Skip to main content

Built-in Patterns

Access Analyzer ships 139 built-in sensitive data patterns organized into 11 built-in groups. Both the patterns and the groups carry a Built-in badge on the Sensitive Data Patterns page. Of the 139 patterns, 79 are High confidence, 48 are Medium, and 12 are Low.

Built-in patterns are read-only. You can't edit or delete them, and you can't add a built-in pattern to a group or remove it from one. On the Sensitive Data Patterns page, the Regex / Description column shows what each built-in pattern detects rather than its regular expression. You can add your own custom patterns to any built-in group.

Built-in Groups

GroupPatternsDescription
CCPA4California Consumer Privacy Act personal information.
CMMC27Cybersecurity Maturity Model Certification controlled data and credentials.
GDPR44EU General Data Protection Regulation personal data.
GDPR Restricted29GDPR special-category (Article 9) data requiring heightened protection.
GLBA12Gramm-Leach-Bliley Act non-public personal financial information.
HIPAA5Health Insurance Portability and Accountability Act protected health information.
PCI DSS3Payment Card Industry Data Security Standard cardholder data.
Credentials25Cloud keys, API tokens, private keys, passwords, and other secrets.
Financial Records38Bank account, routing, and tax identifiers.
PHI5Protected health information: medical codes, terms, and treatment records.
PII34Personally identifiable information: names, IDs, contact details, and dates.

Many patterns belong to more than one group: 85 of the 139 do. US SSN (US Social Security number), for example, is in GLBA, HIPAA, and PII. Every pattern in Credentials is also in CMMC. A scan selects groups rather than individual patterns, so Access Analyzer reports a pattern's matches whenever you pick any group it belongs to. Pattern groups explains how that selection works.

Patterns by Group

Expand a group to see its patterns in alphabetical order, each with its confidence level and the text from the Regex / Description column.

CCPA

CCPA holds four consumer-identity patterns: a driver's license number, an email address, a phone number, and a US street address. All four also belong to PII.

CCPA patterns (4)
PatternConfidenceDescription
Driver's licenseMediumDriver's license numbers, identified by a nearby driver's-license or DL-number label.
Email addressMediumEmail addresses in standard local-part@domain format.
Phone numberLowTelephone numbers in US, UK, and general international dialing formats.
US addressHighUS street addresses, matched by house number, street name, and a standard street-type suffix (St, Ave, Blvd, Rd, and similar).

CMMC

CMMC contains every Credentials pattern plus two for International Traffic in Arms Regulations (ITAR) export-control terms and restricted-party names.

