Pastes an office note into ChatGPT to draft a specialist referral. The note includes the patient's full name, DOB, MRN, and diagnosis - all now stored in OpenAI's logs, potentially used to train future models.
AI Leak Guard warns your team before PHI is pasted, attached, or sent into ChatGPT, Claude, Gemini and more - a technical safeguard that supports your HIPAA program. It runs on your device; we never see your data.
A technical safeguard that supports your HIPAA program. Reduces the risk of impermissible PHI disclosure to third-party AI tools without a BAA. We never see your data - nothing new to add to your BAA.
Independent practices don't have enterprise DLP. Staff use personal ChatGPT and Copilot accounts to save time - and patient identifiers get pasted in, often without anyone noticing. Here's what happens across small clinics every day.
Pastes an office note into ChatGPT to draft a specialist referral. The note includes the patient's full name, DOB, MRN, and diagnosis - all now stored in OpenAI's logs, potentially used to train future models.
Asks Gemini to write a "sorry we missed you" email for a no-show. Copy-pastes the patient's name, phone, and appointment reason into the prompt. That's now on Google's servers, keyed to a Google account with no BAA.
Drops a denied claim into Claude and asks it to draft an appeal letter. The paste includes the patient's insurance ID, member number, DOB, and clinical codes - all sitting in Anthropic's context window for the session and beyond.
Pastes a patient complaint into Copilot to draft a professional reply. Patient's full name, phone, email, and specific complaint details go straight into a Microsoft consumer account - and are now discoverable in a lawsuit.
You paste text into a supported AI tool, or attach a PDF, Word, Excel, PowerPoint or text file, like you always do.
AI Leak Guard reads it in your browser and checks for patient identifiers. For paste, it replaces them with safe placeholders like [PATIENT_NAME], [MRN], or [DOB]. For files, it warns you before the file is uploaded.
For paste: send the protected version, send as-is, or cancel. For an attached file: upload anyway or cancel. Nothing leaves until you choose. Clean files upload normally without interrupting you.
Attach a PDF, Word, Excel, PowerPoint or text file to a supported AI tool and AI Leak Guard reads it on your device first. Clean files upload without interrupting you. Files with identifiers get a warning so you decide.
Files it cannot read as text (like scanned images) are flagged honestly so you decide, not silently missed. Microsoft 365 Copilot documents are handled by your Microsoft 365 environment, not by AI Leak Guard.
AI Leak Guard now checks your message at the moment you send it, so patient information you typed or dictated is caught even if you never pasted it. You see what it would hide and decide before the message goes.
Example values only. Send-time protection does not record what you typed - only that a check happened.
A staff member who types Jane Doe and MRN 12345678 straight into a prompt is protected the same way as someone who pastes.
If you step back to review, your text stays in the composer. Nothing is lost while you decide.
If a check ever fails, your message still sends. AI Leak Guard is a safety net, not a gate.
Verify it's working on a page any time from the extension popup. Coverage details below.
Four real prompts a small practice might send to ChatGPT this week - and the exact identifiers AI Leak Guard hides before send. You still get the answer you need. The AI never sees the patient.
3 identifiers masked. Clinical context (chest pain, troponin, stress echo) is preserved - the AI can still write the letter.
3 identifiers masked. The AI writes a strong appeal using the CPT code and denial reason - without ever knowing the patient's name.
3 identifiers masked. Name, email, and phone stay in your chart - not in a Google account with no BAA.
2 identifiers masked. The clinical justification (A1c, BMI, prior failures) is preserved - that's what the payer needs, not the name.
Detected identifiers include: names, DOBs, MRNs, phone numbers, email addresses, mailing addresses, insurance IDs, claim numbers, prescription numbers, SSNs, and financial identifiers. AI Leak Guard also catches API keys and credit-card numbers for anyone doing double duty as practice IT.
Every category below is caught in your browser the moment you paste it into a supported AI tool, or the moment you attach a document that contains it. Clinical context - diagnoses, medications, procedures, lab values - is left alone so the AI can still give you a useful answer.
Clinical context isn't identifying on its own, so we don't flag it. That's why the AI can still write the referral, appeal, or summary you asked for - just without the patient attached.
You're not a 500-person hospital with a security team. That doesn't mean the exposure is smaller - it usually means it's bigger, because the safety net isn't there.
OCR settlements for improper PHI disclosure to third parties routinely run six figures for small practices - and OpenAI, Google, Microsoft, and Anthropic don't sign BAAs for consumer AI accounts. Every paste is a disclosure.
One local news story about "clinic sent patient records to ChatGPT" and the referral pipeline dries up. Small practices survive on trust and word-of-mouth - there's no recovering from that headline.
ChatGPT retains history by default. If a patient sues, opposing counsel can request account records - and consumer AI accounts don't have the audit controls to defend what was and wasn't shared. Every prompt becomes evidence.
Staff are using AI because it saves them an hour a day. Banning it doesn't work - they'll use it on personal devices. AI Leak Guard is the only realistic middle path: keep the productivity, remove the risk.
Send-time protection works on ChatGPT, Claude, Gemini, and Microsoft Copilot (a two-press review on Copilot). Paste checking also covers Perplexity. Document scanning covers ChatGPT, Claude, Gemini, and Perplexity. Here is exactly where each one runs.
| Site | Send-time | Paste checking | Document upload |
|---|---|---|---|
| ChatGPT | YES | YES | YES |
| Claude | YES | YES | YES |
| Gemini | YES | YES | YES |
| Perplexity | PLANNED | YES | YES |
| Microsoft Copilot copilot.microsoft.com |
YES | YES | YES |
| Microsoft 365 Copilot m365.cloud.microsoft |
NO | NO | NO |
Microsoft 365 Copilot (m365.cloud.microsoft) is out of scope. See the security brief for the full detail.
