Discharge summary de-identification is the removal of direct and indirect identifiers from the summary a hospital sends to the patient's GP. The document is health data, so it is special category under UK GDPR Art. 9(1), and the header fields the PRSB eDischarge Summary Standard puts on every summary — name, NHS number, date of birth, admission and discharge dates — are exactly the fields that must come out before reuse. anonym.plus clears them on your own device. Once no one can reasonably re-identify the person, UK GDPR Recital 26 puts the copy outside the regulation.
When this applies
Sending the original to the patient's GP is a duty under NHS Act 2006 s.251B. Teaching, audit, and analytics are different purposes. For those you strip the identifier block first and keep the diagnosis, the discharge medicines, and the follow-up plan.
How anonym.plus handles it
- Open the summary (PDF, DOCX, or scan) in anonym.plus on your device.
- Local OCR reads scanned pages, so printed header boxes are caught too.
- The tool flags names, dates, NHS numbers, addresses, and phone numbers.
- Check the flagged items and keep any clinical term caught by mistake.
- Swap each identifier for a safe label, or black it out.
- Save the clean file. The original never leaves your machine.
What you need to provide
- The summary (PDF, DOCX, TXT, or image scan).
- An operator: Replace (swap), Redact (remove), or Mask (partial).
- Optional alias map if you need to re-link records later.
Patient data entity types detected
| Category | anonym.plus entity type | Example |
|---|---|---|
| Names | PERSON | Oliver Bennett → [PATIENT_1] |
| Dates | DATE_TIME | Admitted 11/03/2026 → [DATE] |
| Record IDs | MEDICAL_RECORD_NUMBER | MRN 884213 → [MRN] |
| NHS Number | UK_NHS | NHS 943 476 5919 → [NHS_NO] |
| Location | LOCATION | 14 Elm Road, Leeds → [ADDRESS] |
| Contact | PHONE_NUMBER | +44 7700 900123 → [PHONE] |
Compliance achieved
- Clears the health data UK GDPR Art. 9(1) treats as special category.
- Targets the identifier block the PRSB eDischarge Summary Standard puts on every summary.
- The source record is held under DPA 2018 Schedule 1, Part 1, paragraph 2 (health or social care purposes).
- True anonymity takes the copy outside the law under UK GDPR Recital 26, judged by the ICO motivated-intruder test.
- Retention of the original still follows the Records Management Code of Practice for Health and Social Care 2021.
- Runs offline with AES-256-GCM at rest — no cloud upload, no processor contract.
Anonymise discharge summaries offline — see plans & start free →
Limitations & cautions
UK GDPR Recital 26 asks whether anyone could reasonably re-identify the person. The tool removes direct and indirect identifiers. You still judge rare free-text clues, such as an unusual illness paired with a small town. For those, apply the ICO motivated-intruder test before you share.
Frequently asked questions
Which identifiers must go for UK GDPR anonymisation?
There is no fixed UK list to tick off, unlike the 18-identifier US Safe Harbor rule. UK GDPR Recital 26 sets a risk test instead: the file is anonymous only when no one can reasonably re-identify it. In practice that means removing the name, the NHS number, the date of birth, admission and discharge dates, the address, phone numbers, and any other detail that could single the person out.
Does this need a data processor contract?
No. anonym.plus runs on your own device with no cloud step, so no outside party receives the summary and no UK GDPR Art. 28 processor contract is triggered. Uploading the same file to a cloud redaction service would make that vendor a processor and would require exactly such an agreement.
Does de-identifying a copy change how long we keep the original?
No. The Records Management Code of Practice for Health and Social Care 2021 sets the retention period for the source record, and de-identifying a working copy does not shorten or extend it. The clean copy is a separate artefact with its own purpose and its own retention decision.