Clinical notes capture most of what is documented about a patient's care, but they cannot be used for research until protected health information (PHI) is removed. De-identification is often treated as a detection problem. Detection alone is not sufficient: redaction strips clinical content along with identifiers, date blanking destroys the temporal intervals needed for longitudinal analysis, and assigning a fresh random surrogate at each occurrence breaks links between a patient's notes. We present TIDE 2.0, an MIT-licensed engine with two separable stages: an interchangeable recognizer and a keyed anonymizer. Both run on hardware the institution owns. Surrogates are generated cryptographically with no stored linkage table. Dates shift by a per-patient, interval-preserving offset; each value receives the same surrogate across all occurrences under a given key; and a release produced under a new key cannot be linked to earlier releases. We also release TIDE2-Sentry, a recognizer distilled from a large language model. On two gold-annotated corpora from two institutions, the default configuration reached span-level recall of 0.88 in-domain and 0.77 on the second institution's corpus, at precision 0.88 and 0.87. We report recall and precision per category alongside these aggregates. The engine is open source, and the recognizer is available under a gated research-use agreement, so institutions can run, inspect and extend both within their own environments.
Figures & tables
Figure 1: One sentence through the pipeline. The recognizer stage detects and types PHI spans and caches them before any text is altered. A reviewer can therefore inspect the detected spans before the anonymizer runs. The anonymizer stage applies a keyed strategy to each category. Both dates move by the same per-patient offset, so the fourteen-day interval between them is preserved. Fig. 4 shows the component-level architecture.
SHIELD
i2b2 2014
micro
macro
micro
macro
Recognizer
P
R
P
R
P
R
P
R
TIDE2 regex
0.97
0.42
0.52
0.39
0.98
0.39
0.48
0.27
tide1
0.48
0.39
0.41
0.38
–
–
–
–
AIMI v1
0.67
0.72
0.45
0.55
0.73
0.67
0.44
0.49
AIMI v2
0.63
0.70
0.43
0.53
0.70
0.65
0.43
0.47
Table 1: PHI detection performance by recognizer and corpus. Span-level precision (P) and recall (R) are micro-averaged over pooled category counts and macro-averaged over the 9 categories, at an overlap threshold of 0.8. The upper block shows the regular-expression and gazetteer layer alone, TIDE 1.0, the two AIMI recognizers, and the distilled TIDE2-Sentry with and without the regex layer; TIDE2-Sentry +regex is the default configuration. The lower block shows the 6 external open-source PII taggers. TIDE 1.0 was run on SHIELD only (“–”). The AIMI recognizers have no AGE, LOCATION or WEB label, and their macro averages include zeros for these three categories. The AIMI recognizers were also trained on i2b2 2014, so that corpus is not held out for them. No other model was trained on either corpus. Per-category values are in Supplementary Tables S1–S2. The same values with bootstrap confidence intervals are in Supplementary Tables S4–S5.
Figure 2: Per-category recall of all recognizers on each corpus. Each axis is one PHI category, and the radial scale is span-level recall from 0 to 1 at an overlap threshold of 0.8. Top: SHIELD. Bottom: i2b2 2014. Each panel shows the regex layer, the two AIMI recognizers, TIDE2-Sentry and the 6 external open-source taggers. The +regex ablations are omitted. Values are those in Supplementary Tables S1–S2.
Property
Construction
N
Result
Determinism (same key)
keyed HMAC / FF3 / selection
2,000
100.0% identical
Remapping (rotated key)
new key remaps surrogate
2,000
100.0% remapped
Cross-note consistency
same value → same surrogate
1,000
100.0% linked
Interval preservation
per-patient date shift
2,000
100.0% exact day-delta
ID collisions, 8 digits
FF3, no padding
2,000
0.00% (2,000 distinct)
ID collisions, 3–5 digits
FF3, padded, truncated
111,000
34.8%–36.6%
Table 2: Anonymizer verification. A seeded synthetic stress set containing no PHI (2,000 distinct values per keyed category). The first four rows are structural guarantees of the keyed construction, and they check that the implementation realizes them. The remapping row uses 1,000 two-token names and 1,000 eight-digit identifiers. The collision rows measure a property that is not guaranteed a priori: whether distinct real values receive distinct surrogates. The 3–5-digit row tests every value of each length. N is the number of distinct values tested. These are unit-level checks of the implementation on synthetic values, not a re-identification or linkage attack.
