Secure by design: How we manage PHI and PII data

HealthGO helps deliver value-based care in a secure, compliant and highly scalable way. You can trust HealthGO - and our dedicated security team - to keep your data safe with enterprise-grade security features, compliance audits, privacy protections and all the capabilities of a fully on-demand, cloud environment.

Data Security is Patient Security. Here's how we ensure it.
  • To keep all your data secure, HealthGO encrypts data at rest and in transit. While our services are hosted in your regional HIPAA compliant AWS facilities, servers live within HealthGO's own VPCs to prevent unauthorized network requests.
  • PII and PHI can be stored exclusively on client's AWS servers (requires additional setup). If data is stored on HealthGO's servers, it is stored on an independent database separate from rest of the data unique to an organisation or entity.
  • You can manage access to HealthGO with any identity provider that supports SAML and SCIM, including Azure AD, Okta, OneLogin, and more. And use SAML SSO, 2FA, and domain capture to securely deploy HealthGO across your entire organization.
  • Employ strict need-based access with our employees and perform thorough background checks, sign PIIA and NDA and have structured trainings with all members.
  • Ensure that our subprocessors are HIPAA Eligible and trusted cloud vendors with enterprise grade security. For subprocessor list and 3rd party certifications, visit here. They are also listed on this page.
  • Actively identify and redact all PHI and PII incoming or stored in HealthGO servers, if not required. Employ granular access, if required.
Do not need, do not keep. Industry-leading "Active PHI/PII Redaction"

Each interaction with HealthGO is first scanned for PII and PHI to detect and then redact the entities. This operation happens both in real-time (eg - scanning documents, audio/ video conversations) or asynchronously.

Why?

Under the HIPAA act, PHI that is based on a list of 18 identifiers must be treated with special care. HealthGO/ AI Library Medical detects entities associated with these identifiers but these entities don't map 1:1 to the list specified by the Safe Harbor method. Not all identifiers are contained in unstructured clinical text, but HealthGO does cover all the relevant identifiers. These identifiers consist of data that can be used to identify an individual patient.

For more information, see Health Information Privacy

We go a step further and detect & redact all Personally Identifiable Identifiers as well, as a higher security measure.

How we do it

Before every interaction, HealthGO scans and returns a list of detected PII and PHI entities, with the following information for each entity:

  • A score that estimates the probability that the detected text span is the detected entity type.

  • The PII/ PHI entity type.

  • The location of the PII entity in the document, specified as character offsets for the start and the end of the entity.

  • The location of the entity in the document, specified as character offsets for the start and the end of the entity.

Once the entities are identified, it is redacted from the text before any further operation is made. For example, for the following input text

Angela Steward age 78 came in today for her medications for XYZ disease. She forgot her credit card at the clinic. Sharing the details for record 1111-0000-1111-0000. It was mailed to 123 Any Street, Seattle, WA 98109.

The output that is processed further is

***** ****** age ** came in today for her medications for XYZ disease. She forgot her credit card at the clinic. Sharing the details for record *******************. It was mailed to *** *** ******* ******** ** *****.

Entity

Description

HIPAA Category

AGE

An individual's age, including the quantity and unit of time. For example, in the phrase "I am 40 years old," HealthGO recognizes "40 years" as an age.

3. Dates related to an individual

DATEDate related to patient or patient care. 3. Dates related to an individual

NAME

All names mentioned in the clinical note, typically belonging to patient, family, or provider. An individual's name. This entity type does not include titles, such as Dr., Mr., Mrs., or Miss. HealthGO does not apply this entity type to names that are part of organizations or addresses. For example, HealthGO recognizes the "John Doe Organization" as an organization, and it recognizes "Jane Doe Street" as an address.

1. Name

PHONE_OR_FAX

Any phone, fax, pager; excludes named phone numbers such as 1-800-QUIT-NOW as well as 911.

4. Phone number

5. FAX number

EMAIL

Any email address, such as marymajor@email.com.

6. Email addresses

ID

Any sort of number associated with the identity of a patient. This includes their social security number, medical record number, facility identification number, clinical trial number, certificate or license number, vehicle or device number. It also includes biometric numbers, and numbers identifying the place of care or provider.

See ID details below

7. Social Security Number

8. Medical Record number

9. Health Plan number

10. Account numbers

11. Certificate/License numbers

12. Vehicle identifiers

13. Device numbers

16. Biometric information

18. Any other identifying characteristics

URL

Any web URL.

14. URLs

ADDRESS

This includes all geographical subdivisions of an address of any facility, named medical facilities, or wards within a facility. A physical address, such as "100 Main Street, Anytown, USA" or "Suite #12, Building 123". An address can include information such as the street, building, location, city, state, country, county, zip code, precinct, and neighborhood.

2. Geographic location

PROFESSION

Includes any profession or employer mentioned in a note as it pertains to the patient or the patient’s family.

18. Any other identifying characteristics

PII entities

Some PII entity types are universal (not specific to individual countries), such as email addresses and credit card numbers. HealthGO detects the following types of universal PII entities, in addition to the PHI entities mentioned above:

CREDIT_DEBIT_CVV

A three-digit card verification code (CVV) that is present on VISA, MasterCard, and Discover credit and debit cards. For American Express credit or debit cards, the CVV is a four-digit numeric code.

CREDIT_DEBIT_EXPIRY

The expiration date for a credit or debit card. This number is usually four digits long and is often formatted as month/year or MM/YY. HealthGO recognizes expiration dates such as 01/21, 01/2021, and Jan 2021.

CREDIT_DEBIT_NUMBER

The number for a credit or debit card. These numbers can vary from 13 to 16 digits in length. However, HealthGO also recognizes credit or debit card numbers when only the last four digits are present.

