Skip to main content

phi-guard-mcp

CI Release Python License

MCP server and CLI for detecting, redacting, and auditing PHI before medical text is sent to AI agents.

phi-guard-mcp is healthcare AI safety infrastructure, not a clinical product. It is a local, rule-based guardrail that helps developers identify PHI-like identifiers in plain text, redact them with stable placeholders, and produce audit-friendly JSON before content reaches an AI agent or MCP workflow.

Proof points for maintainers:

  • Synthetic benchmark with exact-match PHI finding evaluation.
  • Safe Harbor mapping audit fields for review workflows.
  • CI privacy gate that blocks PHI-like identifiers in maintained source and docs.
  • CLI, Python API, and MCP stdio tools sharing one stable JSON result model.

Important scope limits:

  • Not for diagnosis, treatment, triage, medical advice, or medication recommendations.
  • Not a HIPAA compliance guarantee and not a substitute for legal, privacy, or security review.
  • Not an FDA-regulated clinical decision support or device software function.
  • Do not test with real patient records. The examples in this repo are synthetic.

The project aligns its documentation vocabulary with HHS HIPAA de-identification concepts such as Safe Harbor and Expert Determination, while intentionally avoiding clinical decision support scope. See HHS de-identification guidance, FDA CDS guidance, and FDA device software functions.

Install

Install from the current GitHub release wheel:

python -m pip install https://github.com/charlesree826/phi-guard-mcp/releases/download/v0.1.2/phi_guard_mcp-0.1.2-py3-none-any.whl

For local development:

python -m pip install -e ".[dev]"

PyPI publishing is configured through GitHub Actions trusted publishing and will be enabled after the PyPI package owner creates the matching pending publisher entry for this repository.

Quickstart

Scan a synthetic note:

phi-guard scan examples/synthetic_clinical_note.txt

Redact PHI-like identifiers:

phi-guard redact examples/synthetic_clinical_note.txt --out /tmp/synthetic_redacted.txt

Audit a note:

phi-guard audit examples/synthetic_clinical_note.txt

Validate text before it enters an AI agent:

phi-guard validate examples/synthetic_clean_note.txt

Run the synthetic benchmark:

phi-guard benchmark benchmarks/synthetic/cases --out benchmarks/synthetic-report.json

Run the repository privacy gate:

phi-guard gate --config .phi-guard.toml

All CLI commands output stable JSON for automation.

See docs/demo.md for a complete CLI and MCP transcript.

MCP Server

Run the stdio MCP server:

phi-guard-mcp

Available tools:

  • scan_phi(text)
  • redact_phi(text, mode="placeholder")
  • audit_deidentification(text)
  • validate_no_phi(text)

MCP tools return the same finding schema as the CLI, including safe_harbor_identifier.

Example MCP client config:

{
  "mcpServers": {
    "phi-guard": {
      "command": "phi-guard-mcp"
    }
  }
}

Python API

from phi_guard_mcp import audit_text, evaluate_benchmark, redact_text, scan_text, validate_no_phi

result = scan_text("Patient Name: Jordan Rivera, MRN: MRN-48291")
redacted = redact_text("Patient Name: Jordan Rivera, MRN: MRN-48291")
audit = audit_text("Patient Name: Jordan Rivera, MRN: MRN-48291")
validation = validate_no_phi("No identifiers are present in this synthetic note.")
benchmark = evaluate_benchmark("benchmarks/synthetic/cases")

What It Detects

The first release focuses on plain text and common PHI-like identifiers:

  • Names in clinical label contexts
  • Dates
  • Phone numbers
  • Email addresses
  • Address-like fragments
  • Medical record numbers
  • Social Security numbers
  • URLs and IP addresses
  • Medical facility names
  • Account, member, policy, and patient ID tokens

This is a deterministic heuristic engine. It favors transparent behavior and repeatable JSON over opaque model judgment.

Safe Harbor mapping is included as a review aid only. It does not make output HIPAA compliant and does not replace Expert Determination or legal review.

Project Docs

Development

python -m compileall -q src tests
python -m pytest -q
ruff check .
phi-guard gate --config .phi-guard.toml
python -m build
twine check dist/*

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

phi_guard_mcp-0.1.2.tar.gz (26.0 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

phi_guard_mcp-0.1.2-py3-none-any.whl (14.7 kB view details)

Uploaded Python 3

File details

Details for the file phi_guard_mcp-0.1.2.tar.gz.

File metadata

  • Download URL: phi_guard_mcp-0.1.2.tar.gz
  • Upload date:
  • Size: 26.0 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.12

File hashes

Hashes for phi_guard_mcp-0.1.2.tar.gz
Algorithm Hash digest
SHA256 69abe21fa97994e4af49e1e006c97fcdcd5ed9ff2c724754be51bfdb098e2647
MD5 e49a4b05c23eae4a2e3e6b830efe69ff
BLAKE2b-256 d26335d4ea49dd4a3daf623fb752b6dcdb5d76ea98a7ddb35fe72c5a5a1c4a95

See more details on using hashes here.

Provenance

The following attestation bundles were made for phi_guard_mcp-0.1.2.tar.gz:

Publisher: publish.yml on charlesree826/phi-guard-mcp

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file phi_guard_mcp-0.1.2-py3-none-any.whl.

File metadata

  • Download URL: phi_guard_mcp-0.1.2-py3-none-any.whl
  • Upload date:
  • Size: 14.7 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.12

File hashes

Hashes for phi_guard_mcp-0.1.2-py3-none-any.whl
Algorithm Hash digest
SHA256 a98136f703919590597240e8a098b1b92de1cd14868d56082c7dd41b4647a5e9
MD5 cafff328ba710981a174aab19e54bc7b
BLAKE2b-256 c0b4aba3e36e5a2aa6e134554304fdd0d21920882ab95a5e8f732ef4cbc198d0

See more details on using hashes here.

Provenance

The following attestation bundles were made for phi_guard_mcp-0.1.2-py3-none-any.whl:

Publisher: publish.yml on charlesree826/phi-guard-mcp

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Release history Release notifications | RSS feed

This release

0.1.2 This release

2 files

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page