CMMC patterns (27)
PatternConfidenceDescription
Amazon MWS Auth TokenHighAmazon Marketplace Web Service (MWS) authorization tokens, identified by their fixed amzn.mws. prefix.
AWS Access Key IDHighAWS access key IDs embedded in code, configuration files, or connection strings, identified by AWS's fixed access-key-ID prefix.
AWS Account IDLowAWS account ID numbers, identified by a nearby aws_account_id-style label.
AWS Secret Access KeyMediumAWS secret access keys — a bare 40-character base64-style secret — identified by a nearby aws_secret_access_key label.
AWS Session TokenMediumAWS temporary session tokens, identified by a nearby aws_session_token-style label.
Azure Cosmos DB (DocumentDB) Auth KeyHighAzure Cosmos DB (DocumentDB) authorization keys, identified by a nearby DocumentDb label and their fixed base64 length.
Azure SAS TokenHighAzure Shared Access Signature (SAS) tokens, identified by their versioned sv=20YY-MM-DD query-string prefix.
Azure Storage Account KeyHighAzure Storage account keys embedded in code or connection strings, identified by their fixed base64 length.
CredentialsHighA broad set of application secrets and credentials — labeled API keys and tokens, JWTs, and vendor-specific tokens for GitHub, npm, SendGrid, Stripe, and Twilio — identified by their distinctive fixed-format prefixes or by a nearby secret/token label.
Credentials Embedded in URIMediumUsernames and passwords embedded directly in a URI, such as an FTP or database connection URL, identified by the scheme://user:pass@host structure.
Database Connection StringHighDatabase connection strings with an embedded password, identified by their Server=...;Password=... key-value format.
Generic Private KeyHighPrivate key material in PEM format, identified by the standard '-----BEGIN ... PRIVATE KEY-----' header.
Google Cloud API KeyHighGoogle Cloud API keys, identified by their fixed 'AIza' prefix.
Google Cloud OAuth Access TokenMediumGoogle Cloud OAuth access tokens, identified by their fixed 'ya29.' prefix.
Google Cloud Service Account KeyHighGoogle Cloud service-account key files, identified by the JSON private_key_id field they contain.
ITAR Controlled Munitions List TermsLowTerms from the ITAR Controlled Munitions List nomenclature, identified alongside nearby export-control context.
ITAR Restricted Party / Denied Persons MatchLowNames appearing on ITAR restricted-party/denied-persons lists, identified alongside nearby export-control context.
Kerberos Ticket File (krbtgt .kirbi)HighExported Kerberos golden/silver ticket files, identified by the krbtgt filename fragment and .kirbi extension.
PasswordMediumPasswords appearing in configuration files, connection strings, and markup, identified by a nearby password label.
PEM certificate blockHighX.509 certificates in PEM format, identified by the standard '-----BEGIN CERTIFICATE-----' header.
PEM public key blockHighPublic key material in PEM format, identified by the standard '-----BEGIN ... PUBLIC KEY-----' header.
PGP Key BlockHighPGP public and private key blocks, identified by their standard '-----BEGIN PGP ... KEY BLOCK-----' delimiters.
PKCS#7/P7B Certificate BlockHighPKCS#7/P7B certificate blocks, identified by the standard '-----BEGIN PKCS7-----' header.
Slack TokenHighSlack API tokens, identified by Slack's fixed token prefix.
Slack Webhook URLHighSlack incoming-webhook URLs, identified by their fixed hooks.slack.com format.
SSH Authorized KeysHighSSH public keys as they appear in authorized_keys files and key listings, identified by their key-type prefix and encoded key body.
UNIX /etc/passwd file exposureMediumExposed UNIX /etc/passwd-style colon-delimited user records.

GDPR

GDPR is the largest group, with 44 patterns. Most are national identifiers, social security and tax numbers, and passports for EU and other European countries. The rest are European street addresses, UK postcodes, email addresses, IP addresses, and dates of birth.

