Home/Redact/Medical records

Redact a medical record without stripping the clinical picture

A record is mostly the part you want read. The identifiers are scattered through it: the header, the footer, an accession number stamped on every page, a phone number in a referral note. They’re the reason it can’t go out unchanged.

Drop the PDF you want to redact

or choose a file

Confirm first that the file really holds something that must not get out. Redaction cannot be undone.

The identifiers aren’t all in the header

Everyone remembers the name at the top. The ones that travel are the ones nobody looks at twice: the medical record number repeated in the page footer, the accession number on a lab result, the date of birth in a line of clinical text, the referring clinician’s direct line.

A record is also the worst document to over-redact. Take out the medication table and the reader can’t answer the question you sent the file to answer, so you get asked again, and the second request usually asks for more than the first would have.

Separate the identifiers from the clinical content

Go through once and sort what’s on the page into two piles. Then box one pile and leave the other alone.

Name and address
Box unless the reader already has them and needs them to match the file.
Date of birth
Usually box. Keep the age if the reader needs to stratify it, and write it in the covering note instead.
Record and accession numbers
Box every occurrence. They reappear in the footer of each page, so check the whole document rather than the first page.
Clinician names
Box the direct contact details. The name itself is often needed so the reader knows who wrote it.
Dates of care
Keep. The timeline is clinical information, and removing it changes the meaning of the record.
Diagnoses, medication, results
Keep. This is the part the file was sent to communicate.

A box takes the whole page with it

On export, each page carrying a box is redrawn as an image at the resolution you choose, and the text layer goes with it. That’s what makes the covering real, because there’s no text left underneath to select or search.

The cost is that the page stops being searchable, including the clinical text you deliberately left visible. If a clinician is going to copy a result into their own system, note it in the covering letter, or send an unredacted copy through a channel you trust.

Only the pages you box are redrawn. Pages you leave alone are copied through untouched and keep their text layer. On a long record this usually means boxing the few pages that carry identifiers, not the medication history.

The export is checked, not promised

The tool reopens the file it just wrote, pulls the text off every page you boxed, and counts the characters. It reads 0 when the pages are clean. That figure is the only evidence that the covering worked, and it’s more useful than a tick beside a filename.

If the file has to satisfy a regulator, read this first

Redaction makes a document safe to send to the person you’re sending it to. It doesn’t make you compliant with anything. That depends on your legal basis for the disclosure, who the recipient is, and what your jurisdiction requires.

This site has no compliance certification and doesn’t claim one. What it does claim is narrower and checkable: the file is processed in your browser, and the covered text is gone from the exported file.

A record that has been redacted is still a record. Once the file has left your machine, the copy in the recipient’s inbox is theirs to keep. Send the smallest set of pages that answers the question.

Straight answers

Can I keep the patient’s age but remove the date of birth?

Not automatically, because nothing in the file distinguishes them. The age is usually printed as part of the same line. Box the line and put the age in the covering note, where you can phrase it exactly.

What about the record number in the page footer?

That’s the occurrence people miss. It repeats on every page, so boxing the first page isn’t enough. Tick through the document with the page arrows and box each footer that carries it.

Will the reader still be able to read the results?

Yes. At 200 dpi, the default, a redrawn page reads and prints normally. At 150 dpi it’s noticeably softer when zoomed. A table of small numbers is the case where you want 300 dpi.

Does it strip the file’s metadata as well?

Yes. Title, author, producing software and timestamps are removed on export. On a record, the author field is often the clinician’s name, which is exactly the kind of identifier that survives a careless redaction.

Is the original changed?

No. The export is a new file. The record you opened is untouched, so keep it wherever you keep files you haven’t redacted.

More on redact

The full tool, with every option: Redact.