Shield · Outbound PHI Guard
Compliance you can actually verify.
Shield screens every outbound message before it leaves your practice's number. Anything that looks like protected health information is blocked and logged, not delivered. Here is exactly what it checks and what it doesn't.
How it works
Three steps. No exceptions.
Looks for identifiers
Every outbound message is checked against five patterns: Social Security numbers, labeled fields like MRN, DOB, or insurance ID, and any run of 10 or more digits, the shape a member ID takes.
Blocks before it sends
A match stops the message. It is never delivered. There is no one-tap rewrite or auto-suggestion. The sender has to remove the identifier and send it again themselves.
Logs every block
Every blocked attempt is recorded: channel, timestamp, reason. Nothing about the block relies on someone remembering to report it.
It blocks identifiers. It doesn't read medicine. Shield is a pattern matcher. A message describing symptoms in plain language, with no identifier attached, won't be flagged. That boundary is deliberate, and it's the honest limit of what a pattern matcher can promise.
Beyond the guard
The rest of a HIPAA program
The message filter is one layer. The others run underneath it, all audited.
BAA tracked at onboarding
Your Business Associate Agreement status is tracked from the day you sign up, surfaced in your dashboard’s compliance panel alongside your audit log.
10DLC readiness gate
A medical number can’t go live until its SMS brand clears carrier registration. Same gate every vertical has to clear, with no bypass for medical.
Break-glass access, logged
When an engineer needs to touch PHI outside the normal app flow, the session is time-boxed to four hours, tied to a written reason, and closed with its own audit row.
Data-subject requests
Patient access and deletion requests are handled through an internal, audited workflow. Every export or redaction is logged against the request that triggered it.
FAQ
Common questions
Which channels does the guard run on?
SMS, WhatsApp, and email today. It checks the message before it leaves your organization’s number or address, ahead of send.
Is RexRuby SOC 2 certified?
A SOC 2 audit is in progress. We say that plainly rather than claim a certification that doesn’t exist yet.
Why is voice locked to OpenAI for medical and dental orgs?
xAI Grok offers no HIPAA BAA for call audio, so it is off by default for every HIPAA org and cannot be turned on from settings. OpenAI’s realtime models are the only voice engine available to HIPAA practices.
HIPAA-safe from the first patient.
$999/mo flat · BAA included · No card charged until day 8 · Cancel anytime