GDPR patterns (44)
PatternConfidenceDescription
Austrian National IDMediumAustrian national population-register identifiers (sourcePIN/ZMR), identified by a nearby sourcePIN, ZMR, or ccr-ID label.
Austrian Social Security Number (SSN)MediumAustrian social security numbers, identified by a nearby ASVG or Sozialversicherungsgesetz label.
Belgian National ID (BSN)HighBelgian national register numbers in dash-grouped form, identified by a nearby BEID/EID label and validated against the Belgian national register mod-97 checksum.
Belgian National Register Number (Rijksregisternummer)MediumBelgian national register numbers (Rijksregisternummer) in dot-grouped, birth-date-anchored form, identified by a nearby SIS or Rijksregisternummer label.
Bulgarian EGNMediumBulgarian EGN (uniform civil number) identifiers, identified by a nearby EGN label.
Czech Birth Number (Rodné číslo)MediumCzech birth numbers (Rodné číslo), identified by a nearby Rodné číslo or RČ label.
Czech National ID (Občanský průkaz)MediumCzech national identity card numbers (Občanský průkaz), identified by a nearby ČOP or identification-card label.
Czech Passport NumberLowCzech passport numbers, identified by a nearby passport or Cestovní pas label.
Danish National ID (CPR number)MediumDanish CPR (personal identification) numbers, identified by a nearby CPR or personnummer label.
Date of birthMediumDates of birth, identified by a nearby date-of-birth, DOB, or 'born on' label.
Dutch BSN (Burgerservicenummer)LowDutch citizen service numbers (BSN), identified by a nearby BSN/Burgerservicenummer/sofinummer label; the format carries no checksum here, so this stays a lower-confidence signal.
Email addressMediumEmail addresses in standard local-part@domain format.
Estonian National IDMediumEstonian personal identification codes (isikukood), identified by a nearby IK or Isikukood label.
EU addressHighEuropean street addresses in German- and French-style formats (e.g. a Straße/allee/platz name or a rue/avenue/boulevard name), matched by street name and house number.
Finnish Personal Identity Code (HETU)MediumFinnish personal identity codes (HETU), identified by a nearby HETU or henkilötunnus label.
French National ID Card (CNI)LowFrench national identity card (CNI) numbers, identified by a nearby carte d'identité or identification-nationale label.
French NIRHighFrench social security (INSEE/NIR) numbers, identified by a nearby 'numéro de sécurité sociale' or INSEE label and validated against the NIR check-digit algorithm.
French tax identification number (SPI/SID)MediumFrench tax identification numbers (SPI/SID), identified by a nearby SID or numéro d'identification fiscale label.
German national ID card number (Personalausweis)MediumGerman national identity card numbers (Personalausweis), identified by a nearby Personalausweis or Ausweis label.
German passport numberMediumGerman passport numbers, identified by a nearby Reisepass or Ausweisnummer label.
German SSNMediumGerman social security numbers, identified by a nearby Sozialversicherungsnummer, VSNR, or RVNR label.
German tax IDHighGerman tax identification numbers (Steuer-ID), identified by a nearby Steueridentifikationsnummer or tax-ID label and validated against the German tax-ID check-digit algorithm.
Greek National IDMediumGreek national identity card numbers, identified by a nearby tautotita label.
Hungarian National IDMediumHungarian national identity card numbers, identified by a nearby személyigazolvány szám label.
Hungarian Personal IDMediumHungarian personal identification numbers, identified by a nearby Szám/Személyi szám label, distinct from the Hungarian national ID card and TAJ social-insurance number.
Hungarian TAJ (Social Insurance) NumberMediumHungarian TAJ social insurance numbers, identified by a nearby TAJ or társadalombiztosítási szám label.
IPv4 AddressLowIPv4 addresses in standard dotted-decimal notation.
IPv6 AddressMediumIPv6 addresses in full 8-group hexadecimal-colon notation.
Irish PPS NumberMediumIrish Personal Public Service (PPS) numbers, identified by a nearby PPS label.
Italian Codice FiscaleHighItalian Codice Fiscale (tax code) numbers, identified by a nearby codice fiscale or Italian fiscal-code label and validated against the Codice Fiscale check-character algorithm.
Latvian Personal Code (Personas kods)MediumLatvian personal codes (Personas kods), identified by a nearby PK/Personas kods label.
Lithuanian Personal Code (Asmens kodas)MediumLithuanian personal codes (Asmens kodas), identified by a nearby AK/Asmens kodas label.
Norwegian National ID (Fødselsnummer)MediumNorwegian national identity numbers (Fødselsnummer), identified by a nearby fødselsnummer/fn label.
Polish NIP (Tax ID)HighPolish NIP tax identification numbers, identified by a nearby NIP label and validated against the NIP weighted mod-11 checksum.
Polish PESEL (National ID)HighPolish PESEL national identification numbers, identified by a nearby PESEL label and validated against the PESEL weighted mod-10 checksum.
Romanian CNP (Personal Numeric Code)HighRomanian personal numeric codes (CNP), identified by a nearby CNP/Cod Numeric Personal label and validated against the CNP weighted mod-11 checksum.
Slovak Passport NumberMediumSlovak passport numbers, identified by a nearby passport or Cestovný pas label.
Spain PassportMediumSpanish passport numbers, identified by a nearby Pasaporte label.
Spain Social Security Number (NUSS)MediumSpanish social security numbers (NUSS), identified by a nearby número de seguridad social label.
Spanish DNI/NIEHighSpanish national identity numbers (DNI/NIE), identified by a nearby DNI/NIE label and validated against the Spanish ID check-letter algorithm.
Swedish Personal ID Number (Personnummer)MediumSwedish personal identity numbers (Personnummer), identified by a nearby Personnr/personnummer label.
UK NHS NumberHighUK NHS numbers, identified by a nearby NHS label and validated against the NHS number's modulus-11 check digit.
UK NINOHighUK National Insurance numbers, validated against National Insurance number prefix and format rules.
UK postcodeHighUK postal codes, identified either by a nearby postcode or address label, or on their own when they match standard UK postcode formatting rules.

GDPR Restricted

GDPR Restricted is the subset of GDPR that covers national identity, social security, and tax identifiers.

