also be able to identify those values.
Redaction and reversible masking serve different purposes. Decide which output the task needs, and keep recovery information out of the material being shared.
Account for browser storage
The online masker keeps its working state in the active tab. Extension settings, saved rules, Known contacts and supported conversation recovery have different storage and deletion behavior.
Treat browser profiles and unlocked devices as part of the privacy boundary. Use the relevant deletion controls when the workflow no longer needs the retained information.
Assess the receiving service and its output
The selected AI service receives the copy you send. Its retention, training settings, access and agreement terms need their own review.
PHI Mask does not establish the accuracy or suitability of that service's output. Clinical and other professional decisions require the appropriate human judgment.
Report a problem without exposing a record
Describe the problem without including patient or client identifiers. Use an obviously fictional example when it can reproduce the issue.
Send product feedback through the feedback page. Use the private security intake for a suspected vulnerability.