PHI Compliance Infrastructure

The audit chain your
OCR investigator
can actually read.

Hermes produces a per-token, CFR-cited, SHA-256 hash-chained record of every PHI scrubbing decision — inside your environment, never leaving it. Built for MSPs serving HIPAA-covered entities.

Zero-egress architecture. Data never leaves your environment.

Illustrative output — sample audit stream (CFR citations shown are demo format)

hermes.audit.stream
14:32:01ZREDACT45CFR§164.514(b)(2)(i)(A)sha256:a3f8...c291
14:32:02ZVERIFY45CFR§164.514(b)(2)(i)(B)sha256:7b21...e4f0
14:32:03ZCHAIN_LINK45CFR§164.514(b)(2)(i)(C)sha256:e09a...8d17
14:32:04ZREDACT45CFR§164.514(b)(2)(i)(J)sha256:4d72...91ab
14:32:06ZSEAL45CFR§164.514(b)(2)(i)(P)sha256:8c54...0e3d
14:32:07ZREDACT45CFR§164.514(b)(2)(i)(Q)sha256:b6f1...2a48
14:32:09ZVERIFY45CFR§164.514(b)(2)(i)(A)sha256:1e9d...5b76
14:32:10ZREDACT45CFR§164.514(b)(2)(i)(B)sha256:fa30...c812
14:32:11ZCHAIN_LINK45CFR§164.514(b)(2)(i)(C)sha256:25a7...8e09
14:32:13ZREDACT45CFR§164.514(b)(2)(i)(J)sha256:9b4c...d367
14:32:14ZSEAL45CFR§164.514(b)(2)(i)(P)sha256:6e08...41fc
14:32:16ZVERIFY45CFR§164.514(b)(2)(i)(Q)sha256:cd17...a59b
14:32:01ZREDACT45CFR§164.514(b)(2)(i)(A)sha256:a3f8...c291
14:32:02ZVERIFY45CFR§164.514(b)(2)(i)(B)sha256:7b21...e4f0
14:32:03ZCHAIN_LINK45CFR§164.514(b)(2)(i)(C)sha256:e09a...8d17
14:32:04ZREDACT45CFR§164.514(b)(2)(i)(J)sha256:4d72...91ab
14:32:06ZSEAL45CFR§164.514(b)(2)(i)(P)sha256:8c54...0e3d
14:32:07ZREDACT45CFR§164.514(b)(2)(i)(Q)sha256:b6f1...2a48
14:32:09ZVERIFY45CFR§164.514(b)(2)(i)(A)sha256:1e9d...5b76
14:32:10ZREDACT45CFR§164.514(b)(2)(i)(B)sha256:fa30...c812
14:32:11ZCHAIN_LINK45CFR§164.514(b)(2)(i)(C)sha256:25a7...8e09
14:32:13ZREDACT45CFR§164.514(b)(2)(i)(J)sha256:9b4c...d367
14:32:14ZSEAL45CFR§164.514(b)(2)(i)(P)sha256:6e08...41fc
14:32:16ZVERIFY45CFR§164.514(b)(2)(i)(Q)sha256:cd17...a59b

✓ Illustrative chain — tamper-evident format shown for demo purposes

The Documentation Gap

Every tool detects PHI.
None of them can prove
what they did with it.

When OCR investigates a business associate, they do not ask whether you had a scrubbing tool. They ask you to produce the evidence — exactly what was found, under which regulation, by which method, in an unbroken chain from scan to audit. Cloud-based competitors run ML models that cannot answer that question. Their architecture makes honest attestation impossible.

What carriers ask

Is MFA enforced for privileged access? How many PHI records do you handle? Can you document what was found and how it was handled?

Coalition Application Q4, Q6 — verbatim

What OCR demands

Produce documentation of your de-identification method, the specific identifiers found, and the regulatory basis for each classification decision.

45 CFR §164.514(b) — Safe Harbor standard

What MSPs cannot produce

A per-token, CFR-cited, cryptographically signed record that documents Safe Harbor-aligned de-identification — with core identifier coverage today and full Safe Harbor coverage actively expanding.