GDPR Restricted patterns (29)
PatternConfidenceDescription
Austrian National IDMediumAustrian national population-register identifiers (sourcePIN/ZMR), identified by a nearby sourcePIN, ZMR, or ccr-ID label.
Austrian Social Security Number (SSN)MediumAustrian social security numbers, identified by a nearby ASVG or Sozialversicherungsgesetz label.
Belgian National ID (BSN)HighBelgian national register numbers in dash-grouped form, identified by a nearby BEID/EID label and validated against the Belgian national register mod-97 checksum.
Belgian National Register Number (Rijksregisternummer)MediumBelgian national register numbers (Rijksregisternummer) in dot-grouped, birth-date-anchored form, identified by a nearby SIS or Rijksregisternummer label.
Bulgarian EGNMediumBulgarian EGN (uniform civil number) identifiers, identified by a nearby EGN label.
Czech Birth Number (Rodné číslo)MediumCzech birth numbers (Rodné číslo), identified by a nearby Rodné číslo or RČ label.
Danish National ID (CPR number)MediumDanish CPR (personal identification) numbers, identified by a nearby CPR or personnummer label.
Dutch BSN (Burgerservicenummer)LowDutch citizen service numbers (BSN), identified by a nearby BSN/Burgerservicenummer/sofinummer label; the format carries no checksum here, so this stays a lower-confidence signal.
Estonian National IDMediumEstonian personal identification codes (isikukood), identified by a nearby IK or Isikukood label.
Finnish Personal Identity Code (HETU)MediumFinnish personal identity codes (HETU), identified by a nearby HETU or henkilötunnus label.
French National ID Card (CNI)LowFrench national identity card (CNI) numbers, identified by a nearby carte d'identité or identification-nationale label.
French NIRHighFrench social security (INSEE/NIR) numbers, identified by a nearby 'numéro de sécurité sociale' or INSEE label and validated against the NIR check-digit algorithm.
French tax identification number (SPI/SID)MediumFrench tax identification numbers (SPI/SID), identified by a nearby SID or numéro d'identification fiscale label.
German SSNMediumGerman social security numbers, identified by a nearby Sozialversicherungsnummer, VSNR, or RVNR label.
German tax IDHighGerman tax identification numbers (Steuer-ID), identified by a nearby Steueridentifikationsnummer or tax-ID label and validated against the German tax-ID check-digit algorithm.
Greek National IDMediumGreek national identity card numbers, identified by a nearby tautotita label.
Hungarian Personal IDMediumHungarian personal identification numbers, identified by a nearby Szám/Személyi szám label, distinct from the Hungarian national ID card and TAJ social-insurance number.
Hungarian TAJ (Social Insurance) NumberMediumHungarian TAJ social insurance numbers, identified by a nearby TAJ or társadalombiztosítási szám label.
Irish PPS NumberMediumIrish Personal Public Service (PPS) numbers, identified by a nearby PPS label.
Italian Codice FiscaleHighItalian Codice Fiscale (tax code) numbers, identified by a nearby codice fiscale or Italian fiscal-code label and validated against the Codice Fiscale check-character algorithm.
Latvian Personal Code (Personas kods)MediumLatvian personal codes (Personas kods), identified by a nearby PK/Personas kods label.
Lithuanian Personal Code (Asmens kodas)MediumLithuanian personal codes (Asmens kodas), identified by a nearby AK/Asmens kodas label.
Norwegian National ID (Fødselsnummer)MediumNorwegian national identity numbers (Fødselsnummer), identified by a nearby fødselsnummer/fn label.
Polish NIP (Tax ID)HighPolish NIP tax identification numbers, identified by a nearby NIP label and validated against the NIP weighted mod-11 checksum.
Polish PESEL (National ID)HighPolish PESEL national identification numbers, identified by a nearby PESEL label and validated against the PESEL weighted mod-10 checksum.
Romanian CNP (Personal Numeric Code)HighRomanian personal numeric codes (CNP), identified by a nearby CNP/Cod Numeric Personal label and validated against the CNP weighted mod-11 checksum.
Spain Social Security Number (NUSS)MediumSpanish social security numbers (NUSS), identified by a nearby número de seguridad social label.
Spanish DNI/NIEHighSpanish national identity numbers (DNI/NIE), identified by a nearby DNI/NIE label and validated against the Spanish ID check-letter algorithm.
Swedish Personal ID Number (Personnummer)MediumSwedish personal identity numbers (Personnummer), identified by a nearby Personnr/personnummer label.