SHIELD
Longest notes
Stage
L4 path
CPU-only
L4 path
CPU-only
Transformer
4,063
200
10,104
358
Recognizer
6,127
6,127
27,591
27,591
Anonymizer
4,421
4,421
21,547
21,547
End-to-end
1,573
186
5,506
348
Table 3: Throughput per stage, in content-tokens per second. 1 NVIDIA L4 GPU on a GCP VM with 16 vCPUs and 64 GB of RAM, running TIDE2-Sentry with a 512-token window budget and 40-token overlap. Transformer: the token classifier. Recognizer: the CPU regex and Aho–Corasick stage. Left: the full SHIELD corpus (1,381 notes, 359,779 tokens). Right: a bounded subset of the longest notes (2,096,828 tokens). One run per configuration, so these are indicative rather than a mean. The CPU-only columns are an untuned single-actor configuration; the CPU stages are shared between the two paths.
Figure 3: Deployment and the institutional perimeter at inference. All components that handle identified text run inside the institution. Keys are held per study or tenant. A new key re-maps every surrogate deterministically, so releases under different keys cannot be linked; releases already issued are not changed. The de-identified corpus is the only artefact that crosses the perimeter.
Figure 4: Component architecture. The recognizer slot accepts transformer token classifiers, an LLM recognizer, regular expressions and an Aho–Corasick gazetteer; span resolution passes a RecognizerResult list to the anonymizer, which applies keyed surrogates, format-preserving encryption, hashing and per-patient date jitter under a “same input + same keys = same output” rule. A Ray Data layer supplies GPU and CPU actors, out-of-memory batch splitting and checkpointing over a cryptographic foundation.
Appendix figures & tables15 assets
Supplementary material from the paper’s appendix.
Appendix
Figure S1: Teacher and student per category on SHIELD. Span-level precision (left) and recall (right) for the Gemini 2.5 Flash teacher and the distilled TIDE2-Sentry student. The student trails the teacher on recall in every category, most on WEB, AGE and LOCATION and least on DATE. Table S3 gives the same comparison with confidence intervals and paired p -values.
Model
AGE
DATE
DOCTOR
HOSP
ID
LOC
PATIENT
PHONE
WEB
Recall
TIDE2 regex
0.00
0.92
0.00
0.00
0.56
0.38
0.00
0.80
0.82
AIMI v1
–
0.95
0.46
0.90
0.95
–
0.78
0.92
–
AIMI v1 + regex
0.00
0.95
0.46
0.90
0.95
0.36
0.78
0.94
0.60
AIMI v2
–
0.95
0.42
0.89
0.95
–
0.71
0.81
–
AIMI v2 + regex
0.00
0.96
0.42
0.88
0.95
0.37
0.71
0.86
0.56
Appendix
Table S1: Per-category span-level recall and precision on SHIELD. Point estimates at an overlap threshold of 0.8 for regex, the two AIMI recognizers and TIDE2-Sentry with their +regex ablations, and the 6 external PII taggers. “–” marks a category absent from the AIMI label set (AGE, LOCATION, WEB). The +regex rows isolate the effect of the regex layer. TIDE 1.0 is not shown; its SHIELD aggregates are in main-text Table 1. Every external tagger scores at or near zero on DOCTOR, because their taxonomies carry one generic person type where clinical de-identification needs the patient/provider distinction (pooled NAME results in Table S14).
Model
AGE
DATE
DOCTOR
HOSP
ID
LOC
PATIENT
PHONE
WEB
Recall
TIDE2 regex
0.00
0.75
0.00
0.00
0.44
0.13
0.00
0.38
0.71
AIMI v1
–
0.94
0.25
0.87
0.81
–
0.56
0.94
–
AIMI v1 + regex
0.00
0.95
0.25
0.87
0.81
0.08
0.56
0.93
0.57
AIMI v2
–
0.94
0.23
0.84
0.80
–
0.54
0.88
–
AIMI v2 + regex
0.00
0.95
0.23
0.84
0.80
0.09
0.54
0.88
0.29
Appendix
Table S2: Per-category span-level recall and precision on i2b2 2014. Same models and same conventions as Table S1 , after the label crosswalk of Table S6 . The 6 external PII taggers are included as an off-distribution probe, as on SHIELD.
