The discovery problem

Find the PHI before it leaks

The HIPAA Security Rule expects you to know where electronic protected health information lives before you can safeguard it. On real workstations, ePHI scatters into Downloads, email exports, scanned charts, and old spreadsheets that no inventory ever captured.

FileSentinel reads inside your documents, spreadsheets, PDFs, and images and flags PHI: health record identifiers, patient data, insurance numbers, and clinical terms paired with personal identifiers. Each finding is scored so genuine records rise above passing mentions.

What FileSentinel maps to

PHI categories it surfaces

CategoryExamples FileSentinel flags
Personal identifiersNames with SSNs, dates of birth, addresses
Medical identifiersMedical record numbers, insurance/member numbers
Clinical contentDiagnoses and health terms that signal regulated data
Visible PHI in scansText inside scanned charts and image PDFs, read via OCR

Why local matters here

Discovery without a new exposure

Sending PHI to a cloud scanner to check whether it is sensitive is its own disclosure risk. FileSentinel runs entirely on-device with no uploads, so the data-discovery step does not create a new path for ePHI to leave your control.

  • On-device scanning
  • No uploads
  • Remediation history

FAQ

Does FileSentinel make my practice HIPAA compliant?

No single tool makes you compliant. FileSentinel supports the data-discovery and remediation steps: it helps you find where PHI lives on your Windows machines and clean or redact it, which is foundational to a HIPAA program but not the whole of one.

Where does the scanning happen?

Entirely on your device. FileSentinel makes no network connections to scan, so PHI is never uploaded to a cloud service to be checked.

Can it find PHI inside scanned documents?

Yes. With OCR enabled, FileSentinel reads text inside scanned charts, faxes, and image-based PDFs, so PHI captured as an image is caught too.

What can I do with the findings?

Review them by severity, redact sensitive values, strip metadata to a clean copy, mark false positives, and export a report. A remediation history records exactly what changed.