GLBA

GLBA groups payment card, bank, securities, and tax identifiers with financial-statement terms and the US Social Security number. It includes all three PCI DSS patterns.

GLBA patterns (12)
PatternConfidenceDescription
ABA routing numberHighUS bank routing numbers, validated against the ABA routing-number checksum.
Credit Card Magnetic Stripe Track 1HighRaw ISO/IEC 7813 Track 1 magnetic-stripe dumps, matched by the %B sentinel and cardholder/expiry field structure.
Credit Card Magnetic Stripe Track 2MediumRaw ISO/IEC 7813 Track 2 magnetic-stripe dumps, matched by the leading ';' sentinel and expiry-date field structure.
Credit Card NumberHighPayment card numbers for major brands, validated with the Luhn checksum.
CUSIP NumberHighUS/Canada CUSIP securities identifiers, validated against the ANSI X9.6 modulus-10 check-digit algorithm.
Employer Identification Number (EIN)MediumUS Employer Identification Numbers (EIN), identified by a nearby EIN or employer-identification label.
Financial Document IndicatorsLowFinancial-statement terms (EBITDA, operating margin, net income, and similar) appearing together with a currency amount.
French VAT numberMediumFrench VAT identification numbers, identified by a nearby TVA/VAT label.
German VATMediumGerman VAT identification numbers, identified by a nearby Mehrwertsteuer/USt-Id/VAT label.
Spain VAT/CIF NumberMediumSpanish VAT/CIF numbers, identified by a nearby IVA/VAT label and the mandatory ES country-code prefix.
US bank account numberLowBank account numbers, matched as a 7- to 14-digit sequence with no additional validation.
US SSNHighUS Social Security numbers in formatted or unformatted form, validated against Social Security Administration allocation rules.

HIPAA

HIPAA pairs medical billing codes and provider identifiers with the Medicare Beneficiary Identifier and the US Social Security number.

HIPAA patterns (5)
PatternConfidenceDescription
HCPCS CodesMediumHealthcare Common Procedure Coding System (HCPCS) billing codes, matched against the closed list of known codes.
Medical codeHighMedical billing and diagnostic codes — ICD-10 diagnosis codes, CPT procedure codes, and NDC drug codes — identified by a nearby diagnosis, procedure, or drug-code label.
Medicare Beneficiary Identifier (MBI)LowUS Medicare Beneficiary Identifiers (MBI), identified by a nearby Medicare-beneficiary or MBI label; the format carries no public checksum, so this stays a lower-confidence signal.
Personal IdentifierHighNational Provider Identifier (NPI) and DEA registration numbers for healthcare providers, identified by a nearby NPI or DEA label.
US SSNHighUS Social Security numbers in formatted or unformatted form, validated against Social Security Administration allocation rules.

PCI DSS

PCI DSS covers payment card numbers and raw magnetic-stripe data. All three patterns also belong to GLBA.

PCI DSS patterns (3)
PatternConfidenceDescription
Credit Card Magnetic Stripe Track 1HighRaw ISO/IEC 7813 Track 1 magnetic-stripe dumps, matched by the %B sentinel and cardholder/expiry field structure.
Credit Card Magnetic Stripe Track 2MediumRaw ISO/IEC 7813 Track 2 magnetic-stripe dumps, matched by the leading ';' sentinel and expiry-date field structure.
Credit Card NumberHighPayment card numbers for major brands, validated with the Luhn checksum.

Credentials

The Credentials group targets cloud provider keys and tokens, private keys and certificates, passwords, connection strings, and chat-platform tokens. Every pattern here is also in CMMC.