OCR Risk Analysis Initiative — 2026

OCR issued seven resolution agreements against business associates in 2025 alone — the highest enforcement total against business associates since 2013. For MSPs serving healthcare clients, the documentation gap is not a hypothetical compliance problem. It is an active enforcement trend.

How Hermes Works

Deterministic. Zero-egress.
Court-defensible by design.

ARCHITECTURE

Zero-egress

Hermes runs entirely inside your environment. PHI never transits external infrastructure — making your attestations technically accurate, not just aspirational.

METHOD

Deterministic

Regex and a fixed-version spaCy model detect core PHI identifiers — SSN, payment cards, and names, dates, and organizations — with Safe Harbor coverage actively expanding. Never a hosted LLM: the same input produces the same output, every run.

EVIDENCE

Court-defensible

Each decision is recorded as a per-token, CFR-cited event and sealed into a SHA-256 hash chain. The result is an unbroken, tamper-evident record an OCR investigator can verify byte by byte.

Sample audit chain output

Illustrative output — not live product data. CFR citations shown are sample format; per-token citations are actively expanding.

Every scrubbing decision.
Hash-chained.
Audit-ready.

Illustrative sample of Hermes' audit chain format. Today Hermes detects SSN, payment cards, and names, dates, and organizations via spaCy NER — high-recall detection on core identifier types, with transparent per-category coverage. Each redaction is sealed into a SHA-256 hash chain inside your environment. No external processor. No black box.

input.payload
Patient: Sarah Mitchell, DOB 03/14/1978, SSN 412-55-8901
Phone: (555) 000-0000
Diagnosis: Type 2 Diabetes, ICD-10 E11.9
Referring physician requested AI-assisted prior auth summary.

⚠ PHI detected — payload blocked from AI pipeline

output.scrubbed
Patient: [PATIENT_NAME_A], DOB [DATE_C], SSN [SSN_J]
Phone: [PHONE_REDACTED]
Diagnosis: Type 2 Diabetes, ICD-10 E11.9
Referring physician requested AI-assisted prior auth summary.

✓ Core identifiers redacted — name, DOB, SSN, phone numbers (illustrative sample)

hermes.audit.chain — payload_id: hx_20260628_001
5 blocks
blocktimeeventfieldcfr citation
#00000114:32:01ZREDACTPATIENT_NAME45CFR§164.514(b)(2)(i)(A)prev: 0000000000000000hash: sha256:a3f8b291c7e402d1f95a6b3c8e1d4f72a0b5c9e3d6f8a2b4c7e0d3f6a9b2c5e8
#00000214:32:02ZREDACTDATE_OF_BIRTH45CFR§164.514(b)(2)(i)(C)prev: sha256:a3f8b291c7e402d1hash: sha256:7b21e4f0d8c395a2b6f1e8d4c7a0b3e6f9c2d5a8b1e4f7a0c3d6e9b2c5f8a1d4
#00000314:32:03ZREDACTSSN45CFR§164.514(b)(2)(i)(J)prev: sha256:7b21e4f0d8c395a2hash: sha256:e09a8d17f3b4c6e1a2d5f8b0c3e6a9d2f5b8c1e4a7d0f3b6c9e2a5d8f1b4c7e0
#00000414:32:04ZCHAIN_LINKBLOCK_SEAL45CFR§164.312(b)prev: sha256:e09a8d17f3b4c6e1hash: sha256:4d7291ab8c3e6f0a1b4d7e0c3f6a9b2e5d8f1a4c7e0b3d6f9a2c5e8b1d4f7a0c3
#00000514:32:07ZSEALPAYLOAD_SEAL45CFR§164.312(b)prev: sha256:4d7291ab8c3e6f0ahash: sha256:b6f12a48e3c7d0f5a8b2e5d9c1f4a7b0e3d6f9c2a5e8b1d4f7a0c3e6b9d2f5a8b1

✓ Chain integrity verified — each block hash includes the previous block hash. Tamper-evident since block #000001.

Hash-chained audit records are generated inside your environment for every payload Hermes processes. Safe Harbor-aligned documentation with expanding identifier coverage.