AI Leak Guard keeps a local activity view of every check: how many sensitive items were found, which categories, which site, and when. It never records the text, the file contents, or the filename. You can export it to CSV or JSON on your own device. Nothing is uploaded.
By category
Recent activity
Illustrative view. Counts, categories, site, and time only. Never the text, file contents, or filename.
Counts of identifiers detected, the categories they fell into, the AI tool they were headed to, and the timestamp. That is the entire record.
The text you pasted. The contents of files you attached. The filename. None of that is written to the activity view or included in the export.
The export is built in your browser and saved to your own device. Useful for your own record-keeping, or for a monthly review with your compliance advisor. It is your record.
Detection happens entirely in your browser. Your text and your files are never uploaded, stored, or sent anywhere by the extension.
Privacy tools that overstate what they do are a bigger risk than the problem they solve. Here's the plain truth, in one place, in your language.
This is a preventive privacy control that helps reduce risk. It's a safety net that keeps you in control - not a guarantee, not a compliance product.
Individual protection is free forever. For practices, we're building centralized deployment, simple policy configuration, and aggregate visibility into risky AI submissions prevented - shown as metadata only, never patient content ("AI Leak Guard protected 27 risky submissions this week - without ever seeing your patient data"). Pricing is being finalized with early practices.
Also relevant to: healthcare IT providers, MSPs managing multiple clinics, and HIPAA compliance consultants recommending tooling as part of an acceptable-use policy.
Not VC-funded. Not data brokers. Not building toward acquisition. Just small, focused tools that respect your data - built the way we'd want them built if they ran on our own systems.
No. Detection happens entirely in your browser. Your text and your files are never uploaded, stored, or sent anywhere by the extension. You can verify this in our open-source code on GitHub. Full details on /privacy.
No, and no software can, on its own. AI Leak Guard is a technical safeguard that supports your HIPAA program: it reduces the risk of impermissible PHI disclosure to third-party AI tools that don't have a BAA with your practice. Compliance itself remains your organization's responsibility. AI Leak Guard supports your organization's HIPAA compliance efforts. It does not, by itself, make any organization HIPAA compliant.
It's free for individual healthcare workers - free forever, not a trial. Centralized deployment and policy options for clinics and teams are being built with early practices; pricing is being finalized. Talk to us if you're deploying across a practice.
Send-time protection (checks your message the moment you send it) runs on ChatGPT, Claude, Gemini, and Microsoft Copilot (copilot.microsoft.com). Copilot uses a two-press review to fit its send flow. Paste checking also covers Perplexity. Document scanning (PDF, Word, Excel, PowerPoint or text files) covers ChatGPT, Claude, Gemini, and Perplexity - not Copilot. Send-time protection on Perplexity is planned for a later release. All of this in Google Chrome. Edge, Brave, and Arc also work today because they're Chromium-based. Firefox and Safari are on the roadmap but not yet supported.
Yes. Send-time protection now covers Microsoft Copilot (copilot.microsoft.com) with a two-press review that fits its send flow. Paste checking is also covered. Document scanning is not: attachments on Copilot are not intercepted by AI Leak Guard. Microsoft 365 Copilot (the work or school version at m365.cloud.microsoft) is out of scope entirely - files uploaded there go into your Microsoft 365 environment and are governed by your Microsoft 365 and Purview controls. AI Leak Guard focuses on the personal and unmanaged AI tools those controls often do not cover.
No account, no login, no setup, no configuration. Add it to Chrome and it works. Zero friction - the same reason people fell in love with the AI tools we're helping you use safely.
Yes. The full source code is open on GitHub under an MIT license. Anyone - your IT contractor, your compliance consultant, a security-minded family member - can audit exactly what the extension does.
It catches a broad set of common patient identifiers - names, DOBs, addresses, phone numbers, MRNs, insurance IDs, claim numbers, SSNs, and financial identifiers - both in pasted text and in the documents you attach. But no tool can guarantee every possible identifier, and files it cannot read as text (like scanned images) are flagged so you decide, not silently missed. AI Leak Guard is a safety net that keeps you in control, not a guarantee.
You always make the final call. On paste, you see the preview and choose: Paste protected version, Paste as-is, or Cancel. On an attached document, you get a warning listing exactly which identifiers were found and you choose: Upload anyway, or Cancel upload. The extension does not edit or redact your file - it just tells you what is in there before it leaves your device. Nothing is silently rewritten and nothing uploads until you choose. You can also disable the extension entirely from the popup for the current tab or forever.
No. Paste detection runs in under 5 milliseconds for typical content. Document scanning takes as long as it takes to read the file - usually a fraction of a second for typical PDFs, Word, Excel, PowerPoint or text attachments, longer for very large files. The extension is under 200KB and makes no outbound network requests at all: no server contact, no telemetry, no runtime fetches. Detection patterns are bundled and change only when the extension itself updates through the Chrome Web Store.
No account. No email. No tracking. Add it to Chrome and it's on. You can disable it any time from the popup, on any tab, forever.
Live on the Chrome Web Store · MIT-licensed · source on GitHub.
github.com/zabcore/ai-leak-guard · MIT licensed · Built by Zabcore