PHI Schema Check, a Custosa Labs project
Find and fix HIPAA gaps in your database schema.
Check your schema, understand the risks, and review suggested fixes inside your AI coding assistant. Works with your Custosa account.
Use it with
Choose your assistant above to get started.
Connect your assistant
Follow the steps for your assistant. Sign in to Custosa when prompted, approve the connection, and return to your assistant. Change assistant ↑
Claude Code — terminal
- Open your terminal and add Custosa:
claude mcp add --transport http --scope user custosa-phi-schema-check https://mcp.custosa.com/mcp - Run this command, then finish signing in and approving the connection in your browser:
claude mcp login custosa-phi-schema-check - Open a new Claude Code session. Enter
/mcpand check that custosa-phi-schema-check is connected.
Already added Custosa? Start with step 2. If your version does not recognize the login command, open Claude Code, enter /mcp, and select custosa-phi-schema-check to sign in.
Claude — desktop and web
- Open Custosa in Claude. The connector name and URL are filled in for you. If the form does not open, go to Customize → Connectors → + → Add custom connector.
- Check that the name is Custosa PHI Schema Check and the server URL matches below. If you opened the form manually, enter these details:
https://mcp.custosa.com/mcp - Follow Claude’s prompts to add and connect Custosa. Sign in to Custosa and approve the connection.
- Return to Claude and enable Custosa in your chat's connectors. For Claude Code in the desktop app, start a new Code session after connecting.
On a Team or Enterprise account, ask your workspace owner to add the connector first, then connect with your own Custosa account. Available options depend on your Claude plan.
Codex — terminal
- Open your terminal and add Custosa:
codex mcp add custosa-phi-schema-check --url https://mcp.custosa.com/mcp - Follow the browser sign-in prompt. If it does not open, or you already added Custosa, run:
Sign in to Custosa and approve the connection.
codex mcp login custosa-phi-schema-check - Start a new Codex session and enter
/mcpto check that Custosa's tools are available.
Codex — desktop app
- Open Settings → MCP servers → Add server.
- Name the server custosa-phi-schema-check, choose Streamable HTTP, and paste this URL:
https://mcp.custosa.com/mcp - Save the server and select Restart. Select Authenticate when prompted, then sign in to Custosa and approve the connection.
- Start a new chat and try the connection check below.
Already connected through Codex CLI on this computer? Check the server list before adding it again.
Check your connection
Send this message in your assistant:
Use Custosa's health tool to check my connection.Your assistant should run the check and report that Custosa is available. If it cannot find the tool, finish signing in using the steps above, then start a new chat or session.
Need help connecting? Contact us with your assistant's name and the error you see.
What would you like to check?
Once connected, copy a prompt into your assistant. Open a schema file in your project or attach it to the chat for a schema check.
Check a schema
Get a score and a ranked list of risks in your existing schema.
Review suggested fixes
Turn findings into proposed changes you can inspect before applying.
Plan a new schema
Describe what you are building and review a schema plan with suggested safeguards.
Share table definitions and column names only. Leave out patient records, real data, passwords, and connection strings.
How it works
Choose your assistant above and sign in when prompted.
At a schema. Metadata only.
Score plus a ranked report.
Review suggested migrations before applying them.
Check the remaining findings.
About PHI Schema Check
PHI Schema Check is a Custosa Labs project for development teams. The core Custosa platform controls data access for AI applications at runtime.
PHI Schema Check is metadata-only and informational: it helps you find and fix HIPAA gaps, but it does not make your database “HIPAA-compliant” or certify it — only HHS OCR can determine HIPAA compliance, and your organization remains responsible for its own compliance program. Review output with qualified counsel before relying on it. Terms · Privacy.