Standard 01 / Privacy

Medical imaging de-identification

Medical imaging de-identification removes or transforms direct and indirect identifiers in DICOM metadata and image pixels while preserving only the technical fields required for the agreed AI task. It should be validated independently and documented before external transfer.

MetadataTag policy and pseudonymous UIDs
PixelsBurned-in text review
AnatomyDefacing where required
EvidenceValidation report
01

Metadata, pixels and linkages

Patient names and identifiers are only the obvious layer. Free-text fields, institution details, accession numbers, dates, private vendor tags, burned-in annotations and recognizable facial surfaces can also carry identity risk. Each category needs an explicit rule rather than a blanket delete operation.

  • Remove direct identifiers and transform study, series and instance UIDs
  • Review free text, private tags and burned-in annotations
  • Apply date removal, generalization or consistent shifting as approved
  • Deface head imaging when facial reconstruction risk is in scope
  • Keep the re-identification key under hospital control when linkage is needed
02

Technical allow-lists

Useful acquisition fields such as modality, field strength, sequence parameters, scanner model or reconstruction may be essential for bias analysis. They should be preserved through an approved allow-list after privacy review, not retained by accident.

03

Validation before delivery

Automated tag tests are combined with sampling, pixel inspection and exception review. The resulting report records the ruleset, tool version, failures, manual actions and residual limitations. Legal adequacy depends on jurisdiction and the governing agreement, so this technical process is not a substitute for legal review.

04

Questions, answered directly.

Is deleting PatientName enough?

No. Identifiers can exist in many DICOM fields, private tags, free text and image pixels.

Who should retain the identity linkage?

Where linkage is necessary, the hospital or authorized data controller should retain the mapping rather than the external buyer.

Can scanner information be kept?

Often yes, when it is non-identifying, necessary for the task and expressly included in an approved technical allow-list.

Institutional engagement

Build the programme.

hello@medcorpora.com