DataStealth
HIPAA Compliance

Protect PHI Everywhere.
Simplify HIPAA Compliance.

Real safeguards for Protected Health Information, deployed inline, without disrupting clinical or operational systems.

Schedule a Demo

How DataStealth Helps With HIPAA Compliance

Tokenization & Masking

Replace PHI with secure tokens or masked values so raw identifiers never appear in systems.

Data Discovery & Classification

Locate PHI across structured, unstructured, on-prem, and cloud environments.

Dynamic Access Control

Enforce role-based, "minimum necessary" access to PHI.

Flexible Deployment

Deploy on-prem, in the cloud, or hybrid: no application rewrites.

De-Identification

Protected by Default. De-Identified When You Need It.

A DataStealth token can only be reversed from inside the vault, by a request from an authorized system, verified against policy. Outside that boundary, a token carries no mathematical or statistical relationship to the original value; an attacker who exfiltrates tokenized PHI gets nothing usable. Because that reversal path exists for legitimate purposes, HIPAA classifies the data as PHI, so it keeps receiving the Security Rule's full protection rather than falling out of scope.

HIPAA also recognizes two ways to remove data from PHI status entirely: Safe Harbor, which requires removing all 18 identifiers defined under §164.514(b)(2), and Expert Determination, where a qualified statistician certifies that re-identification risk is very small. A Limited Data Set sits in between: direct identifiers are stripped, but dates and geography can remain, and it still requires a signed Data Use Agreement.

DataStealth supports both models from the same platform. Keep tokenization reversible for day-to-day operations, where clinicians, applications, and analytics keep working and authorized users can always recover the real value. Or configure irreversible masking across all 18 Safe Harbor fields when you need output that is no longer PHI at all. If your use case calls for Expert Determination instead, DataStealth's protected output is a strong foundation for your independent statistician's certification.

Safe Harbor · 18 identifiers§164.514(b)(2)
Names
Geographic subdivisions smaller than a state
Dates (except year) tied to an individual
Telephone numbers
Fax numbers
Email addresses
Social Security numbers
Medical record numbers
Health plan beneficiary numbers
Account numbers
Certificate / license numbers
Vehicle identifiers and serial numbers
Device identifiers and serial numbers
URLs
IP addresses
Biometric identifiers
Full-face photos and comparable images
Any other unique identifying number or code

Three Paths, Three Different Outcomes

Safe Harbor

§164.514(b)(2)

All 18 identifiers above are removed or generalized, with no actual knowledge that what remains could still identify someone. Output is no longer PHI.

Expert Determination

§164.514(b)(1)

A qualified statistician applies accepted methods and formally certifies that re-identification risk is very small. Output is no longer PHI.

Limited Data Set

§164.514(e)

Direct identifiers are stripped but dates and geographic detail down to town/city/state/ZIP may remain. Still PHI: requires a signed Data Use Agreement.

More Than a Checkbox. Real Safeguards for PHI.

HIPAA requires covered entities and business associates to implement administrative, physical, and technical safeguards for PHI at rest, in motion, and in use. Compliance is about more than policies: it's about keeping PHI out of reach in the first place.

business associate status
Business Associate AgreementEXECUTED

DataStealth is a business associate under HIPAA. We execute a signed BAA with every covered entity and business associate customer before touching PHI, and operate under its safeguard obligations for the life of the relationship.

Ready to Simplify HIPAA Compliance?

Talk to a DataStealth architect about protecting PHI across every clinical and operational system.

Schedule a Demo