CloakLLM for Health

Use AI with patient data. Without exposing your patients.

Names, record numbers and dates of birth are removed before a prompt reaches any AI model. The clinical question arrives intact, and the answer comes back with the patient’s details restored.

Book a data-protection assessmentRuns on your systems. Patient data never reaches us.

Stays on your infrastructure

Self-hosted. Not a cloud service that sees your data.

Audit-ready by design

Every AI request is recorded, with no patient data in the record.

Open source

Inspect it, verify it, never be locked in.

The problem

Your clinicians are already asking AI about patients.

They paste notes into chatbots to summarise a history, check an interaction or draft a letter. Your product team is wiring AI into the same workflows. Every one of those prompts can carry a patient's identity to a company you have no agreement with.

Regulators

Health data is a special category under GDPR, protected health information under HIPAA, and sensitive data almost everywhere else.

Patients

Trust is the whole relationship. A leaked diagnosis is not something an apology repairs.

Your AI roadmap

Without a safe way to use patient data, the useful AI projects stall in review.

See the difference

Generic privacy settings miss what matters in clinical text.

The same note, run through CloakLLM twice. Generic settings let the record number and date of birth through, and removed a drug name the doctor needed answered. Tuned for health data, it removed exactly the patient's identity and nothing else.

Generic settings

Patient ████(removed), MRN 00482913, DOB 03/14/1961, phone ████(removed), email ████(removed). 64-year-old woman with type 2 diabetes, HbA1c 8.9%, eGFR 52.4, on metformin 1000 mg twice daily. Should we add an SGLT2 inhibitor?

red sent to the AIamber removed, but needed

CloakLLM for Health

Patient ████(removed), MRN ████(removed), DOB ████(removed), phone ████(removed), email ████(removed). 64-year-old woman with type 2 diabetes, HbA1c 8.9%, eGFR 52.4, on metformin 1000 mg twice daily. Should we add an SGLT2 inhibitor?

██ removed before sending, restored in the answer

Real output from CloakLLM 0.12.7 on a fictitious patient. Every organisation writes notes differently, which is why we tune and measure on yours.

Who it is for

Built for everyone putting AI near patient data.

Health-tech and digital health

Ship AI features without sending patient identities to your model provider, and show buyers and regulators the evidence.

Hospitals and clinics

Let staff use AI on real cases with identifiers removed, and know what is being sent.

Consumer health apps

Keep users' health data away from third-party AI services, wherever your users are.

Any region

One engine, mapped to the rules you answer to.

CloakLLM runs the same way everywhere. What changes is the rulebook, and we map it with you.

European Union

GDPR Article 9, the European Health Data Space, and the AI Act's rules for high-risk health AI.

United States

HIPAA for providers and insurers; the FTC and state health-privacy laws for consumer apps.

United Kingdom

UK GDPR, which treats health data as a special category.

Elsewhere

Most privacy laws treat health data as sensitive. The local mapping is part of the assessment.

CloakLLM helps you meet these obligations. It does not make an organisation compliant on its own, and this page is not legal advice.

Start here

The data-protection assessment

You will know exactly what your AI tools send about your patients, and have a setup that stops it.

01

Scoping call

Which AI tools you use, what goes into them, and which rules apply.

02

Measure on your data

We run CloakLLM with your team, on your systems. Patient data never leaves them.

03

Clear report

What was protected, what got through, and the fix, measured again.

04

Yours to keep

The setup, the report and the evidence. No lock-in.

Book an assessmentFixed fee, quoted after the scoping call.

Why trust it

Privacy software you can check, not just believe.

Open source, MIT licensed

Every line of the engine is public. Your security team can read it before you commit.

Verifiable records

A free, standalone verifier lets your auditor check the AI usage record on their own machine, without trusting us.

The engine is always free

You should not have to pay to find out whether patient data is leaking. We charge for the assessment and the health edition.

Honest about limits

It hides who the patient is, not the clinical content the AI needs. It does not read images. It is one control, not a compliance certificate.

Find out what your AI tools are sending about your patients.

Tell us which tools you use. We will reply with a scope and a fixed price. Please do not include any patient data in your email.