Message anonymisation is the removal of personal detail from the threads patients send through a portal or the NHS App. The Caldicott Principles govern how a health organisation handles confidential patient information. The National Data Guardian who maintains them was put on a statutory footing by the Health and Social Care (National Data Guardian) Act 2018. Portal threads also form part of the record, so they fall inside a UK GDPR Art. 15 subject access request. anonym.plus swaps the identifiers on your device.
When this applies
Portal threads read like text messages. People share a name, an email, and a mobile number freely, and they mention relatives by name. To study these exchanges for service improvement, the identifying turns come out first.
How anonym.plus handles it
- Open the saved thread in anonym.plus on your device.
- It spots names, emails, numbers, and any dates.
- Each sender gets a steady role label across the chat.
- Check the flags, then swap or hide them.
- Save the cleaned thread locally with no upload.
What you need to provide
- The thread (TXT, CSV, JSON, or pasted chat).
- An operator: Replace keeps the back-and-forth readable.
- Optional sender map for [PATIENT] and [STAFF] turns.
Patient data entity types detected
| Category | anonym.plus entity type | Example |
|---|---|---|
| Names | PERSON | “– Priya” → [PATIENT] |
| Contact | EMAIL_ADDRESS | priya.k@nhs.net → [EMAIL] |
| Contact | PHONE_NUMBER | text me +44 7911 123456 → [PHONE] |
| Dates | DATE_TIME | “by Friday” → [DATE] |
| Identifiers | USERNAME | @priya_k → [HANDLE] |
| NHS number | NHS_NUMBER | NHS 943 476 5670 → [NHS_NO] |
Compliance achieved
- Supports the Caldicott Principles on the use of confidential patient information.
- Aligns with the office created by the Health and Social Care (National Data Guardian) Act 2018.
- Keeps the original thread available for a UK GDPR Art. 15 subject access request.
- Handles the special category health content the thread carries under UK GDPR Art. 9(1).
- Emails, mobile numbers, and portal handles are all treated as direct identifiers.
- Fully offline — a private thread is never uploaded to a third party.
Anonymise patient messages offline — see plans & start free →
Limitations & cautions
Casual chat is full of slang, typos, and partial names. A first name with no surname can still slip past. Look over the flags. Informal threads give the tool weaker grammar cues than a structured clinical note.
Frequently asked questions
Are usernames and portal handles treated as identifiers?
Yes. A portal handle or screen name points to one person just as an email address does, so it is flagged and swapped. Handles are also often reused elsewhere online, which makes them a re-identification route on their own.
Do portal messages count as part of the health record?
Usually yes, where clinical content is exchanged. That matters for two reasons: the thread has to be retained under the Records Management Code, and it has to be disclosed in response to a UK GDPR Art. 15 request unless an exemption applies.
Which Caldicott Principle is most relevant here?
The principles ask you to justify the purpose, use the minimum necessary, and access confidential information only when it is needed. A service-improvement study rarely needs names at all, so anonymising the thread is the direct way to satisfy the minimum-necessary point.