The discovery problem
Find the PHI before it leaks
The HIPAA Security Rule expects you to know where electronic protected health information lives before you can safeguard it. On real workstations, ePHI scatters into Downloads, email exports, scanned charts, and old spreadsheets that no inventory ever captured.
FileSentinel reads inside your documents, spreadsheets, PDFs, and images and flags PHI: health record identifiers, patient data, insurance numbers, and clinical terms paired with personal identifiers. Each finding is scored so genuine records rise above passing mentions.
What FileSentinel maps to
PHI categories it surfaces
| Category | Examples FileSentinel flags |
|---|---|
| Personal identifiers | Names with SSNs, dates of birth, addresses |
| Medical identifiers | Medical record numbers, insurance/member numbers |
| Clinical content | Diagnoses and health terms that signal regulated data |
| Visible PHI in scans | Text inside scanned charts and image PDFs, read via OCR |
Why local matters here
Discovery without a new exposure
Sending PHI to a cloud scanner to check whether it is sensitive is its own disclosure risk. FileSentinel runs entirely on-device with no uploads, so the data-discovery step does not create a new path for ePHI to leave your control.
- On-device scanning
- No uploads
- Remediation history
Related
FAQ
Does FileSentinel make my practice HIPAA compliant?
No single tool makes you compliant. FileSentinel supports the data-discovery and remediation steps: it helps you find where PHI lives on your Windows machines and clean or redact it, which is foundational to a HIPAA program but not the whole of one.
Where does the scanning happen?
Entirely on your device. FileSentinel makes no network connections to scan, so PHI is never uploaded to a cloud service to be checked.
Can it find PHI inside scanned documents?
Yes. With OCR enabled, FileSentinel reads text inside scanned charts, faxes, and image-based PDFs, so PHI captured as an image is caught too.
What can I do with the findings?
Review them by severity, redact sensitive values, strip metadata to a clean copy, mark false positives, and export a report. A remediation history records exactly what changed.