Which is why I was asking what you meant by "this technique."
If your question is: "Is client-side de-identification sufficient for HIPAA," then sure, assuming you are de-identifying the data elements required by HIPAA to be de-identified. You'd have to be a real big idiot to rely on something like this though.
If your question is: "Does this library, as described in the blog post, de-identify data sufficiently for HIPAA?" then no, it doesn't appear that it does.
What is? This is nowhere close to what HIPAA requires.
A lot of clinical decision support AI tools essentially scrub the PHI data on the frontend.
PHI is a different set of data points from PII amigo.
Same technique is good enough.
Which is why I was asking what you meant by "this technique."
If your question is: "Is client-side de-identification sufficient for HIPAA," then sure, assuming you are de-identifying the data elements required by HIPAA to be de-identified. You'd have to be a real big idiot to rely on something like this though.
If your question is: "Does this library, as described in the blog post, de-identify data sufficiently for HIPAA?" then no, it doesn't appear that it does.
If they're relying primarily on this type of tool to scrub PHI, I can tell you already they are not in compliance.