Risk Management File De-Identification with anonym.plus

Clear every identifier from a claims or risk file before you pool the data.

In simple terms, PII redaction is the on-device process of finding and masking personally identifiable information in a document before it is shared.

Risk-file de-identification is the removal of personal data from a claims or near-miss dossier, often handled through NHS Resolution under the Clinical Negligence Scheme for Trusts. Where a claim is live, processing the special-category health data in it relies on the legal-claims gateway in UK GDPR Art. 9(2)(f), which — unlike the employment or health-and-social-care gateways — needs no extra domestic condition in DPA 2018 Schedule 1. anonym.plus runs on your device. The facts of the event stay, but the people are no longer named.

When this applies

A risk team tracks claims and near-misses handled through NHS Resolution that name patients, staff, and solicitors. To find trends across them for a different, non-claims purpose, the identifying detail must come out first.

How anonym.plus handles it

  1. Open the dossier in anonym.plus on your device.
  2. Local OCR reads scanned correspondence and forms.
  3. It flags patient, staff, and legal-team names plus dates.
  4. Confirm the flags and keep your non-ID case codes.
  5. Swap each item for a steady label, or remove it.
  6. Save the cleaned copy. The source stays local.

What you need to provide

Patient data entity types detected

Categoryanonym.plus entity typeExample
PatientPERSONclaimant J. Ito → [PATIENT]
StaffPERSONDr. Khan → [STAFF]
LegalPERSONsolicitor M. Stern → [COUNSEL]
DatesDATE_TIMEfiled 06/2025 → [DATE]
Record IDsMEDICAL_RECORD_NUMBERNHS No. 601 234 9871 → [NHS_NUMBER]
IdentifiersIDclaim no. RM-7741 → [CLAIM_ID]

Compliance achieved

Anonymise risk management files offline — see plans & start free →

Limitations & cautions

A claims dossier is mostly narrative and quotes many parties. A unique mix of date, site, and event can still point to one matter after names go. Review such lines, and consider whether the motivated-intruder test warrants further coarsening.

Frequently asked questions

What lets a hospital process health data in a live claim?

UK GDPR Art. 9(2)(f) permits processing special-category data that's necessary to establish, exercise, or defend a legal claim — the gateway a claim handled through NHS Resolution and the Clinical Negligence Scheme for Trusts relies on. Unlike the employment or health-and-social-care gateways, it needs no extra condition from DPA 2018 Schedule 1.

Can I keep matters linked across many records?

Yes. A label map gives one claim the same steady alias wherever it appears, so trend work across a large dossier still groups the right entries together.

Is anything sent off the device?

No. All work is local, so a sensitive claims dossier is never uploaded, whether it's still part of a live claim or being reviewed for a different purpose afterwards.