Medical Record Disclosure Redaction with anonym.plus

Strip patient identifiers from a health file before you disclose it.

In simple terms, PII redaction is the on-device process of finding and masking personally identifiable information in a document before it is shared.

A medical-record disclosure is the copy of a health file you release to a third party. For a living patient, UK GDPR Art. 9 and the DPA 2018 give health data extra protection; the ICO Anonymisation Code of Practice sets the de-identification bar. Where the request instead concerns a deceased patient, UK GDPR and the DPA 2018 no longer apply at all — access runs instead under the older Access to Health Records Act 1990, which gives a more limited class of people (broadly, personal representatives and those with a claim from the death) a right to apply. anonym.plus marks the identifiers on your own device either way, so the health file never reaches the cloud.

When this applies

A request asks for a health file for research or audit. It names the patient and carries the NHS number, dates, and address.

How anonym.plus handles it

  1. Open the health file in anonym.plus on your device.
  2. Local OCR reads scanned charts and forms.
  3. The tool flags names, NHS numbers, dates, and addresses.
  4. Check the flags and fix any clinical term caught wrongly.
  5. Swap each identifier for a label, or black it out.
  6. Save the de-identified file on your machine.

What you need to provide

PII entity types detected

Categoryanonym.plus entity typeExample
NamesPERSONpatient name → [PATIENT]
NHS NumberUK_NHSNHS 943 476 5919 → [NHS_NO]
Record IDsMEDICAL_RECORD_NUMBERMRN 884213 → [MRN]
DatesDATE_TIMEadmitted 03/11 → [DATE]
ContactPHONE_NUMBER+44 20 7946 0147 → [PHONE]
LocationLOCATION14 Oak Road → [ADDRESS]

Compliance achieved

Anonymise medical records offline — see plans & start free →

Limitations & cautions

The ICO Code also needs you to have no reason to think the rest could re-identify the patient. The tool removes the identifier types; you still judge rare free-text clues, like a rare illness plus a small town. Whether a deceased-patient request even engages the 1990 Act, rather than UK GDPR, is itself a threshold legal question. For re-identification risk, apply the motivated-intruder test.

Frequently asked questions

Which identifiers must go for health data?

Names, small geographic areas, all dates tied to a person, phone and fax, email, NHS number, MRN, account numbers, vehicle and device IDs, URLs, IPs, biometrics, photos, and other unique codes that could single out the patient.

Does UK GDPR still apply if the patient has died?

No. UK GDPR and the DPA 2018 protect only living individuals. A request about a deceased patient's health record instead runs under the Access to Health Records Act 1990, which limits who may apply — typically a personal representative or someone with a claim arising from the death — and can itself exclude information the deceased asked to be kept confidential.

Does this disclosure need a contract with a processor?

No. The app runs on your own device with no cloud step, so no outside party touches the health data and no data-processor agreement is triggered, under either regime.

Will the file still read after the swap?

Yes. The Replace operator puts a steady label in place of each identifier, so the clinical text still flows and names no real person, whether the underlying request is a living patient's SAR or a 1990 Act application.