Built for HIPAA-conscious clinics

Keep patient data out of AI chat tools.

AI Leak Guard warns your team before PHI is pasted, attached, or sent into ChatGPT, Claude, Gemini and more - a technical safeguard that supports your HIPAA program. It runs on your device; we never see your data.

Add to Chrome - free

Live on the Chrome Web Store · free forever for individuals.

chatgpt.com
You paste · identifiers masked in your browser
Draft an appeal letter for [PATIENT_NAME], DOB [DOB], MRN [MRN]. UnitedHealth denied claim for CPT 99214 citing lack of medical necessity...
🛡
3 identifiers masked
Patient name · DOB · MRN
On-device No account No new vendor to vet Open source (MIT)
Built for HIPAA-conscious teams

A technical safeguard that supports your HIPAA program. Reduces the risk of impermissible PHI disclosure to third-party AI tools without a BAA. We never see your data - nothing new to add to your BAA.

Why this exists

Healthcare workers use AI tools every day. Patient data goes with them.

Independent practices don't have enterprise DLP. Staff use personal ChatGPT and Copilot accounts to save time - and patient identifiers get pasted in, often without anyone noticing. Here's what happens across small clinics every day.

The primary care physician

Pastes an office note into ChatGPT to draft a specialist referral. The note includes the patient's full name, DOB, MRN, and diagnosis - all now stored in OpenAI's logs, potentially used to train future models.

The front-office receptionist

Asks Gemini to write a "sorry we missed you" email for a no-show. Copy-pastes the patient's name, phone, and appointment reason into the prompt. That's now on Google's servers, keyed to a Google account with no BAA.

The medical biller

Drops a denied claim into Claude and asks it to draft an appeal letter. The paste includes the patient's insurance ID, member number, DOB, and clinical codes - all sitting in Anthropic's context window for the session and beyond.

The practice manager

Pastes a patient complaint into Copilot to draft a professional reply. Patient's full name, phone, email, and specific complaint details go straight into a Microsoft consumer account - and are now discoverable in a lawsuit.

How it works

Three steps. All in your browser.

01

You paste or attach

You paste text into a supported AI tool, or attach a PDF, Word, Excel, PowerPoint or text file, like you always do.

02

We check locally, on your device

AI Leak Guard reads it in your browser and checks for patient identifiers. For paste, it replaces them with safe placeholders like [PATIENT_NAME], [MRN], or [DOB]. For files, it warns you before the file is uploaded.

03

You decide

For paste: send the protected version, send as-is, or cancel. For an attached file: upload anyway or cancel. Nothing leaves until you choose. Clean files upload normally without interrupting you.

See it in action

What you type vs. what AI receives.

You type
Summarize this note for a specialist referral. Patient John Miller, DOB 5/12/1948, MRN 003847, phone (415) 555-0142. Seen today for chest pain radiating to left arm, troponin 0.15, EKG shows ST elevation in leads II, III, aVF.
ChatGPT receives
Summarize this note for a specialist referral. Patient [PATIENT_NAME], DOB [DOB], MRN [MRN], phone [PHONE]. Seen today for chest pain radiating to left arm, troponin 0.15, EKG shows ST elevation in leads II, III, aVF.
And when you attach a file

Warned before the document leaves your device.

Attach a PDF, Word, Excel, PowerPoint or text file to a supported AI tool and AI Leak Guard reads it on your device first. Clean files upload without interrupting you. Files with identifiers get a warning so you decide.

chatgpt.com
You attach a file · AI Leak Guard checks it locally
PDF
prior-authorization-request.pdf
184 KB · ready to upload
⚠
7 patient identifiers found in this file
Checked on your device · nothing uploaded yet
2 × Patient name 1 × DOB 1 × MRN 1 × Insurance ID 1 × Phone 1 × Address

Files it cannot read as text (like scanned images) are flagged honestly so you decide, not silently missed. Microsoft 365 Copilot documents are handled by your Microsoft 365 environment, not by AI Leak Guard.

New in v1.3 · Protection at Send

Also caught the moment you hit send.

