Metadata, pixels and linkages
Patient names and identifiers are only the obvious layer. Free-text fields, institution details, accession numbers, dates, private vendor tags, burned-in annotations and recognizable facial surfaces can also carry identity risk. Each category needs an explicit rule rather than a blanket delete operation.
- Remove direct identifiers and transform study, series and instance UIDs
- Review free text, private tags and burned-in annotations
- Apply date removal, generalization or consistent shifting as approved
- Deface head imaging when facial reconstruction risk is in scope
- Keep the re-identification key under hospital control when linkage is needed
Technical allow-lists
Useful acquisition fields such as modality, field strength, sequence parameters, scanner model or reconstruction may be essential for bias analysis. They should be preserved through an approved allow-list after privacy review, not retained by accident.
Validation before delivery
Automated tag tests are combined with sampling, pixel inspection and exception review. The resulting report records the ruleset, tool version, failures, manual actions and residual limitations. Legal adequacy depends on jurisdiction and the governing agreement, so this technical process is not a substitute for legal review.
Questions, answered directly.
Is deleting PatientName enough?+
No. Identifiers can exist in many DICOM fields, private tags, free text and image pixels.
Who should retain the identity linkage?+
Where linkage is necessary, the hospital or authorized data controller should retain the mapping rather than the external buyer.
Can scanner information be kept?+
Often yes, when it is non-identifying, necessary for the task and expressly included in an approved technical allow-list.