Gemini 2.5 Flash
TIDE2-Sentry
Category
P [95% CI]
R [95% CI]
P [95% CI]
R [95% CI]
Δ R
p
padj
AGE
0.85 [0.79-0.90]
0.90 [0.87-0.93]
0.71 [0.65-0.77]
0.78 [0.74-0.83]
-0.12
<0.0005
<0.005
DATE
0.99 [0.98-0.99]
0.98 [0.98-0.99]
0.97 [0.96-0.97]
0.94 [0.93-0.95]
-0.04
<0.0005
<0.005
DOCTOR
0.95 [0.94-0.97]
0.96 [0.96-0.97]
0.93 [0.92-0.94]
0.90 [0.88-0.92]
-0.06
<0.0005
<0.005
HOSPITAL
0.67 [0.64-0.71]
0.88 [0.85-0.90]
0.61 [0.57-0.65]
0.79 [0.75-0.82]
-0.09
<0.0005
<0.005
ID
0.91 [0.87-0.94]
0.95 [0.92-0.97]
0.92 [0.89-0.94]
0.90 [0.86-0.94]
-0.05
=0.0050
0.045
Appendix
Table S3: Distillation fidelity on SHIELD, per category. Gemini 2.5 Flash (teacher) against TIDE2-Sentry (student), with bootstrap 95% confidence intervals over 2,000 document-level resamples. Δ R is student minus teacher recall, so a negative value means the student trails; p comes from a paired document-bootstrap test, and padj=min(1,9p) is the Bonferroni-adjusted value for a family of 9 categories.
Category
Metric
TIDE2 regex
AIMI v1
AIMI v2
TIDE2-Sentry
TIDE2-Sentry+regex
SHIELD
AGE
Precision
0.00 [0.00-0.00]
0.00 [0.00-0.00]
0.00 [0.00-0.00]
0.71 [0.65-0.77]
0.71 [0.65-0.77]
AGE
Recall
0.00 [0.00-0.00]
0.00 [0.00-0.00]
0.00 [0.00-0.00]
0.78 [0.74-0.83]
0.78 [0.74-0.83]
DATE
Precision
0.98 [0.98-0.99]
0.94 [0.93-0.95]
0.95 [0.94-0.96]
0.97 [0.96-0.97]
0.95 [0.94-0.96]
DATE
Recall
0.92 [0.91-0.94]
0.95 [0.94-0.96]
0.95 [0.94-0.96]
0.94 [0.93-0.95]
0.95 [0.93-0.96]
DOCTOR
Precision
0.00 [0.00-0.00]
0.41 [0.38-0.43]
0.37 [0.34-0.39]
0.93 [0.92-0.94]
0.93 [0.92-0.94]
Appendix
Table S4: Per-category confidence intervals for the core recognizers. Span-level precision and recall with bootstrap 95% intervals over 2,000 document-level resamples, for regex, the fine-tuned clinical transformers and the TIDE2-Sentry +regex ablation, on both corpora. The AIMI recognizers have no AGE, LOCATION or WEB label; their degenerate 0.00 [0.00–0.00] cells in these categories reflect that, and Tables S1–S2 write them as “–”.
Category
Metric
DeBERTa-PII
OpenMed L
OpenMed S
PII-Ident.
Ettin-68M
ekacare
SHIELD
AGE
Precision
0.00 [0.00-0.00]
0.03 [0.01-0.06]
0.06 [0.04-0.09]
0.14 [0.09-0.18]
0.12 [0.05-0.20]
0.72 [0.68-0.77]
AGE
Recall
0.00 [0.00-0.00]
0.03 [0.01-0.05]
0.04 [0.03-0.07]
0.09 [0.06-0.11]
0.02 [0.01-0.04]
0.88 [0.85-0.92]
DATE
Precision
0.42 [0.40-0.44]
0.66 [0.64-0.68]
0.62 [0.59-0.64]
0.65 [0.63-0.67]
0.65 [0.63-0.67]
0.57 [0.54-0.59]
DATE
Recall
0.39 [0.36-0.42]
0.75 [0.73-0.77]
0.72 [0.70-0.75]
0.74 [0.71-0.76]
0.73 [0.71-0.75]
0.66 [0.63-0.68]
DOCTOR
Precision
0.00 [0.00-0.00]
0.00 [0.00-0.00]
0.00 [0.00-0.00]
0.00 [0.00-0.00]
0.00 [0.00-0.00]
0.00 [0.00-0.00]
Appendix
Table S5: Per-category confidence intervals for the external PII taggers. Bootstrap 95% intervals over 2,000 document-level resamples, on SHIELD and i2b2 2014. These models are trained on non-clinical or non-US PII distributions, so their numbers read as an off-distribution check and not as tuned baselines (Supplementary Note 2).
