← All tools

HIPAA credential exposure check

If a leaked credential can reach systems holding PHI, that's a HIPAA problem. GhostCred scans your code for exposed secrets, and the full report flags the ones that map to HIPAA safeguards.

Check a snippet now

This check runs in your browser, nothing is uploaded. Paste a config file or code snippet and matches appear below as you type.

Patterns checked on this page (20)
  • Private key block
  • AWS access key ID
  • AWS secret access key
  • Stripe secret or restricted key
  • Stripe webhook signing secret
  • Stripe publishable key
  • Anthropic API key
  • OpenAI API key
  • GitHub token (ghp_, gho_, ghu_, ghs_, ghr_)
  • GitHub fine-grained personal access token
  • GitLab personal access token
  • Google API key
  • Google OAuth client secret
  • Slack token
  • Slack incoming webhook URL
  • SendGrid API key
  • npm access token
  • JSON Web Token
  • Connection string with an inline password
  • Hardcoded secret assignment (password, token, api_key, secret...)
Start a HIPAA exposure scanFree first repo scan, no signup.

What the full scan checks

Why it matters

Breaches involving PHI carry steep penalties and mandatory notification. Prevention is dramatically cheaper.

Free first scan. No signup. Results in ~60 seconds.

Start a HIPAA exposure scan