Employee medical record redaction is the removal of personal clinical data from the confidential file an employer should keep apart. Equality Act 2010 s.60 restricts pre-offer health questions and treats the answers as sensitive, and they are special category data under UK GDPR Art. 9. anonym.plus marks each detail on your device, so the file stays separate while the worker is shielded.
When this applies
The confidential folder holds occupational health notes and adjustment data for one worker. When any part is shared, you trim the identifiers s.60 keeps off-limits.
How anonym.plus handles it
- Open the record in anonym.plus on your device.
- Local OCR reads scanned occupational letters.
- The tool flags names, conditions, and clinicians.
- Confirm each flag and keep any neutral case label.
- Swap or black out the confirmed items.
- Save the clean copy locally and store it apart.
What you need to provide
- The clinical record (PDF, DOCX, or scan).
- An operator (Redact suits sensitive pages).
- Optional batch for a multi-page set.
PII entity types detected
| Category | anonym.plus entity type | Example |
|---|---|---|
| Names | PERSON | Priya Nair → [WORKER] |
| Health | MEDICAL_CONDITION | diabetes → [CONDITION] |
| NHS Number | UK_NHS | 485 777 3456 → [NHS_NO] |
| NI number | UK_NINO | QQ 61 33 20 C → [NINO] |
| Dates | DATE_TIME | DOB 1982 → [DOB] |
| Contact | EMAIL_ADDRESS | p.nair@example.co.uk → [EMAIL] |
Compliance achieved
- Supports the question limits in Equality Act 2010 s.60.
- Treats the file as special category data under UK GDPR Art. 9.
- Offline work keeps clinical data off any server, as the ICO expects.
Anonymise employee medical records offline — see plans & start free →
Limitations & cautions
anonym.plus is a de-identification aid, not legal advice. It removes identifiers locally, but a rare condition can still re-identify a worker in a small group. Review such cases yourself and keep the file apart from the personnel folder.
Frequently asked questions
Why keep these files separate under the Equality Act?
Section 60 treats medical answers as sensitive, and the ICO expects special category data to be walled off from the personnel file. anonym.plus flags identifiers so a shared copy meets that limit.
Does this make you responsible for compliance?
No. The tool is offline software that strips data on your own device. Compliance under s.60 and UK GDPR stays with you as the controller.
Is the record uploaded?
No. Work runs locally with no cloud step, so the file stays on your machine.