How to redact a medical record or letter
Whether you're an individual sending a letter to an insurer or a professional sharing records, health information needs careful handling. Here's what to remove, the identifiers that get missed, and how to do it without uploading the file anywhere.
Medical documents are among the most sensitive there are, and they get shared more than you'd think: to insurers, employers, solicitors, a specialist for a second opinion, or a forum for advice. Usually the recipient needs the clinical content, not your identity, or a specific fact, not the whole record. Redacting the rest is both sensible and, for professionals, often required.
What to remove
Health-privacy rules give a useful checklist. Under HIPAA's "Safe Harbor" method, de-identifying a record means removing 18 categories of identifier. You don't need to memorise the list, but it's the right mental model. The common ones on a letter or record:
- Name (patient, and often next of kin).
- Address and any geographic detail smaller than a region.
- Dates tied to you: date of birth, admission, discharge. (Ages over 89 are treated specially.)
- Record and plan numbers: medical record number (MRN), NHS number, patient ID, health-insurance/policy numbers.
- Contact details: phone, email.
- Other IDs: national insurance / social security number, account numbers.
What you keep depends on the purpose. A second opinion needs the clinical findings, not your name or address. An insurance claim may need a specific date and provider, but not your full history. Share the minimum that does the job.
The identifiers people miss
- Headers and footers on every page. The name and MRN often repeat on each page; redact page one, miss page four.
- The letterhead and reference line, which can carry your name and a patient number.
- Free-text mentions. A name can appear mid-sentence in the body, not just in the fields.
- Dates woven into the narrative ("seen on 4 March following..."), not only in the date field.
This is exactly where automatic detection earns its place, and where you still have to review every page yourself.
Don't upload health data to redact it
The warning that applies to bank statements and ID is sharpest here. Health information is special-category data under GDPR and protected under HIPAA. Uploading a medical record to an unknown "redact online" service to hide a few fields creates a copy of protected health information on a server you don't control, which may itself be a breach. Redact it on your own device.
A safe workflow
- Work on your device with a tool that doesn't upload the file.
- Remove, don't cover. A black box over a PDF often leaves the text copyable underneath (see how to redact a PDF properly). It has to be removed. Don't blur (reversible).
- Cover every identifier and its repeats, page headers included.
- Verify. Try to copy the redacted areas; check every page; check the filename.
If you handle records at scale, the professional obligations are covered in what "redacted" has to mean under GDPR and HIPAA. For genuinely sensitive processing, it also helps to use a tool whose AI step runs in a verified private enclave, so the text used to find identifiers isn't sent to someone's general-purpose server, the approach behind Private Redaction.
Private Redaction keeps the file on your device and outputs a record with the identifiers genuinely removed. Auto-detect flags names, dates, record and contact numbers; you review every page and download. Free for documents and PDFs, or as a Chrome extension for a scan or photo of a letter.
Takeaways
- Remove the identifiers, not the clinical content: name, address, dates, MRN/NHS/policy numbers, contact details.
- Watch the repeats: names and record numbers usually sit in every page header.
- Cover isn't enough and blur is reversible; the content has to be removed.
- Don't upload health data to redact it. Use a tool that works on your device.
This is general guidance, not legal or compliance advice. Related: GDPR and HIPAA redaction · how to redact a PDF properly