Employee Medical Record Redaction with anonym.plus

Clear identifiers from a confidential medical file the Equality Act keeps walled off.

Employee medical record redaction is the removal of personal clinical data from the confidential file an employer should keep apart. Equality Act 2010 s.60 restricts pre-offer health questions and treats the answers as sensitive, and they are special category data under UK GDPR Art. 9. anonym.plus marks each detail on your device, so the file stays separate while the worker is shielded.

When this applies

The confidential folder holds occupational health notes and adjustment data for one worker. When any part is shared, you trim the identifiers s.60 keeps off-limits.

How anonym.plus handles it

  1. Open the record in anonym.plus on your device.
  2. Local OCR reads scanned occupational letters.
  3. The tool flags names, conditions, and clinicians.
  4. Confirm each flag and keep any neutral case label.
  5. Swap or black out the confirmed items.
  6. Save the clean copy locally and store it apart.

What you need to provide

PII entity types detected

Categoryanonym.plus entity typeExample
NamesPERSONPriya Nair → [WORKER]
HealthMEDICAL_CONDITIONdiabetes → [CONDITION]
NHS NumberUK_NHS485 777 3456 → [NHS_NO]
NI numberUK_NINOQQ 61 33 20 C → [NINO]
DatesDATE_TIMEDOB 1982 → [DOB]
ContactEMAIL_ADDRESSp.nair@example.co.uk → [EMAIL]

Compliance achieved

Anonymise employee medical records offline — see plans & start free →

Limitations & cautions

anonym.plus is a de-identification aid, not legal advice. It removes identifiers locally, but a rare condition can still re-identify a worker in a small group. Review such cases yourself and keep the file apart from the personnel folder.

Frequently asked questions

Why keep these files separate under the Equality Act?

Section 60 treats medical answers as sensitive, and the ICO expects special category data to be walled off from the personnel file. anonym.plus flags identifiers so a shared copy meets that limit.

Does this make you responsible for compliance?

No. The tool is offline software that strips data on your own device. Compliance under s.60 and UK GDPR stays with you as the controller.

Is the record uploaded?

No. Work runs locally with no cloud step, so the file stays on your machine.