7 configurable protection methods per data type. Auto-detection of sensitive fields and built-in HIPAA Safe Harbor with 18 PHI identifiers.
7
Protection Methods
18
HIPAA Identifiers
11+
PII Types Detected
11+
PHI Types Detected
Each method has different characteristics. Choose based on whether you need to recover the data and your security requirements.
MASKMaskingPartial masking that hides most characters but preserves format. Useful for display and logs.
Original data CANNOT be recovered. Only use if you don't need the full value.
Good for
Not for
Examples
HASHSHA-256 HashOne-way cryptographic hash. Same input always produces same output. Perfect for deduplication.
Original data CANNOT be recovered. Only use for comparison/deduplication.
Good for
Not for
Examples
REDACTRedactionComplete removal and replacement with placeholder text. Maximum data minimization.
Data is PERMANENTLY DELETED. Use only when you truly don't need the value.
Good for
Not for
Examples
ENCRYPTAES-256 EncryptionReversible encryption. Data can be decrypted with the encryption key. Recommended for PHI.
Recommended for data you need to access later. Requires encryption key management.
Good for
Examples
TOKENIZETokenizationReplace with a token reference. Original stored in secure vault. Best for PCI-DSS.
Best for references that pass through multiple systems. Vault required.
Good for
Examples
GENERALIZEGeneralizationReduce precision while maintaining analytical value. Required by HIPAA Safe Harbor for dates.
HIPAA Safe Harbor requires dates to be generalized to year only. ZIP codes to first 3 digits.
Good for
Not for
Examples
SKIPSkip (No Protection)No transformation applied. Data passes through unchanged. Use for non-sensitive fields.
Data is NOT protected. Only use for non-sensitive fields.
Good for
Not for
Examples
Nexion automatically detects these PII types and applies the configured protection method. Override defaults per field or per Data Pod.
EMAILEmail addresses
PHONE_NUMBERPhone numbers
PERSON_NAMEFull names
ADDRESSPhysical addresses
SSNSocial Security Numbers
CREDIT_CARDCredit card numbers
DATE_OF_BIRTHBirth dates
IP_ADDRESSIP addresses
PASSPORT_NUMBERPassport numbers
DRIVER_LICENSEDriver license numbers
BANK_ACCOUNTBank account numbers
HIPAA Safe Harbor de-identification requires removing or generalizing 18 specific identifiers. Nexion automatically detects and protects all 18 when PHI protection is enabled.
AI-powered detection identifies PHI fields with configurable confidence threshold (default 80%).
PHI fields cannot be downgraded to less secure methods. ENCRYPT or TOKENIZE required.
Business Associate Agreement available for enterprise customers handling PHI.
Healthcare-specific data types automatically detected and protected with ENCRYPT by default.
MEDICAL_RECORDMedical record numbers
HEALTH_CONDITIONDiagnoses, conditions
MEDICATIONPrescriptions, medications
TREATMENTTreatment information
DIAGNOSISDiagnosis codes (ICD-10)
LAB_RESULTLaboratory results
PATIENT_IDPatient identifiers
PROVIDER_IDHealthcare provider IDs
HEALTH_PLAN_IDInsurance plan IDs
DEVICE_IDMedical device identifiers
BIOMETRIC_IDBiometric identifiers
Sensitive data is never persisted unprotected. Our architecture ensures HIPAA compliance through defense in depth: protection at the pipeline level AND the storage level.
First line of defense
Data Flow
Source → Extract → Transform → PII/PHI Node → Load
Second line of defense
Safety Net
Pipeline Output → DataPod → Protected Storage
Nexion scans your source tables and discovers the schema structure.
AI analyzes column names, data types, and sample values to detect sensitive fields.
Default protection rules are applied based on the Data Pod's compliance level.
Review detected fields and override protection methods as needed.
During extraction, transformation applies the configured protection methods.
Every protection action is logged with field, method, and timestamp.
Start detecting and protecting PII/PHI automatically with Nexion.