Risk-file de-identification is the removal of personal data from a claims or near-miss dossier, often handled through NHS Resolution under the Clinical Negligence Scheme for Trusts. Where a claim is live, processing the special-category health data in it relies on the legal-claims gateway in UK GDPR Art. 9(2)(f), which — unlike the employment or health-and-social-care gateways — needs no extra domestic condition in DPA 2018 Schedule 1. anonym.plus runs on your device. The facts of the event stay, but the people are no longer named.
When this applies
A risk team tracks claims and near-misses handled through NHS Resolution that name patients, staff, and solicitors. To find trends across them for a different, non-claims purpose, the identifying detail must come out first.
How anonym.plus handles it
- Open the dossier in anonym.plus on your device.
- Local OCR reads scanned correspondence and forms.
- It flags patient, staff, and legal-team names plus dates.
- Confirm the flags and keep your non-ID case codes.
- Swap each item for a steady label, or remove it.
- Save the cleaned copy. The source stays local.
What you need to provide
- The claims or near-miss dossier (PDF, DOCX, or scan).
- An operator (Replace keeps cross-file trends linkable).
- Optional map so one matter maps to one label.
Patient data entity types detected
| Category | anonym.plus entity type | Example |
|---|---|---|
| Patient | PERSON | claimant J. Ito → [PATIENT] |
| Staff | PERSON | Dr. Khan → [STAFF] |
| Legal | PERSON | solicitor M. Stern → [COUNSEL] |
| Dates | DATE_TIME | filed 06/2025 → [DATE] |
| Record IDs | MEDICAL_RECORD_NUMBER | NHS No. 601 234 9871 → [NHS_NUMBER] |
| Identifiers | ID | claim no. RM-7741 → [CLAIM_ID] |
Compliance achieved
- Recognises the UK GDPR Art. 9(2)(f) legal-claims gateway a live NHS Resolution claim relies on, which needs no separate Schedule 1 condition.
- Strips identifying details for any use of the file beyond the claim itself.
- Runs offline, so no supplier touches the records.
- Clears patient, staff, and legal-team names in one pass.
Anonymise risk management files offline — see plans & start free →
Limitations & cautions
A claims dossier is mostly narrative and quotes many parties. A unique mix of date, site, and event can still point to one matter after names go. Review such lines, and consider whether the motivated-intruder test warrants further coarsening.
Frequently asked questions
What lets a hospital process health data in a live claim?
UK GDPR Art. 9(2)(f) permits processing special-category data that's necessary to establish, exercise, or defend a legal claim — the gateway a claim handled through NHS Resolution and the Clinical Negligence Scheme for Trusts relies on. Unlike the employment or health-and-social-care gateways, it needs no extra condition from DPA 2018 Schedule 1.
Can I keep matters linked across many records?
Yes. A label map gives one claim the same steady alias wherever it appears, so trend work across a large dossier still groups the right entries together.
Is anything sent off the device?
No. All work is local, so a sensitive claims dossier is never uploaded, whether it's still part of a live claim or being reviewed for a different purpose afterwards.