PHI Boundary Gate

PHI Boundary Gate detects, redacts, blocks, and reports PHI candidate movement across healthcare and insurance AI workflows.

Coverage includes user messages, RAG context, tool output, model input, memory, debug logs, and model provider requests.

A match is only the beginning

Finding an identifier does not explain the full risk.

A useful audit also needs the source, destination, payload path, policy decision, and required action before the value moves again.

SystemOutput
Pattern detectorA possible identifier match
Redaction filterText with matched spans removed
Trace loggerA sequence of application events
PHI Boundary GateThe path, policy decision, redaction, and boundary exposure for each PHI candidate

How it works

  1. Trace. Each JSONL event records the layer, content, source path, and destination path for one piece of context — user message, RAG context, tool output, model input, memory, or debug log.

  2. Policy. A YAML policy you own maps detector categories to layer decisions: allowed, redacted, or a violation.

  3. Scan. One command audits the trace against the policy.

  4. Report. Markdown for human review, JSON for CI. Boundary exposures group the same PHI candidate across events, sorted so violations rise to the top.

phi-boundary-gate scan-trace \
--trace trace.jsonl \
--policy config/phi-policy.yml \
--out report.md --json report.json

It also ships as a Python library — scan text, redact policy-matched spans, or block model calls in-line:

decision = guard_text("member_id=MBR-SYN-8842", layer="debug_log",
policy=policy, mode="block_on_violation")

Get started

python3 -m pip install "phi-boundary-gate>=0.6,<0.7"
phi-boundary-gate init
phi-boundary-gate check-config

init creates starter policy files under config/. Review them with the owners of your logging, prompting, memory, provider, and compliance controls before using them with real PHI.

Treat every detector result as a PHI candidate, not confirmed PHI. The repository contains no real PHI and does not claim HIPAA compliance.

More in the works — built in the open, shipped fast.

Explore Tigerless Labs