Skip to content

De-identification

A de-identification profile removes identities from everything a destination is sent: for AI services, research, teaching and outside collaborators. Configuration › De-identification, then choose the profile on the destination. It applies last, after the destination’s tag edits, and the router’s own copy keeps the original.

  • The DICOM Basic Application Level Confidentiality Profile (PS3.15 Annex E), in full: every one of the 653 attributes of Table E.1-1 (2026d edition) is removed, emptied, given a dummy value or has its UIDs replaced, as the table says, in sequences too: names, IDs, addresses, physicians, operators, accession, admission and order numbers, other patient IDs, original and encrypted attributes, content sequences and the rest. Private tags, curves and overlay data are removed.
    • Where the table’s action depends on the kind of object (X/Z, X/D, Z/D, X/Z/D: required in some, optional in others), a present element is emptied or given a dummy value rather than removed, so that every kind of object stays valid; references to other instances (X/Z/U*) are kept with their UIDs replaced. Nothing identifying stays either way.
    • The Patient’s Birth Date is emptied whatever the options, as the standard says (the age stays, in Patient’s Age, with Retain patient characteristics).
  • Pseudonyms: the Patient ID becomes a prefix and a pseudonym of the original ID and its issuer; the Patient’s Name follows a template such as SUBJECT^{Pseudonym}.
  • UIDs: study, series, instance and frame-of-reference UIDs, and every reference to them, become new 2.25. UIDs. Class and syntax UIDs stay.
  • Dates: shifted back by 1 to n days per patient (intervals kept, times unchanged), kept, or removed.
  • Options to keep patient characteristics (the default), UIDs, device identity, institution, descriptions (not cleaned) and private tags: each keeps exactly the attributes its column of Table E.1-1 lists.
  • The instances record what was done: Patient Identity Removed, De-identification Method and its code sequence, and Longitudinal Temporal Information Modified.
  • Tag edits after de-identification, for clinical trial attributes, with {Pseudonym} available.

Pseudonyms, UIDs and date shifts are derived with a key the central service generates for each profile and gives only to nodes. So they are the same on every node, every time: a patient’s studies stay linked, and references between instances still resolve.

  • A destination whose profile key has not reached the node yet is held: nothing is ever sent identified.
  • New key gives a profile a new key (if it may have been exposed): from then on its patients get new pseudonyms, UIDs and date shifts, so what was sent before and after cannot be linked through them. Audited.
  • Look up a pseudonym (administrators with the history role; audited) shows what a patient ID and UIDs became, for matching results that come back.

AI workflows do this matching for you: results are given the patient’s identity back.

Some images carry identities in the pixels: ultrasound and secondary captures, mostly.

  • Mask rules black out regions of the pixels (every frame) of matching images, by modality, manufacturer, model and image size: a 60-pixel band at the top of one ultrasound model’s images, say. Masked images are decoded, edited and encoded again in the syntax they are sent in, and marked Burned In Annotation NO.
  • Other instances whose header says they carry burned-in annotation, or that have recognizable features, are refused (dead-lettered) unless the profile allows them.