SHIELD category
i2b2 2014 tags
Treatment
AGE
AGE
straight through; right edge extended over the age unit
DATE
DATE
straight through (Philter safe-date re-mapping: sensitivity only)
CITY / STATE / STREET / ZIP / COUNTRY / LOCATION-OTHER
relabelled; adjacent components merged into one span
Appendix
Table S6: The i2b2 2014 to SHIELD label crosswalk. The mapping is applied to the gold spans at scoring time. After exclusions and boundary alignment the corpus has 27,298 gold spans over 1,304 notes. The boundary rules follow from the annotation conventions: i2b2 annotates most ages as a bare number and each address component separately, whereas SHIELD includes the age unit and annotates the whole address as one span.
Capability
TIDE 1.0
TIDE 2.0
Recognizer
coupled, fixed NER
model-agnostic (regex / transformer / LLM)
Name / location surrogate
yes (RNG, non-deterministic)
yes (cryptographic keyed)
Same value → same surrogate
no
yes, automatic (keyed)
New key gives an unlinkable release
n/a
yes
ID / MRN / SSN / phone
redaction only
format-preserving encryption / hash
Email / URL / organization
redaction only
surrogate
Appendix
Table S7: Functional and architectural change from TIDE 1.0 to TIDE 2.0.
Category
PHI span
TIDE 1.0
TIDE 1.0 strat.
TIDE 2.0
TIDE 2.0 strat.
Name
John Smith
Ziyad Bromberg
surrogate (RNG)
Flynn Singleton
keyed surrogate
Location
123 Main St, New York, NY 10001
Nashua NH 03060
surrogate (RNG)
13737 Chestnut Hill Rd, Balance Of Jerome County, NY 49885
keyed surrogate
Org
Stanford Health Care
Stanford Health Care
unchanged (no org surrogate)
Unity Ridge Community Hospital
keyed surrogate
Date
April 18, 2012
04/28/2012
date-shift (jitter)
April 28th, 2012
date-shift (jitter)
Age
95 years old
[90 year old] old
generalization (90+)
89 years old
cap at 89
Age
88 years old
88 years old
unchanged (fires 90+ only)
88 years old
cap at 89
Appendix
Table S8: Worked anonymization examples on identical inputs. TIDE 1.0 redacts structured identifiers and draws non-deterministic name and location surrogates; TIDE 2.0 applies a surrogate, format-preserving encryption or a keyed hash to every category.
Value
Occ.
TIDE 1.0
TIDE 2.0 (same key)
TIDE 2.0 (new key)
Jose (Name)
A/1
Rourke
Tidwell
Rowland
A/2
Suskin
Tidwell
(same)
B/1
Abid
Tidwell
(same)
15851368 (MRN)
A/1
[MRN]
15068153
24176984
A/2
[MRN]
15068153
(same)
B/1
[MRN]
15068153
(same)
Appendix
Table S9: Consistency and remapping. Each value appears three times across two notes for one patient. TIDE 2.0 maps a value to the same surrogate under a fixed key, which is what makes cross-note linkage survive, and to a different surrogate under a new key, so releases under different keys cannot be linked. TIDE 1.0 draws a new random surrogate at each occurrence for names.
Table S10: Feature comparison with OpenMed, a per-document detection toolkit. The two systems address different problems and are complementary: TIDE 2.0 is a batch engine and can host an OpenMed model as a recognizer plugin.