AI Leak Guard now checks your message at the moment you send it, so patient information you typed or dictated is caught even if you never pasted it. You see what it would hide and decide before the message goes.

chatgpt.com
You typed · AI Leak Guard checks at the moment you send
Draft a follow-up letter for Jane Doe, DOB 5/12/1948, MRN 12345678. She was seen last Tuesday for chest pain and needs stress echo scheduling.
Send clicked
⚠
3 patient identifiers found before send
Checked on your device · message not sent yet
1 × Patient name 1 × DOB 1 × MRN

Example values only. Send-time protection does not record what you typed - only that a check happened.

Typed or dictated is now covered

A staff member who types Jane Doe and MRN 12345678 straight into a prompt is protected the same way as someone who pastes.

Your draft is always kept

If you step back to review, your text stays in the composer. Nothing is lost while you decide.

Fail-open, never blocks your work

If a check ever fails, your message still sends. AI Leak Guard is a safety net, not a gate.

Verify it's working on a page any time from the extension popup. Coverage details below.

Real examples

What AI Leak Guard actually catches in your day.

Four real prompts a small practice might send to ChatGPT this week - and the exact identifiers AI Leak Guard hides before send. You still get the answer you need. The AI never sees the patient.

Referral letter
Draft a cardiology referral for [PATIENT_NAME], DOB [DOB], MRN [MRN]. Seeing for chest pain, elevated troponin, needs stress echo.

3 identifiers masked. Clinical context (chest pain, troponin, stress echo) is preserved - the AI can still write the letter.

Insurance appeal
Write appeal for [PATIENT_NAME], member ID [INSURANCE_ID], claim [CLAIM_NUMBER]. UnitedHealth denied CPT 99215 as not medically necessary despite documented comorbidities.

3 identifiers masked. The AI writes a strong appeal using the CPT code and denial reason - without ever knowing the patient's name.

Patient email reply
Reply politely to [PATIENT_NAME] at [EMAIL] confirming [PHONE] is on file, and reschedule for next Tuesday morning.

3 identifiers masked. Name, email, and phone stay in your chart - not in a Google account with no BAA.

Prior authorization
Draft PA for Ozempic 1mg for [PATIENT_NAME], DOB [DOB]. HbA1c 8.9, BMI 34, failed metformin + Jardiance at max doses.

2 identifiers masked. The clinical justification (A1c, BMI, prior failures) is preserved - that's what the payer needs, not the name.

Detected identifiers include: names, DOBs, MRNs, phone numbers, email addresses, mailing addresses, insurance IDs, claim numbers, prescription numbers, SSNs, and financial identifiers. AI Leak Guard also catches API keys and credit-card numbers for anyone doing double duty as practice IT.

What it catches

11 patient-identifier categories. Detected today.

Every category below is caught in your browser the moment you paste it into a supported AI tool, or the moment you attach a document that contains it. Clinical context - diagnoses, medications, procedures, lab values - is left alone so the AI can still give you a useful answer.

Patient identifiers
  • Patient names
  • Dates of birth
  • Mailing addresses
  • Phone numbers
  • Email addresses
  • Medical record numbers (MRN)
  • Insurance member / subscriber IDs
  • Claim numbers
  • Prescription numbers
  • US Social Security Numbers
  • Credit card numbers (with Luhn validation)
Left alone (as they should be)
  • Diagnoses and ICD-10 codes
  • Medications and dosages
  • CPT and procedure codes
  • Lab values and vitals
  • Clinical observations
  • Anatomy and symptoms

Clinical context isn't identifying on its own, so we don't flag it. That's why the AI can still write the referral, appeal, or summary you asked for - just without the patient attached.

Why it matters

Four reasons a small practice can't afford this leak.

You're not a 500-person hospital with a security team. That doesn't mean the exposure is smaller - it usually means it's bigger, because the safety net isn't there.

HIPAA exposure is real

OCR settlements for improper PHI disclosure to third parties routinely run six figures for small practices - and OpenAI, Google, Microsoft, and Anthropic don't sign BAAs for consumer AI accounts. Every paste is a disclosure.

Patient trust is the practice

One local news story about "clinic sent patient records to ChatGPT" and the referral pipeline dries up. Small practices survive on trust and word-of-mouth - there's no recovering from that headline.

It's discoverable in litigation

ChatGPT retains history by default. If a patient sues, opposing counsel can request account records - and consumer AI accounts don't have the audit controls to defend what was and wasn't shared. Every prompt becomes evidence.