Credentials patterns (25)
PatternConfidenceDescription
Amazon MWS Auth TokenHighAmazon Marketplace Web Service (MWS) authorization tokens, identified by their fixed amzn.mws. prefix.
AWS Access Key IDHighAWS access key IDs embedded in code, configuration files, or connection strings, identified by AWS's fixed access-key-ID prefix.
AWS Account IDLowAWS account ID numbers, identified by a nearby aws_account_id-style label.
AWS Secret Access KeyMediumAWS secret access keys — a bare 40-character base64-style secret — identified by a nearby aws_secret_access_key label.
AWS Session TokenMediumAWS temporary session tokens, identified by a nearby aws_session_token-style label.
Azure Cosmos DB (DocumentDB) Auth KeyHighAzure Cosmos DB (DocumentDB) authorization keys, identified by a nearby DocumentDb label and their fixed base64 length.
Azure SAS TokenHighAzure Shared Access Signature (SAS) tokens, identified by their versioned sv=20YY-MM-DD query-string prefix.
Azure Storage Account KeyHighAzure Storage account keys embedded in code or connection strings, identified by their fixed base64 length.
CredentialsHighA broad set of application secrets and credentials — labeled API keys and tokens, JWTs, and vendor-specific tokens for GitHub, npm, SendGrid, Stripe, and Twilio — identified by their distinctive fixed-format prefixes or by a nearby secret/token label.
Credentials Embedded in URIMediumUsernames and passwords embedded directly in a URI, such as an FTP or database connection URL, identified by the scheme://user:pass@host structure.
Database Connection StringHighDatabase connection strings with an embedded password, identified by their Server=...;Password=... key-value format.
Generic Private KeyHighPrivate key material in PEM format, identified by the standard '-----BEGIN ... PRIVATE KEY-----' header.
Google Cloud API KeyHighGoogle Cloud API keys, identified by their fixed 'AIza' prefix.
Google Cloud OAuth Access TokenMediumGoogle Cloud OAuth access tokens, identified by their fixed 'ya29.' prefix.
Google Cloud Service Account KeyHighGoogle Cloud service-account key files, identified by the JSON private_key_id field they contain.
Kerberos Ticket File (krbtgt .kirbi)HighExported Kerberos golden/silver ticket files, identified by the krbtgt filename fragment and .kirbi extension.
PasswordMediumPasswords appearing in configuration files, connection strings, and markup, identified by a nearby password label.
PEM certificate blockHighX.509 certificates in PEM format, identified by the standard '-----BEGIN CERTIFICATE-----' header.
PEM public key blockHighPublic key material in PEM format, identified by the standard '-----BEGIN ... PUBLIC KEY-----' header.
PGP Key BlockHighPGP public and private key blocks, identified by their standard '-----BEGIN PGP ... KEY BLOCK-----' delimiters.
PKCS#7/P7B Certificate BlockHighPKCS#7/P7B certificate blocks, identified by the standard '-----BEGIN PKCS7-----' header.
Slack TokenHighSlack API tokens, identified by Slack's fixed token prefix.
Slack Webhook URLHighSlack incoming-webhook URLs, identified by their fixed hooks.slack.com format.
SSH Authorized KeysHighSSH public keys as they appear in authorized_keys files and key listings, identified by their key-type prefix and encoded key body.
UNIX /etc/passwd file exposureMediumExposed UNIX /etc/passwd-style colon-delimited user records.

Financial Records

Financial Records centers on International Bank Account Numbers (IBANs): one generic IBAN pattern and one for each of 28 European countries. The other nine patterns are routing and bank account numbers, SWIFT/BIC bank identifier codes, securities identifiers, value-added tax (VAT) and employer identification numbers, and financial-statement terms.

