"We strip PHI before it reaches the model" is one of the most common claims on healthcare AI product pages, and one of the least specific. It's worth asking what it actually describes, because the answer determines whether the claim is checkable or just reassuring language.
At minimum, it should describe a de-identification or tokenization step: a process that finds identifiers such as patient names, dates of birth, medical record numbers, and addresses, and replaces them with placeholders before any text leaves your session. The identifiers get swapped back in only on the way back to you, inside your own account.
That's different from encryption, which protects data in transit and at rest but doesn't change what the data says. An encrypted message still contains a patient's name once it's decrypted at the other end. Tokenization and encryption solve different problems, and a serious security page should describe both rather than using "encrypted" to imply de-identification happened too.
It's also worth checking whether the claim applies everywhere identifiers could show up. A chat box, a dictated note, and an uploaded PDF are three different entry points, and a de-identification step that only covers typed text won't catch a name buried in a scanned referral.
The honest version of this claim names the specific mechanism (a tokenization step, not just "encryption"), states what triggers it (before text reaches any model, across chat, dictation, and document uploads), and is willing to say what hasn't been independently certified yet, rather than implying a certification that doesn't exist. If a page can't do that, the claim is doing more reassuring than informing.