Axis
TIDE 2.0
GCP Sensitive Data Protection
Azure Health De-id
AWS Comprehend Medical
Deployment
on-prem, open-source (PHI local)
managed cloud
managed cloud
managed cloud
De-identify (replace) or only detect?
detect + replace
detect + redact/replace/mask/crypto/tokenize
detect + surrogation
detect only
Longitudinal consistency across notes
yes, cryptographic keyed
not documented as built in
not documented as built in
n/a
Interval-preserving per-patient date shift
yes
generic date-shift, not per-patient
limited
n/a
Model-agnostic recognizer
yes
fixed service models
fixed service models
fixed service models
Batch execution
Ray distributed (single-node benchmark in this paper)
via cloud APIs (egress + quota)
via cloud APIs
via cloud APIs
Appendix
Table S11: Feature comparison with managed cloud de-identification services. These services require sending clinical text off-site under a business associate agreement. AWS Comprehend Medical detects PHI but performs no in-service replacement.
Share (%)
Recall
Category
SHIELD
i2b2
SHIELD
i2b2
Recall term
Mix term
AGE
3.5
7.3
0.78
0.68
+0.006
-0.028
DATE
34.7
45.7
0.94
0.85
+0.037
-0.099
DOCTOR
25.4
17.6
0.90
0.85
+0.010
+0.069
HOSPITAL
9.0
8.5
0.79
0.39
+0.034
+0.003
ID
7.1
6.8
0.90
0.64
+0.018
+0.002
Appendix
Table S12: Decomposition of the SHIELD to i2b2 drop in micro-averaged recall, TIDE2-Sentry. Share: the category’s percentage of gold spans on each corpus. Recall term: wˉc(rs,c−ri,c) , the category’s recall change weighted by its mean share. Mix term: rˉc(ws,c−wi,c) , the effect of the different category mix. The two columns sum to the total drop (Methods). A positive value lowers recall on i2b2.
SHIELD
i2b2 2014
Category
Δ R [95% CI]
Δ P [95% CI]
Δ R [95% CI]
Δ P [95% CI]
AGE
+0.000 [+0.000 to +0.000]
+0.000 [+0.000 to +0.000]
+0.000 [+0.000 to +0.000]
+0.000 [+0.000 to +0.000]
DATE
+0.001 [+0.000 to +0.004]
-0.011 [-0.016 to -0.007]
+0.007 [+0.004 to +0.010]
-0.007 [-0.009 to -0.005]
DOCTOR
+0.000 [+0.000 to +0.000]
+0.000 [+0.000 to +0.000]
+0.000 [+0.000 to +0.000]
+0.000 [+0.000 to +0.000]
HOSPITAL
-0.008 [-0.014 to -0.002]
-0.001 [-0.004 to +0.001]
-0.000 [-0.001 to +0.000]
+0.000 [-0.001 to +0.002]
ID
+0.012 [+0.000 to +0.029]
-0.000 [-0.004 to +0.002]
+0.009 [+0.005 to +0.014]
-0.003 [-0.007 to +0.000]
Appendix
Table S13: Effect of the regex layer. Difference in span-level recall ( Δ R) and precision ( Δ P), TIDE2-Sentry +regex minus TIDE2-Sentry, with 95% intervals from a paired document bootstrap (2,000 resamples). Micro pools counts over the 9 categories.
SHIELD
i2b2 2014
Model
P [95% CI]
R [95% CI]
P [95% CI]
R [95% CI]
TIDE2 regex
0.00 [0.00-0.00]
0.00 [0.00-0.00]
0.00 [0.00-0.00]
0.00 [0.00-0.00]
AIMI v1
0.55 [0.53-0.58]
0.59 [0.56-0.61]
0.35 [0.34-0.37]
0.35 [0.33-0.37]
AIMI v2
0.53 [0.51-0.55]
0.56 [0.54-0.58]
0.33 [0.32-0.35]
0.33 [0.32-0.35]
TIDE2-Sentry
0.95 [0.94-0.96]
0.91 [0.89-0.92]
0.93 [0.92-0.94]
0.84 [0.83-0.86]
TIDE2-Sentry + regex
0.95 [0.94-0.96]
0.91 [0.89-0.92]
0.93 [0.92-0.94]
0.84 [0.83-0.86]
Appendix
Table S14: DOCTOR and PATIENT pooled as NAME. Span-level precision and recall with bootstrap 95% intervals when the two person categories are scored as one. This removes the patient/provider distinction that the external taggers’ taxonomies do not make.
