Guide / De-identification

De-identifying DICOM, radiology reports and pixel data

Medical imaging de-identification must address more than patient-name tags. A governed programme evaluates DICOM metadata, private tags, radiology text, burned-in annotations, recognizable facial anatomy, dates, filenames and linked clinical tables, then validates the released representation against the approved privacy method.

Published 30 July 2026 · Reviewed 12 August 2026 · MedCorpora
MetadataDICOM tags · private elements
TextReports · filenames · free text
PixelsBurned-in text · facial anatomy
EvidenceValidation and exception records
01

What the programme covers

Different modalities and source systems expose identifiers in different places. A rule that is sufficient for one structured field may not detect free-text identifiers, device overlays or reconstructable facial anatomy, so controls must be matched to the programme.

02

What a useful specification includes

A defensible request defines the clinical task, source evidence and acceptance criteria before patient-level data moves. The exact fields and thresholds depend on the intended model claim.

  • Approved privacy method and recipient context
  • DICOM attributes and private-tag policy
  • Report and free-text processing
  • Burned-in annotation and pixel inspection
  • Date handling and longitudinal preservation
  • Pseudonymous linkage and re-identification controls
03

Quality and validation controls

Validation combines deterministic rules, automated detection and risk-based review. Exceptions, false positives and allowed retained fields are documented instead of hidden inside an irreversible transformation.

  • Direct identifier and private-tag scans
  • Free-text and filename review
  • Burned-in text and pixel-region detection
  • Facial-anatomy assessment where relevant
  • Linkage, date and output-manifest verification
04

Availability, rights and delivery

Only the approved de-identified or otherwise authorized representation is released. Source records and any authorized re-identification mapping remain within the applicable controlled environment.

Public pages describe a sourcing and engineering capability, not guaranteed ready inventory. Each release remains subject to verified programme inventory, programme-specific authorization, privacy review, technical acceptance and buyer licence terms.

05

Questions, answered directly.

Is deleting PatientName enough?

No. Identifiers can appear in many metadata fields, private tags, pixels, filenames, reports and linked tables.

Can dates be retained?

Only when the approved privacy method and programme purpose allow the necessary temporal information and associated controls.

Do reports need separate processing?

Yes. Free text requires controls designed for textual identifiers and clinically meaningful context.

Is de-identification the same as programme authorization?

No. Privacy processing does not create commercial rights or replace programme-specific permission.

Institutional engagement

Define the cohort.