Skip to main content
Get your sensitive information detection running in minutes with Fiddler Guardrails for PII/PHI. This guide walks you through detecting PII, PHI, and custom entities to protect sensitive data across your applications.

What You’ll Build

In this quick start, you’ll implement a sensitive information detection system that:
  • Detects a comprehensive set of personally identifiable information (PII) entity types
  • Identifies protected health information (PHI) entity types for healthcare compliance
  • Configures custom entity detection for organization-specific data
  • Provides real-time detection with sub-second latency
Interactive TutorialFor more advanced examples, including batch processing, performance optimization, and production deployment patterns:Open the Complete Sensitive Information Guardrail Notebook in Google Colab β†’Or download the notebook from GitHub β†’

Prerequisites

  • Fiddler account with access token
  • Python 3.10+ environment
  • Basic understanding of data privacy concepts

Overview

Fiddler’s PII and PHI detection, powered by the Centor Model for PII/PHI, provides enterprise-grade protection against data leakage by automatically detecting sensitive information across multiple categories. These guardrails integrate seamlessly with Fiddler’s AI Observability platform, enabling continuous monitoring and automated compliance reporting.

Key Capabilities

  • PII Detection: a comprehensive set of entity types, including names, addresses, SSN, credit cards, emails, and phone numbers
  • PHI Detection: healthcare-specific entity types for HIPAA compliance
  • Custom Entities: Define organization-specific sensitive data patterns
  • Real-time Processing: Sub-second latency for production applications
1

Set Up Your Environment

Connect to Fiddler and configure the Sensitive Information Guardrail API:
2

Define Helper Functions

Create reusable functions for interacting with the API:
3

Example 1: PII Detection

Detect common personally identifiable information:
Expected Output:
4

Example 2: PHI Detection for Healthcare

Detect protected health information in medical contexts:
Expected Output:
5

Example 4: Custom Entity Detection

Define and detect organization-specific sensitive data:
Expected Output:

API Reference

Endpoint

Request Format

Request Parameters

Response Format

Response Fields

Supported Entity Types

The Centor Model for PII/PHI returns labels as lowercase strings β€” use these exact values when filtering responses.
As of Release 26.14, the Centor Model for PII/PHI uses a curated default of 12 high-precision PII entities. To scan for all 27 supported PII entities, pass entity_categories='PII_ALL' in your request.

PII (Default β€” 12 Entities)

When you pass entity_categories='PII' (or omit the field, since PII is the default), the guardrail scans for these 12 high-precision entities:
  • Personal: person, date of birth
  • Contact: email, phone number, address, postal code
  • Financial: credit card number, iban
  • Government IDs: social security number, driver’s license number
  • Digital: ip address, website

PII_ALL (Full Coverage β€” 27 Entities)

When you pass entity_categories='PII_ALL', the guardrail scans for all 27 supported PII entities. This includes the 12 default entities above plus 15 extended entities that provide maximum coverage at a higher false-positive rate:
  • Contact: email address, mobile phone number, landline phone number, fax number
  • Financial: credit card expiration date, cvv, cvc, bank account number, account number
  • Government IDs: passport number, tax identification number, license plate number, cpf, cnpj
  • Digital: digital signature
Use PII_ALL when your application handles international documents (e.g., passports) or needs the broadest possible detection. The default PII set is optimized for precision β€” it was curated from benchmarking across multiple datasets, and the extended entities were separated because they produced higher false-positive rates.

PHI Entities (7 Entities)

Pass entity_categories='PHI' to scan for protected health information. You can combine categories β€” for example, entity_categories=['PII', 'PHI'].
  • Medical: medication, medical condition
  • Insurance: health insurance number, health insurance id number, national health insurance number
  • Identifiers: birth certificate number, serial number

Code Examples

Next Steps

After completing this quick start:

Summary

You’ve learned how to:
  • βœ… Detect a comprehensive set of PII entity types in text data
  • βœ… Identify PHI for healthcare compliance
  • βœ… Configure custom entities for your organization
  • βœ… Integrate the Fiddler Guardrails for PII/PHI API into your applications.
Fiddler Guardrails for PII/PHI offer enterprise-grade protection for sensitive information with sub-second latency, making them ideal for real-time applications while ensuring compliance with privacy regulations such as GDPR, HIPAA, and CCPA.