Here’s how a file moves through the system
Our copies destroyed — logged independently
Data Protection Controls
What we log
Our logs are PHI-clean. We record the coverage decision and the counts — how many identifiers were found and masked, and of which kind — never the values of your cells. The evidence we keep describes what we did, not what your data says.
What you keep
Every completed job comes with a downloadable processing receipt — a verifiable record for your files: the job reference, the coverage class applied, per-category masking counts, SHA-256 hashes of your original and masked files, and the deletion schedule. For a clinical file, it also carries the Business Associate Agreement version and the timestamp you attested.
The symmetry is the point: the receipt is your record, and our logs are PHI-clean — neither ever contains the values from your file.
Supports Safe Harbor workflows
PDM supports the Safe Harbor de-identification method under a Business Associate Agreement attestation — no “HIPAA certified” badge exists for any tool, and we don’t claim one. The BAA is a standing agreement you can read here.
Supports EU and California privacy practices
Masking supports GDPR pseudonymisation and data-minimisation practices — the safeguards Articles 25 and 32 call for when sharing personal data.
Masking supports CCPA deidentification and data-minimization practices — reducing what your shared files carry under California and similar state privacy laws.
Files are encrypted, hidden, protected, processed, and deleted. No unauthorized access, either direction.
We test our detection against pre-assessed, scored datasets and analyze every exception. Full methodology and benchmark results are available on request. Detection results are published on the Safe Harbor detection page.