Incident-report de-identification is the removal of personal data from a harm write-up. Regulation 20 of the Health and Social Care Act 2008 (Regulated Activities) Regulations 2014 sets the statutory duty of candour: a registered provider must tell a patient, honestly and promptly, when a notifiable safety incident happens to them. DPA 2018 s.3(2) sets the test for what still counts as personal data once names are stripped. anonym.plus applies both on your own device, so the lesson stays while the names go.
When this applies
A fall or medication error gets logged with the individual, the nurse, and the ward. The duty of candour under regulation 20 requires the provider to be open with that patient directly, in the original record. Pooling the same write-up for wider improvement work is a different use, and it needs the personal details cleared first.
How anonym.plus handles it
- Open the write-up in anonym.plus on your workstation.
- Local OCR reads scanned or printed pages, so nothing slips by.
- It flags patient names, staff names, dates, and the ward.
- Check each flag and keep any non-ID safety code you need.
- Swap each detail for a clear label, or black it out.
- Save the cleaned file. The original never leaves your machine.
What you need to provide
- The write-up (PDF, DOCX, TXT, or image scan).
- An operator: Replace (swap), Redact (remove), or Mask (partial).
- Optional allow-list to keep your own event codes.
Patient data entity types detected
| Category | anonym.plus entity type | Example |
|---|---|---|
| Patient | PERSON | James Patel → [PATIENT] |
| Staff | PERSON | RN Sarah Okafor → [STAFF] |
| Dates | DATE_TIME | fell 12/04/2026 → [DATE] |
| Location | LOCATION | Ward 6, Bed 3 → [LOCATION] |
| Record IDs | MEDICAL_RECORD_NUMBER | NHS No. 943 476 5919 → [NHS_NUMBER] |
| Staff ID | ID | badge E-4471 → [STAFF_ID] |
Compliance achieved
- Meets the statutory duty of candour in reg. 20, Health and Social Care Act 2008 (Regulated Activities) Regulations 2014 without exposing the write-up beyond the disclosure it requires.
- Clears identifying detail under DPA 2018 s.3(2) before the case is pooled for improvement work.
- Keeps the common-law duty of confidence intact by never sending the file to a third party.
- Runs offline, so working files are guarded by AES-256-GCM.
Anonymise incident reports offline — see plans & start free →
Limitations & cautions
An incident write-up mentions both a patient and a worker. Both sets of identifying detail must go. Free-text lines can also hold a unique clue, like a rare event on a quiet ward, so give those a careful read before you export.
Frequently asked questions
Does the duty of candour affect whether I can de-identify this report?
No. Regulation 20 of the Health and Social Care Act 2008 (Regulated Activities) Regulations 2014 requires the provider to tell the patient directly when a notifiable incident happens to them, and that disclosure happens in the original record, not the anonymised copy. Removing names from a version used for a separate purpose, like a trust-wide safety review, doesn't touch that duty at all.
Does an incident log count as protected information?
Yes, when it names the person involved or carries their NHS number. It also cites staff by name, and staff records are personal data too. Both sets of identifiers need to come out before the event is pooled with others for review.
Will the lesson survive the swap?
Yes. Only the identifying details change, so the sequence of events and the root cause stay intact. That's the part a safety review actually needs, and it reads the same with or without the names.