DATE_TIME

A date can include a year, month, day, day of week, or time of day. For example, HealthGO recognizes "January 19, 2020" or "11 am" as dates. HealthGO will recognize partial dates, date ranges, and date intervals. It will also recognize decades, such as "the 1990s".

DRIVER_ID

The number assigned to a driver's license, which is an official document permitting an individual to operate one or more motorized vehicles on a public road. A driver's license number consists of alphanumeric characters.

INTERNATIONAL_BANK_ACCOUNT_NUMBER

An International Bank Account Number has specific formats in each country. See www.iban.com/structure.

IP_ADDRESS

An IPv4 address, such as 198.51.100.0.

LICENSE_PLATE

A license plate for a vehicle is issued by the state or country where the vehicle is registered. The format for passenger vehicles is typically five to eight digits, consisting of upper-case letters and numbers. The format varies depending on the location of the issuing state or country.

MAC_ADDRESS

A media access control (MAC) address is a unique identifier assigned to a network interface controller (NIC).

PASSWORD

An alphanumeric string that is used as a password, such as "*very20special#pass*".

PIN

A four-digit personal identification number (PIN) with which you can access your bank account.

SWIFT_CODE

A SWIFT code is a standard format of Bank Identifier Code (BIC) used to specify a particular bank or branch. Banks use these codes for money transfers such as international wire transfers.

SWIFT codes consist of eight or 11 characters. The 11-digit codes refer to specific branches, while eight-digit codes (or 11-digit codes ending in 'XXX') refer to the head or primary office.

USERNAME

A user name that identifies an account, such as a login name, screen name, nick name, or handle.

VEHICLE_IDENTIFICATION_NUMBER

A Vehicle Identification Number (VIN) uniquely identifies a vehicle. VIN content and format are defined in the ISO 3779 specification. Each country has specific codes and formats for VINs.

Country-specific PII entity types

Some PII entity types are country-specific, such as passport numbers and other government-issued ID numbers. HealthGO detects the following types of country-specific PII entities:

CA_HEALTH_NUMBER

A Canadian Health Service Number is a 10-digit unique identifier, required for individuals to access healthcare benefits.

CA_SOCIAL_INSURANCE_NUMBER

A Canadian Social Insurance Number (SIN) is a nine-digit unique identifier, required for individuals to access government programs and benefits.

The SIN is formatted as three groups of three digits, such as 123-456-789. A SIN can be validated through a simple check-digit process called the Luhn algorithm.

IN_AADHAAR

An Indian Aadhaar is a 12-digit unique identification number issued by the Indian government to the residents of India. The Aadhaar format has a space or hyphen after the fourth and eighth digit.

IN_NREGA

An Indian National Rural Employment Guarantee Act (NREGA) number consists of two letters followed by 14 numbers.

IN_PERMANENT_ACCOUNT_NUMBER

An Indian Permanent Account Number is a 10-digit unique alphanumeric number issued by the Income Tax Department.

IN_VOTER_NUMBER

An Indian Voter ID consists of three letters followed by seven numbers.

UK_NATIONAL_HEALTH_SERVICE_NUMBER

A UK National Health Service Number is a 10-17 digit number, such as 485 777 3456. The current system formats the 10-digit number with spaces after the third and sixth digits. The final digit is an error-detecting checksum.

The 17-digit number format has spaces after the 10th and 13th digits.

UK_NATIONAL_INSURANCE_NUMBER

A UK National Insurance Number (NINO) provides individuals with access to National Insurance (social security) benefits. It is also used for some purposes in the UK tax system.

The number is nine digits long and starts with two letters, followed by six numbers and one letter. A NINO can be formatted with a space or a dash after the two letters and after the second, forth, and sixth digits.

UK_UNIQUE_TAXPAYER_REFERENCE_NUMBER

A UK Unique Taxpayer Reference (UTR) is a 10-digit number that identifies a taxpayer or a business.

BANK_ACCOUNT_NUMBER

A US bank account number, which is typically 10 to 12 digits long. HealthGO also recognizes bank account numbers when only the last four digits are present.

BANK_ROUTING

A US bank account routing number. These are typically nine digits long, but HealthGO also recognizes routing numbers when only the last four digits are present.

PASSPORT_NUMBER

A US passport number. Passport numbers range from six to nine alphanumeric characters.

US_INDIVIDUAL_TAX_IDENTIFICATION_NUMBER

A US Individual Taxpayer Identification Number (ITIN) is a nine-digit number that starts with a "9" and contain a "7" or "8" as the fourth digit. An ITIN can be formatted with a space or a dash after the third and forth digits.

SSN

A US Social Security Number (SSN) is a nine-digit number that is issued to US citizens, permanent residents, and temporary working residents. HealthGO also recognizes Social Security Numbers when only the last four digits are present.

Trusted Subprocessors
AWS
PHI data may be stored and shared with HIPAA compliant services

HealthGO uses Amazon Web Services, Inc. to process and store user data for the duration set forth in the user’s (or its organization’s) agreement with HealthGO/ AI Library Medical.

Google Analytics
PHI data is not stored or shared with this service

AI Library uses Google Analytics to analyse its platform traffic

OpenAI
PHI data is not stored or shared with this service

AI Library uses various Large Language Models provided by OpenAI across our artificial language tools. We mask Personal Identifiable Information before sharing data with OpenAI. Our enterprise customers have the option to use their own OpenAI keys to leverage their contracts with OpenAI.

More Information
  • One or more annual third-party audit(s)
  • Has a disaster recovery plan
  • Deletes customer data on request
  • Uses a centralized IAM solution (SSO) to manage employee access
  • Annual third-party penetration testing
  • Subprocessors list available
  • Has an API available
  • Has a privacy policy