You already lost the time argument

Staff are using AI because it saves them an hour a day. Banning it doesn't work - they'll use it on personal devices. AI Leak Guard is the only realistic middle path: keep the productivity, remove the risk.

Where it works

Three protections. Clear coverage on each.

Send-time protection works on ChatGPT, Claude, Gemini, and Microsoft Copilot (a two-press review on Copilot). Paste checking also covers Perplexity. Document scanning covers ChatGPT, Claude, Gemini, and Perplexity. Here is exactly where each one runs.

Coverage matrix: three protections, six sites.
Site Send-time Paste checking Document upload
ChatGPT YES YES YES
Claude YES YES YES
Gemini YES YES YES
Perplexity PLANNED YES YES
Microsoft Copilot
copilot.microsoft.com
YES YES YES
Microsoft 365 Copilot
m365.cloud.microsoft
NO NO NO

Microsoft 365 Copilot (m365.cloud.microsoft) is out of scope. See the security brief for the full detail.

Your record. Your machine.

See what was protected, privately.

AI Leak Guard keeps a local activity view of every check: how many sensitive items were found, which categories, which site, and when. It never records the text, the file contents, or the filename. You can export it to CSV or JSON on your own device. Nothing is uploaded.

AI Leak Guard · Activity
This week · local only
v1.2
47
Checks
38
Identifiers caught
3
AI tools
Patient name
18
Date of birth
12
MRN
9
Phone
5
Insurance ID
3
chatgpt.com · paste · 2 identifiers
3 MIN AGO
claude.ai · document · 5 identifiers
12 MIN AGO
gemini.google.com · paste · 1 identifier
1 H AGO
perplexity.ai · document · 0 identifiers (clean)
3 H AGO
Export on your device

Illustrative view. Counts, categories, site, and time only. Never the text, file contents, or filename.

What is stored

Counts of identifiers detected, the categories they fell into, the AI tool they were headed to, and the timestamp. That is the entire record.

What is never stored

The text you pasted. The contents of files you attached. The filename. None of that is written to the activity view or included in the export.

CSV or JSON, on your machine

The export is built in your browser and saved to your own device. Useful for your own record-keeping, or for a monthly review with your compliance advisor. It is your record.

Detection happens entirely in your browser. Your text and your files are never uploaded, stored, or sent anywhere by the extension.

Honest about what this is

What AI Leak Guard does - and what it doesn't.

Privacy tools that overstate what they do are a bigger risk than the problem they solve. Here's the plain truth, in one place, in your language.

✓

What it does

  • →Detects sensitive patient identifiers before you paste them into a supported AI tool
  • →Checks your message at the moment you send it on ChatGPT, Claude, Gemini, and Microsoft Copilot (two-press review), so typed or dictated content is caught too
  • →Reads the PDF, Word, Excel, PowerPoint or text files you attach and warns you before they upload
  • →Lets you replace identifiers with placeholders in one click, or cancel
  • →Keeps a local activity history you can review (counts, categories, site, time - never content) and export to CSV or JSON on your device
  • →Reduces the chance - and the blast radius - of accidental disclosure
  • →Helps your team follow an AI acceptable-use policy in practice, not just on paper
✕

What it doesn't do

  • ×Make ChatGPT, Claude, Gemini, Perplexity, or Copilot compliant with any regulation
  • ×Guarantee every possible identifier is caught
  • ×Read files it cannot open as text (like scanned images) - those get flagged so you decide, not silently missed
  • ×Scan document uploads on Microsoft 365 Copilot (the work or school version) - those go into your organization's Microsoft 365 environment
  • ×Replace a Business Associate Agreement
  • ×Replace your organization's privacy and security program
  • ×Constitute legal or compliance advice

This is a preventive privacy control that helps reduce risk. It's a safety net that keeps you in control - not a guarantee, not a compliance product.

For clinics & teams

Deploying across a practice? Talk to us.

Individual protection is free forever. For practices, we're building centralized deployment, simple policy configuration, and aggregate visibility into risky AI submissions prevented - shown as metadata only, never patient content ("AI Leak Guard protected 27 risky submissions this week - without ever seeing your patient data"). Pricing is being finalized with early practices.

