AI help with the paperwork. Nothing about the patient leaves.
Draft the letter and tidy the summary with names, dates of birth and record numbers replaced on the device, never sent.
What you have
Discharge summary for Tomas Keller, born 14/03/1961, NHS 943 476 5919, of 12 Rowan Court, Leeds.
What the assistant receives
Discharge summary for ⟦PERSON_1⟧, born ⟦DATE_1⟧, NHS ⟦NHS_NUMBER_1⟧, of ⟦ADDRESS_1⟧.
Synthetic. The reply comes back with the tokens in it and the real values are restored on your machine.
- What gets masked
- Names, dates of birth, addresses, contact details and identification numbers. In pseudonymised mode a shifted date stays a plausible date, so the note still reads as a note.
- Where it runs
- The browser extension does the whole round trip with no network access, which you can test by pulling the connection. A cloud de-identification API has to receive the identifiable text before it can remove anything.
- Measured, not promised
- Precision, recall and what still slips through are published per language, along with the honest part: no detector catches everything, so read the numbers before relying on them.
Clinical work generates exactly the text an assistant is good at, and exactly the text with the least room for error in handling. A patient note is identifying almost by definition.
The pasting already happens. The choice is not whether AI touches clinical text, but whether anything identifying is still in it when it does.
What detection catches, and what still slips through, is measured and published on the benchmarks page.
What people ask first
Is masking patient identifiers the same as de-identification under health privacy rules?
Does it recognise medical record numbers and health-specific identifiers?
Can I use this without sending anything to Velum?
See it work on your own data.
Tell us what you work with and we will walk you through it on a call, on your own files. Nothing leaves your machine while we do.
Your address is used to reply to you, and for nothing else.