Request a Pilot

Technical architecture

What runs. Where it runs.
What it touches.

Hermes deploys as a single Python service inside the customer environment. No external classifier. No data in transit. The scrubbing pipeline is fully deterministic — the same input produces the same output, every run, with a cryptographic record to prove it.

Deployment specification
Deployment targetCustomer environment — Docker, bare metal, or VM
External network callsNone during scrubbing. Zero-egress by design.
Detection methodRegex + fixed-version spaCy NER + Microsoft Presidio
PHI categories covered8 of 18 Safe Harbor identifiers today — expanding
Audit record formatSHA-256 hash-chained JSON — independently verifiable
CFR citation per tokenYes — 45 CFR §164.514(b)(2)(i) subcategory attached
LLM dependencyNone. Deterministic pipeline only.
SigningHMAC-SHA256 per audit record — HERMES_SIGNING_KEY
API surfaceREST — /v1/scrub, /v1/attest, /v1/health
Language / runtimePython 3.12 — uvicorn ASGI

Full technical documentation and API reference available to pilot partners upon request.

Structural differentiation

Three things competitors
cannot replicate without
rebuilding from scratch.

01

Zero-Egress Architecture

Your PHI never leaves your environment. Every competitor's does.

Most cloud-based PHI classifiers -- regardless of vendor -- transit data through external infrastructure to run detection. That transit is the exposure: once PHI crosses your environment's boundary to reach a hosted classifier, a zero-egress claim no longer holds. Hermes runs entirely inside the customer's environment. No external classifier. No data in transit. That architecture is what makes a zero-egress attestation accurate rather than aspirational.

02

Deterministic, CFR-Cited Audit Trail

Every token. Every citation. Every block. Cryptographically sealed.

ML classifiers are powerful and non-deterministic. The same input can produce different outputs on different runs. There is no per-token record. There is no CFR citation attached to each decision. There is no cryptographic proof the log was not tampered with after the fact. Hermes produces a SHA-256 hash-chained, per-token, CFR-cited record of every single scrubbing decision. An OCR investigator can verify it byte-by-byte. No competitor -- open-source or commercial -- can make that statement.

03

Built for MSPs and SMB Healthcare

The customers who need this most are the ones no competitor serves.

Nightfall costs $20,000-$60,000 per year and requires enterprise procurement, a security team, and a multi-month sales cycle. The 10-person billing company in Knoxville, the regional clinic, the MSP managing 15 HIPAA-covered clients -- none of them will ever see a Nightfall contract. Hermes is priced, packaged, and deployed for exactly those customers. Self-hostable. Operational in a week. No enterprise contract, no security team required.

-> No funded competitor produces token-level, CFR-cited, cryptographically-signed scrubbing decision records. That is not a roadmap gap. It is an architectural one.

Who built this

Compliance background first.
Engineering second.
That order matters.

Andrew Rogers, Founder & Engineer at Hermes Relay
Andrew RogersFounder & Engineer

Before writing a line of Hermes, I spent years in manufacturing and construction trades, then moved into systems engineering — building self-directed expertise in HIPAA, DSCSA, 21 CFR Part 11, ALCOA+, and GAMP 5 through hands-on pharmaceutical supply chain compliance work, not a classroom.

That order — regulatory depth before the code — is why Hermes is built the way it is. The CFR citations attached to every scrubbing decision aren't decorative. They come from actually having sat with the standard long enough to know which subsection applies to which identifier, in the same way a compliance officer would.

Hermes is built and operated by one person. When you request a pilot, the person who architected the attestation chain is the person on the call.

Vendor-agnostic architecture

Hermes is not a replacement
for your stack. It is the layer
your stack cannot provide.

No DLP platform -- Purview, Netskope, Nightfall -- can produce a zero-egress, deterministic, CFR-cited audit record on its own. Hermes fills that gap and exports the evidence as a generic JSON webhook, ready for anything that accepts one today, with platform-specific connectors as ongoing work.

Generic Webhook Export

Any HTTP JSON webhook receiver

Every scrubbing decision fires a structured JSON event to a URL you configure, with an optional auth header for token-based intake. This is a real, tested capability today -- not a mockup.

