Pre-authorisation anonymisation is the removal of patient and provider IDs from a pre-auth request. Where the request takes the form of a letter from the patient's own treating doctor, it can fall within the Access to Medical Reports Act 1988, which gives the patient a right to see that report and to withhold consent to its release before it reaches the insurer. DPA 2018 Schedule 1, Part 1, paragraph 2 is the separate condition that lets the insurer hold the health data once it arrives. anonym.plus works on your device and keeps the medical reasoning the request rests on.
When this applies
A pre-auth packet names the patient, the referring doctor, and the diagnosis, and where a treating doctor supplied the covering letter, the 1988 Act's access rights may already have applied to it. To reuse the packet for turnaround analysis or training, strip the identifying fields first and keep the diagnosis and requested service.
How anonym.plus handles it
- Load the request into anonym.plus on your device.
- It scans the cover sheet and the attached notes.
- The tool flags names, dates, and membership numbers.
- The diagnosis and the requested service stay in place.
- Swap or black out the confirmed IDs.
- Save the clean packet on your machine.
What you need to provide
- The request (PDF, DOCX, or insurer portal export).
- An operator (Replace keeps the packet readable).
- Optional allow-list for service and diagnosis codes.
Patient data entity types detected
| Category | anonym.plus entity type | Example |
|---|---|---|
| Names | PERSON | Patient Ines Vogt → [PATIENT] |
| Provider | PERSON | Dr Amani → [REQUESTER] |
| Member ID | UK_HEALTH_INSURANCE_MEMBER | Mbr BUP-88442 → [MEMBER_ID] |
| Dates | DATE_TIME | Requested 03/05 → [DATE] |
| Phone | PHONE_NUMBER | +44 1632 960221 → [PHONE] |
| Auth ref | ID | Auth PA-9920 → [REF] |
Compliance achieved
- Meets DPA 2018 Schedule 1, Part 1, paragraph 2 for reuse of the underlying health data.
- Where the request is a doctor's report, respects the access rights in the Access to Medical Reports Act 1988.
- Keeps the diagnosis and requested service for analysis.
- Fully offline — data stays within your organisation.
- On-device AES-256-GCM guards working copies.
Anonymise pre-authorisation requests offline — see plans & start free →
Limitations & cautions
A pre-auth packet often staples notes to a cover sheet. Check that every page is scanned, since an ID can hide on an attachment. Free-text notes need the same review as any clinical note.
Frequently asked questions
Is the referring doctor’s name removed too?
Provider names are not the patient's own data, but teams often swap them for blinded review anyway. Where the request is itself a medical report from the patient's treating doctor, the doctor is also a data subject in their own professional capacity, so the tool can flag both names together or apart.
Will the clinical reasoning stay intact?
Yes. The diagnosis, the requested service, and the supporting clinical notes stay exactly as written. Only the identifying fields around them change.
Can I process a whole queue at once?
Yes. Point anonym.plus at a folder of pre-auth packets and it works through each one on your device, applying the same rules consistently across the queue.