Compounding Record Redaction with anonym.plus

Clear IDs from the batch record while the formula stays.

In simple terms, PII redaction is the on-device process of finding and masking personally identifiable information in a document before it is shared.

Compounding-record redaction is the removal of patient and operator identifiers from a batch sheet. Extemporaneous preparation in a registered pharmacy runs on the section 10 exemption of the Medicines Act 1968; anything larger needs a licence under Part 3 of the Human Medicines Regulations 2012. anonym.plus runs locally and keeps the formula, lot, and quantity.

When this applies

A batch sheet names the patient it was made for and the operator who signed it off. For an inspection copy, a supplier query, or a teaching set, the formula and lot carry the meaning; the two names do not.

How anonym.plus handles it

  1. Open the sheet in anonym.plus on your device.
  2. It finds the patient and operator names plus codes.
  3. Dates and electronic-signature names get flagged.
  4. Confirm the flags; the formula and lot are kept as content.
  5. Black out items for inspection, or swap them for teaching.
  6. Save the clean copy; the source stays on your machine.

What you need to provide

Patient data entity types detected

Categoryanonym.plus entity typeExample
NamesPERSONmade for J. Marek → [PATIENT]
NamesPERSONoperator sign-off → [OPERATOR]
DatesDATE_TIMEcompounded 02 Mar → [DATE]
Record IDsMEDICAL_RECORD_NUMBERbatch no. OR-5521 → [BATCH_ID]
IdentifiersIDe-sig hash → [SIG_ID]
LocationLOCATIONclean room 3 → [SITE]

Compliance achieved

Anonymise compounding records offline — see plans & start free →

Limitations & cautions

MHRA GxP expectations and Annex 11 govern the integrity of your electronic records and audit trail. The tool removes patient and operator names from a copy; it does not run, validate, or replace your system, and it must never be used on the retained batch record itself. The formula and lot are kept as content.

Frequently asked questions

Is the formula removed?

No. The formula, lot, and quantity are product data, not patient identifiers, so they stay. Only the patient and operator names are taken out.

Does this make my system GxP compliant?

No. Annex 11 and the MHRA data integrity guidance cover your validated record system and its audit trail. The tool only de-identifies an exported copy of a batch sheet for safe sharing.

Are electronic-signature names removed?

Yes, from the copy. The signer's name is flagged, while the Annex 11 clause 14 signature controls stay in your own validated system, untouched.