Financial Records patterns (38)
PatternConfidenceDescription
ABA routing numberHighUS bank routing numbers, validated against the ABA routing-number checksum.
Austrian IBANHighAustrian IBANs, validated against the IBAN ISO 7064 check-digit algorithm.
Belgian IBANHighBelgian IBANs, validated against the IBAN ISO 7064 check-digit algorithm.
Bulgarian IBANHighBulgarian IBANs, validated against the IBAN ISO 7064 check-digit algorithm.
Croatian IBANHighCroatian IBANs, validated against the IBAN ISO 7064 check-digit algorithm.
CUSIP NumberHighUS/Canada CUSIP securities identifiers, validated against the ANSI X9.6 modulus-10 check-digit algorithm.
Cypriot IBANHighCypriot IBANs, validated against the IBAN ISO 7064 check-digit algorithm.
Czech IBANHighCzech IBANs, validated against the IBAN ISO 7064 check-digit algorithm.
Danish IBANHighDanish IBANs, validated against the IBAN ISO 7064 check-digit algorithm.
Employer Identification Number (EIN)MediumUS Employer Identification Numbers (EIN), identified by a nearby EIN or employer-identification label.
Estonian IBANHighEstonian IBANs, validated against the IBAN ISO 7064 check-digit algorithm.
Financial Document IndicatorsLowFinancial-statement terms (EBITDA, operating margin, net income, and similar) appearing together with a currency amount.
Finnish IBANHighFinnish IBANs, validated against the IBAN ISO 7064 check-digit algorithm.
French IBANHighFrench IBANs, validated against the IBAN ISO 7064 check-digit algorithm.
French VAT numberMediumFrench VAT identification numbers, identified by a nearby TVA/VAT label.
German IBANHighGerman IBANs, validated against the IBAN ISO 7064 check-digit algorithm.
German VATMediumGerman VAT identification numbers, identified by a nearby Mehrwertsteuer/USt-Id/VAT label.
Greek IBANHighGreek IBANs, validated against the IBAN ISO 7064 check-digit algorithm.
Hungarian IBANHighHungarian IBANs, validated against the IBAN ISO 7064 check-digit algorithm.
IBANHighInternational Bank Account Numbers, validated against the IBAN ISO 7064 check-digit algorithm.
Irish IBANHighIrish IBANs, validated against the IBAN ISO 7064 check-digit algorithm.
Italian IBANHighItalian IBANs, validated against the IBAN ISO 7064 check-digit algorithm.
Latvian IBANHighLatvian IBANs, validated against the IBAN ISO 7064 check-digit algorithm.
Lithuanian IBANHighLithuanian IBANs, validated against the IBAN ISO 7064 check-digit algorithm.
Luxembourgian IBANHighLuxembourgish IBANs, validated against the IBAN ISO 7064 check-digit algorithm.
Maltan IBANHighMaltese IBANs, validated against the IBAN ISO 7064 check-digit algorithm.
Netherland IBANHighDutch IBANs, validated against the IBAN ISO 7064 check-digit algorithm.
Polish IBANHighPolish IBANs, validated against the IBAN ISO 7064 check-digit algorithm.
Portuguese IBANHighPortuguese IBANs, validated against the IBAN ISO 7064 check-digit algorithm.
Romanian IBANHighRomanian IBANs, validated against the IBAN ISO 7064 check-digit algorithm.
Slovak IBANHighSlovak IBANs, validated against the IBAN ISO 7064 check-digit algorithm.
Slovenian IBANHighSlovenian IBANs, validated against the IBAN ISO 7064 check-digit algorithm.
Spain IBANHighSpanish IBANs, validated against the IBAN ISO 7064 check-digit algorithm.
Spain VAT/CIF NumberMediumSpanish VAT/CIF numbers, identified by a nearby IVA/VAT label and the mandatory ES country-code prefix.
Swedish IBANHighSwedish IBANs, validated against the IBAN ISO 7064 check-digit algorithm.
SWIFT/BIC CodeHighSWIFT/BIC bank identifier codes, identified by a nearby SWIFT or BIC label and validated against BIC format rules.
UK IBANHighUK IBANs, validated against the IBAN ISO 7064 check-digit algorithm.
US bank account numberLowBank account numbers, matched as a 7- to 14-digit sequence with no additional validation.

PHI

PHI combines medical codes and provider identifiers with two patterns that detect clinical vocabulary and chart-style documentation phrasing.

PHI patterns (5)
PatternConfidenceDescription
HCPCS CodesMediumHealthcare Common Procedure Coding System (HCPCS) billing codes, matched against the closed list of known codes.
Medical codeHighMedical billing and diagnostic codes — ICD-10 diagnosis codes, CPT procedure codes, and NDC drug codes — identified by a nearby diagnosis, procedure, or drug-code label.
Medical licenseHighNational Provider Identifier (NPI) and DEA registration numbers for healthcare providers, identified by a nearby NPI or DEA label.
Medical TermsMediumClinical vocabulary drawn from a curated medical dictionary — disease and condition names, prescription drug names, diagnostic procedures, and lab tests — counted toward a health-information determination when it appears alongside clinical-context phrasing and a patient or provider identifier.
Medical treatmentMediumClinical documentation phrasing — chart-section markers such as chief complaint, discharge summary, history of present illness, and assessment and plan — counted toward a health-information determination when combined with medical-term density, or on their own when several such markers appear together in a chart-style document.

PII

PII spans personal identifiers from countries around the world, contact details, addresses, network identifiers, dates of birth, salary data, and privileged legal documents.

