HIPAA Readiness

Find where PHI is in your cloud data estate.

PostQKey classifies Protected Health Information across your connected data stores. Surfaces PHI in unexpected locations: data warehouses, SaaS exports, and object storage. PostQKey does not certify HIPAA compliance. It discovers and classifies PHI to support your internal security review.

What PostQKey classifies as PHI.

PostQKey detects PHI identifiers at the field level using pattern matching and contextual classification. It does not rely on column names alone. It samples actual field values to determine whether the content matches PHI patterns in context. A column named "code" in a claims dataset with ICD-10 values is flagged. A column named "diagnosis" in a config table with text like "ERROR" and "PENDING" is not. Confidence scores are shown for every finding, and configurable sample data is available so your team can review before acting.

  • Names in context with health conditions
  • Dates of service and dates of birth
  • Social Security Numbers
  • Medical record numbers
  • Health plan beneficiary numbers
  • ICD-10 diagnosis code patterns
  • CPT procedure code patterns
  • Device identifiers in clinical context

PostQKey shows confidence scores and sample data, not binary PHI/not-PHI. Your security team reviews the results and determines the appropriate response. The tool informs the decision, not the other way around.

How security teams use PostQKey for HIPAA readiness.

1

Run PostQKey scan across connected stores

Connect your data stores with read-only credentials. PostQKey crawls, samples, and classifies fields across warehouses, object stores, and SaaS apps.

2

Export PHI inventory to your security team

Download the PHI classification results as CSV or JSON. Each finding includes: store ID, field name, confidence score, location, access count.

3

Review unexpected PHI locations

Focus on PHI found outside designated covered systems: analytics staging tables, data lake exports, SaaS integrations, BI tool caches. These are the unexpected locations that manual review misses.

4

Remediate and re-scan to verify

Restrict access, encrypt stores, delete unnecessary PHI copies, or document the legitimate processing reason. Re-scan to confirm the finding is resolved. PostQKey supports the remediation workflow by making re-verification fast. It does not make legal determinations about HIPAA compliance and is not a substitute for a compliance officer or legal review. It is a data discovery tool for security teams.

Scan for PHI in your cloud estate.

Connect data stores. PostQKey surfaces where PHI is. Your team determines what to do about it.