De-identification of clinical text is a prerequisite for the secondary use of electronic health records. Existing public benchmarks such as the i2b2 2006 and 2014 corpora are over a decade old and lack the semantic and demographic diversity of modern clinical narratives. Large Language Models (LLMs) reach state-of-the-art zero-shot extraction, but their use at enterprise scale is limited by computational cost and by hospital data governance that restricts sending Protected Health Information (PHI) to cloud APIs. We introduce SHIELD (Synthetic Human-annotated Identifier-replaced Entries for Learning and De-identification), a diverse clinical note dataset of 1,381 notes with 10,229 gold-standard PHI spans across 9 categories, built with set-cover diversity sampling across demographic and document-type strata and human-in-the-loop adjudication. We evaluate four LLMs (two proprietary, two open-weight) to establish a performance ceiling on SHIELD, then show that a teacher-student distillation framework transfers these capabilities into locally deployable Small Language Models. Our best distilled model reaches micro-averaged span-level precision of 0.89 and recall of 0.88 while running on standard workstation hardware. It trails its cloud teacher on per-category recall (0.90 vs. 0.81 macro-averaged) but remains competitive given its lower cost and on-premise deployability. Cross-dataset evaluation shows that diversity-trained models generalize well on universal structured PHI categories, while institution-specific entities remain hard to transfer in both directions, which suggests pairing broad-coverage models with specialized models for high-volume, semi-structured note types. We publicly release the SHIELD dataset and the distilled DeBERTa v3 model to provide an accurate, cost-effective de-identification pipeline deployable entirely behind institutional firewalls.
Jose D. Posada, David Love, Somalee Datta +1
Technology & Digital Solutions Stanford Medicine · Stanford Medicine
Clinical notes contain personally identifiable information (PII), restricting reuse for research and medical AI, especially when data cannot leave an institution. We developed MedDeID, an on-premises framework combining in-house annotation and synthetic-note generation with model training, inference, pseudonymisation and evaluation. On an independently annotated, adjudicated 300-note Dutch hospital benchmark, a hospital-trained compact transformer detected 98.9% of identifying text while redacting 0.24% of text outside annotated identifiers; a synthetic-only counterpart detected 96.1%. On 100 primary-care notes, the synthetic-trained model achieved higher recall than the hospital-trained model (90.3% versus 87.0%) and greater robustness to identifier-format perturbations. An English instantiation trained without real text detected 99.7% and 98.9% of annotated identifier characters on two external synthetic benchmarks. These results demonstrate transfer of the workflow to another language, but not clinical English performance. MedDeID provides a route to locally governed de-identification using real or synthetic training data.
Stig Hellemans, Tom Stroobants, Elyne Scheurwegs +3
Adrem Data Lab, Department of Computer Science, University of Antwerp, Antwerp, Belgium · Antwerp University Hospital (UZA), Edegem, Belgium · Laboratory of Experimental Medicine and Pediatrics (LEMP), University of Antwerp, Antwerp, Belgium
Structure-preserving de-identification replaces protected health information (PHI) with realistic same-type surrogates -- "Anna S." becomes "Maria S.", not [NAME] -- so that clinical text stays fluent and downstream tools keep working. But this only helps if the substitution does not itself corrupt the signal those tools rely on. We ask a narrow, testable question: on the spans a de-identifier actually masks, can downstream PHI detectors still find the surrogate? We introduce a paired, multi-detector evaluation protocol that (i) scores utility only on masked spans, decoupling coverage from utility; (ii) uses equivalence testing (TOST) rather than null-hypothesis significance testing, which is uninformative at our sample size (57k paired spans); and (iii) builds a surrogate-failure typology separating fixable generator defects from intrinsic detector limits. Across 11 detectors, 7 benchmarks, and 7 languages (1,750 documents), recall on masked spans moves from 76.1% to 74.9% -- a change our equivalence test shows is statistically equivalent to zero within a +/-2-point margin (p ~ 3e-9), with detector ranking preserved. The residual loss does not reflect detectors getting worse at PHI: it concentrates in malformed and out-of-distribution surrogates (truncation Chicago -> Illino, salience loss Cedars-Sinai -> Vidant). A redaction floor and an open-source surrogate baseline indicate the effect is a property of well-formed substitution, not of one tool. We release the evaluation subsets, scoring code, and an interactive dashboard at https://custodianai.pages.dev so the protocol can audit any structure-preserving transform.
Qiming Bao, Sherry J. H. Feng, Kim Chester Eugenio +1