PII patterns (34)
PatternConfidenceDescription
Australian Medicare Number (AMN)MediumAustralian Medicare card numbers, identified by a nearby AMN or Medicare label.
Australian TFNHighAustralian Tax File Numbers, validated against the Australian Taxation Office's TFN check-digit algorithm.
Brazilian CPFHighBrazilian CPF (individual taxpayer registry) numbers, identified by a nearby CPF or Brazilian tax-ID label and validated against the CPF check-digit algorithm.
Canadian addressHighCanadian street addresses, matched by house number, street name, and a standard street-type suffix (St, Ave, Blvd, Rd, and similar).
Canadian SINHighCanadian Social Insurance Numbers, validated against the SIN Luhn-style checksum.
Chinese Resident IDHighChinese Resident Identity Card numbers, identified by a nearby resident-ID or Chinese national-ID label and validated against the Resident ID check-digit algorithm.
Czech National ID (Občanský průkaz)MediumCzech national identity card numbers (Občanský průkaz), identified by a nearby ČOP or identification-card label.
Czech Passport NumberLowCzech passport numbers, identified by a nearby passport or Cestovní pas label.
Date of birthMediumDates of birth, identified by a nearby date-of-birth, DOB, or 'born on' label.
Driver's licenseMediumDriver's license numbers, identified by a nearby driver's-license or DL-number label.
Email addressMediumEmail addresses in standard local-part@domain format.
German national ID card number (Personalausweis)MediumGerman national identity card numbers (Personalausweis), identified by a nearby Personalausweis or Ausweis label.
German passport numberMediumGerman passport numbers, identified by a nearby Reisepass or Ausweisnummer label.
Hungarian National IDMediumHungarian national identity card numbers, identified by a nearby személyigazolvány szám label.
Indian AadhaarHighIndian Aadhaar (unique identification) numbers, identified by a nearby Aadhaar or Indian national-ID label and validated against the Aadhaar check-digit algorithm.
Indian PANHighIndian Permanent Account Numbers (PAN), identified by a nearby PAN or income-tax-PAN label and validated against the PAN format rules.
IPv4 AddressLowIPv4 addresses in standard dotted-decimal notation.
IPv6 AddressMediumIPv6 addresses in full 8-group hexadecimal-colon notation.
Japanese My NumberHighJapanese My Number (individual number) identifiers, identified by a nearby My Number or Japanese national-ID label and validated against the My Number check-digit algorithm.
MAC addressMediumNetwork hardware (MAC) addresses in colon- or hyphen-separated hexadecimal form.
Medicare Beneficiary Identifier (MBI)LowUS Medicare Beneficiary Identifiers (MBI), identified by a nearby Medicare-beneficiary or MBI label; the format carries no public checksum, so this stays a lower-confidence signal.
Mexican CURPHighMexican CURP (unique population registry code) numbers, identified by a nearby CURP or Mexican national-ID label and validated against the CURP format rules.
Passport NumberMediumPassport numbers, identified by a nearby passport-number label.
Phone numberLowTelephone numbers in US, UK, and general international dialing formats.
Privileged Legal DocumentLowPrivileged legal filings, identified by their docket-style 'Case ... Document ... Filed' structure.
Salary dataHighSalary, wage, and compensation figures, identified by a nearby salary, pay, or compensation label and checked for a plausible currency amount.
Slovak Passport NumberMediumSlovak passport numbers, identified by a nearby passport or Cestovný pas label.
Spain PassportMediumSpanish passport numbers, identified by a nearby Pasaporte label.
Swiss Social Security Number (AHV/AVS)MediumSwiss AHV/AVS social security numbers, identified either by their fixed 756. country-code prefix or by a nearby AHV-Nr/No AVS label.
UK NHS NumberHighUK NHS numbers, identified by a nearby NHS label and validated against the NHS number's modulus-11 check digit.
UK NINOHighUK National Insurance numbers, validated against National Insurance number prefix and format rules.
US addressHighUS street addresses, matched by house number, street name, and a standard street-type suffix (St, Ave, Blvd, Rd, and similar).
US ITINMediumUS Individual Taxpayer Identification Numbers (ITIN), identified by a nearby ITIN or taxpayer-ID label and validated against IRS ITIN numbering rules (a leading '9' with a qualifying group range).
US SSNHighUS Social Security numbers in formatted or unformatted form, validated against Social Security Administration allocation rules.