PHI De-identification by ClerkAI
ClerkAI · Software Development
Certification per AWS Marketplace.
Evidence tier Source Confirmed · 4 captures on record
What the publisher says
As described on AWS Marketplace.
PHI De-identification by ClerkAI is a production-ready API that identifies, anonymizes, and de-anonymizes Protected Health Information (PHI) in medical text using large language models (LLMs). It is deployed entirely within your AWS account, ensuring your patient data never leaves your environment.
The product supports three storage backends to fit your architecture:
Show the rest of the publisher’s description (6 more lines)
- AWS KMS for encryption-at-rest with no database required,
- DynamoDB Token-Based storage for scalable token lookups, and
- DynamoDB Record-Based storage for granular per-record retrieval and deletion.
All anonymization is fully reversible - original PHI values can be restored at any time using the same API.
Deployed via a single CloudFormation stack, the product provisions an EC2 instance (pre-baked AMI), DynamoDB tables, a KMS key, IAM roles, and a CloudWatch log group with no manual setup.
A built-in web dashboard provides an interactive interface for anonymization, deanonymization, token lookup, and API key management. Access is secured with named API keys backed by DynamoDB, supporting optional expiry and individual revocation. The instance runs in a private subnet with VPC peering and AWS SSM Session Manager support for secure access without exposing a public IP.
Highlights
Highlighted by the publisher on AWS Marketplace.
AI powered PHI extraction and anonymization. Identifies names, dates, SSNs, addresses, and 19 other PHI categories from unstructured medical text with no custom training required.
Fully reversible anonymization with AWS KMS encryption and DynamoDB token storage. Original PHI values can be restored at any time, supporting both de-identification and re-identification workflows.
Designed for sensitive healthcare data. Runs entirely inside your AWS account in a private VPC subnet with no public IP, KMS-encrypted PHI at rest, IAM-controlled least-privilege access, individually-revocable named API keys, and CloudWatch audit logging on every request. Patient data never leaves your environment.
Agent build and provenance
See the full provenance
The layer-by-layer build, the evidence behind each claim, the risk basis and the cross-marketplace links are open to any account. Some rows are disclosed, some the source leaves Unknown; a free account shows you which.
Plans and pricing as listed
21 listed- Hrs
- Hrs
- Hrs
- Hrs
- Hrs
- Hrs
- Hrs
- Hrs
- Hrs
- Hrs
- Hrs
- Hrs
Refund terms
As stated by the publisher on AWS Marketplace.
Please contact clerkai@generative-technologies.com to request a refund. We will respond within 2 to 7 business days.
Sources
Linked repositories
Unknown means this listing does not publish a repository. It is not a statement that the code is closed, and a linked repository is not a claim that the publisher wrote it: the registry computes that relationship privately and does not publish it.
Evidence risk is the share of the build you cannot see before you deploy, not a security rating. Sign in to see the layer-by-layer basis for this band.