-> POST + configurable auth header
Splunk (HTTP Event Collector)

Splunk Cloud - Splunk Enterprise

Point the webhook at your HEC endpoint and set the auth header to your HEC token. Every scrub call lands as a structured event -- CFR citation, field type, hash chain ID, timestamp -- with no custom parser required.

-> HEC-compatible JSON POST
SIEM / DLP -- Broader Landscape

Datadog - CrowdStrike - Azure Sentinel - Purview - Netskope - Zscaler

Platforms that accept a generic webhook or HTTP intake can consume Hermes' event stream today. Platforms requiring signed requests -- Sentinel's Data Collector API, for example -- are not yet supported; that is roadmap work, not a shipped connector.

-> Compatible where webhook intake exists
AI Pipelines

OpenAI - Azure OpenAI - Anthropic - Any LLM endpoint

Call /v1/scrub before your LLM request in your own pipeline code. Core identifiers are scrubbed and the audit record is sealed before payload content reaches the model. Today this is a direct API call you wire in, not an automatic transparent proxy.

-> Direct API call, ahead of your LLM request
How it works

One generic JSON event exporter. Any destination.

Hermes emits a structured event for every scrubbing decision: field type, CFR citation, hash chain ID, payload ID, and timestamp. That event is platform-agnostic JSON over a configurable webhook, with an optional auth header for token-based intake like Splunk's HTTP Event Collector. Platforms requiring signed requests are on the roadmap, not yet shipped.

The enforcement context

The documentation gap has a
dollar figure attached to it.

7

OCR resolution agreements against business associates in 2025 alone

HHS Office for Civil Rights — 2025 Enforcement Report

$7.42M

Average cost of a healthcare data breach — the costliest industry for the 15th consecutive year

IBM Cost of a Data Breach Report 2025

18

Safe Harbor identifier categories OCR expects documented per incident

45 CFR §164.514(b)(2) — HIPAA Safe Harbor Standard

Pricing

No enterprise contract.
No security team required.

Hermes is built for the MSP managing 15 HIPAA-covered clients and the 10-person billing company — not the Fortune 500 with a six-month procurement cycle.

PILOT

$2,00030 days

Full production deployment in your environment. No shared infrastructure.

  • Zero-egress deployment in your environment
  • Hash-chained audit trail from day one
  • SSN, PAN, name, date, phone detection
  • API key + integration support
  • Direct access to the engineer who built it

PRODUCTION

$500/ month

After pilot. Month-to-month. No enterprise contract required.

  • Everything in Pilot, ongoing
  • Expanding identifier coverage
  • CFR citation updates as regulations change
  • Priority support via direct channel

Starts after pilot

Pilot pricing is fixed for current design partners. Production pricing locks at pilot rate for the first 12 months.

Business Associate Agreement (BAA) available upon request. Required for HIPAA-covered deployments.

Know your exposure before your insurer asks

PHI AI Readiness Assessment

A written gap analysis of your current AI tooling against the 45 CFR §164.514(b) Safe Harbor standard — with remediation priorities and an attestation readiness score your insurer or auditor can read. Delivered in five business days. The $750 fee applies in full toward the pilot if you proceed.

  • Gap analysis against 45 CFR §164.514(b) Safe Harbor — all 18 identifier categories
  • Remediation priorities ranked by enforcement exposure, not theoretical risk
  • Attestation readiness score formatted for cyber insurers and OCR auditors
  • Written report delivered within five business days of intake
  • $750 fee credited in full toward the pilot program if you proceed

The process: you complete a 15-minute intake questionnaire covering your current AI tooling, PHI workflows, and existing controls. Andrew reviews it against the Safe Harbor standard and delivers a written report. No calls required unless you want one.

$750flat fee
5-day turnaround · credited toward pilot

One pilot.
Your environment.
Your audit chain.

Hermes is currently accepting design partners for remote pilots. 30-day engagement, your infrastructure, full hash-chained audit evidence record from day one.

Zero-egress architecture · Data never leaves your environment · SHA-256 independently verifiable · Safe Harbor-aligned — building toward 45 CFR §164.514(b) · BAA available upon request