Hospitals run on Gmail and cannot switch it off. The same staff now paste discharge notes and lab reports into browser AI tools to summarise them. No email control sees that text leave.
Email volumeText pasted into browser toolsSends a control actually inspects
How it works
One extension. Two enforcement paths.
Install the extension
One Chrome extension, enrolled with the organization code. It runs on Gmail and on every other http and https page.
Gmail sends are held
Subject, body, recipients and attachments are scanned server-side, and the policy returns allow, warn, quarantine or block.
Every other text box is guarded
Paste, keystroke, drop and autofill are checked inside the page against the same rule pack. Nothing typed is transmitted.
Reviewers see all of it
Quarantined mail waits for an approver. Every verdict lands in an append-only audit log and in analytics split by channel.
Core features
Four parts, one verdict
Detection finds the identifiers. Extractors open the attachments. Policy turns the findings into a verdict. The audit log records what was decided.
Discharge summarySCANNING
Aadhaar number**********7460
Medical record numberUHID 00*****18
Diagnosis codeU09.9
Date of birth**/**/1971
4 identifiers, masked before storage
01/
Detection
21 identifier types, validated by checksum where one exists
4 attachmentsOCR ON
discharge.pdf0%
patients.xlsx0%
scan.png0%
records.zip0%
02/
Attachments
Every attachment opened, scanned pages read by OCR
PolicyFIRST MATCH
01blocked-recipient-domain
02unapproved-sender-with-phi
03high-risk-phi-to-public-emailquarantine
04medium-risk-phi-external
03/
Policy
Ordered rules that return allow, warn, quarantine or block
Audit logAPPEND ONLY
8f3c...a91elinked
b207...4dd1linked
e0df...b714linked
df5f...5276linked
Each hash covers the row before it
04/
Audit
A hash-chained log in which a removed row shows
PHI
Corpus [119 documents]: measured 0.9826 entity F1, 0 false alarms on clean mail
Detection matches spans. A note saying the patient in bed 7 became oliguric overnight carries no Aadhaar number, no MRN and no name. It scores 0.0 and it is allowed.
The extension is a deterrent against an accidental send, not a guarantee. Mobile Gmail, a second browser and a disabled extension all route around it.
Subject, body and attachments are scanned the moment send is pressed. A clean mail goes straight out. A risky one returns a warning that names the identifier types it found.
02/Billing
Billing and insurance desks
Attachments are opened, not trusted by their name.
PDF, DOCX, XLSX, PPTX, ZIP and EML are extracted and read, and scanned pages go through OCR. Files are classified by content signature, so renaming one does not skip the scan.
03/Compliance
Security and compliance
An audit log that shows when a row goes missing.
Every verdict is appended and each entry hash covers the one before it, so an edited or deleted row breaks the chain. Only masked values are stored: an Aadhaar number is kept as **********7460.
04/IT
IT administration
One policy, edited with a live preview.
Ordered first-match rules over recipient class, risk score, severity, entity type and distinct patient count. The editor shows the verdict a draft rule would return before it is saved.
Blade reads the subject, the body and every attachment. Scanned pages go through OCR, and a file is classified by its content signature rather than by its name.
PDF
DOCX
XLSX
XLS
PPTX
RTF
CSV
TXT
EML
ZIP
JPG
Stop the accidental send
One Chrome extension, two enforcement paths, one policy and one audit log.