Get early access Ask a question

Also relevant to: healthcare IT providers, MSPs managing multiple clinics, and HIPAA compliance consultants recommending tooling as part of an acceptable-use policy.

Built by Zabcore

An independent studio building privacy-first tools.

Not VC-funded. Not data brokers. Not building toward acquisition. Just small, focused tools that respect your data - built the way we'd want them built if they ran on our own systems.

View the source on GitHub
MIT
License
< 200KB
Extension size
< 5ms
Per-paste scan
0
Servers needed
Honest answers

Frequently asked questions.

No. Detection happens entirely in your browser. Your text and your files are never uploaded, stored, or sent anywhere by the extension. You can verify this in our open-source code on GitHub. Full details on /privacy.

No, and no software can, on its own. AI Leak Guard is a technical safeguard that supports your HIPAA program: it reduces the risk of impermissible PHI disclosure to third-party AI tools that don't have a BAA with your practice. Compliance itself remains your organization's responsibility. AI Leak Guard supports your organization's HIPAA compliance efforts. It does not, by itself, make any organization HIPAA compliant.

It's free for individual healthcare workers - free forever, not a trial. Centralized deployment and policy options for clinics and teams are being built with early practices; pricing is being finalized. Talk to us if you're deploying across a practice.

Send-time protection (checks your message the moment you send it) runs on ChatGPT, Claude, Gemini, and Microsoft Copilot (copilot.microsoft.com). Copilot uses a two-press review to fit its send flow. Paste checking also covers Perplexity. Document scanning (PDF, Word, Excel, PowerPoint or text files) covers ChatGPT, Claude, Gemini, and Perplexity - not Copilot. Send-time protection on Perplexity is planned for a later release. All of this in Google Chrome. Edge, Brave, and Arc also work today because they're Chromium-based. Firefox and Safari are on the roadmap but not yet supported.

Yes. Send-time protection now covers Microsoft Copilot (copilot.microsoft.com) with a two-press review that fits its send flow. Paste checking is also covered. Document scanning is not: attachments on Copilot are not intercepted by AI Leak Guard. Microsoft 365 Copilot (the work or school version at m365.cloud.microsoft) is out of scope entirely - files uploaded there go into your Microsoft 365 environment and are governed by your Microsoft 365 and Purview controls. AI Leak Guard focuses on the personal and unmanaged AI tools those controls often do not cover.

No account, no login, no setup, no configuration. Add it to Chrome and it works. Zero friction - the same reason people fell in love with the AI tools we're helping you use safely.

Yes. The full source code is open on GitHub under an MIT license. Anyone - your IT contractor, your compliance consultant, a security-minded family member - can audit exactly what the extension does.

It catches a broad set of common patient identifiers - names, DOBs, addresses, phone numbers, MRNs, insurance IDs, claim numbers, SSNs, and financial identifiers - both in pasted text and in the documents you attach. But no tool can guarantee every possible identifier, and files it cannot read as text (like scanned images) are flagged so you decide, not silently missed. AI Leak Guard is a safety net that keeps you in control, not a guarantee.

You always make the final call. On paste, you see the preview and choose: Paste protected version, Paste as-is, or Cancel. On an attached document, you get a warning listing exactly which identifiers were found and you choose: Upload anyway, or Cancel upload. The extension does not edit or redact your file - it just tells you what is in there before it leaves your device. Nothing is silently rewritten and nothing uploads until you choose. You can also disable the extension entirely from the popup for the current tab or forever.

No. Paste detection runs in under 5 milliseconds for typical content. Document scanning takes as long as it takes to read the file - usually a fraction of a second for typical PDFs, Word, Excel, PowerPoint or text attachments, longer for very large files. The extension is under 200KB and makes no outbound network requests at all: no server contact, no telemetry, no runtime fetches. Detection patterns are bundled and change only when the extension itself updates through the Chrome Web Store.

Add it in 30 seconds

Free, local-only, open source. That's the whole product.

No account. No email. No tracking. Add it to Chrome and it's on. You can disable it any time from the popup, on any tab, forever.

Add to Chrome - free

Live on the Chrome Web Store · MIT-licensed · source on GitHub.

github.com/zabcore/ai-leak-guard · MIT licensed · Built by Zabcore