← All tools
HIPAA credential exposure check
If a leaked credential can reach systems holding PHI, that's a HIPAA problem. GhostCred scans your code for exposed secrets, and the full report flags the ones that map to HIPAA safeguards.
Check a snippet now
This check runs in your browser, nothing is uploaded. Paste a config file or code snippet and matches appear below as you type.
Patterns checked on this page (20)
- Private key block
- AWS access key ID
- AWS secret access key
- Stripe secret or restricted key
- Stripe webhook signing secret
- Stripe publishable key
- Anthropic API key
- OpenAI API key
- GitHub token (ghp_, gho_, ghu_, ghs_, ghr_)
- GitHub fine-grained personal access token
- GitLab personal access token
- Google API key
- Google OAuth client secret
- Slack token
- Slack incoming webhook URL
- SendGrid API key
- npm access token
- JSON Web Token
- Connection string with an inline password
- Hardcoded secret assignment (password, token, api_key, secret...)
Start a HIPAA exposure scanFree first repo scan, no signup.
What the full scan checks
- ✓Database and storage credentials that can reach PHI
- ✓API keys for systems processing health data
- ✓Secrets violating access-control safeguards
- ✓A mapped report for your compliance file
Why it matters
Breaches involving PHI carry steep penalties and mandatory notification. Prevention is dramatically cheaper.
Free first scan. No signup. Results in ~60 seconds.
Start a HIPAA exposure scan