You have consent, you have cropped the photograph so the face is out of frame, and you have exported the CT slice as a JPEG because the DICOM file was too large to email. All three actions are about the picture. The identifier is not in the picture.
A phone photograph carries an EXIF block recording the camera, the capture time and, if location services were on in the ward, the coordinates of the building. A DICOM file carries the patient's name, medical record number, date of birth, accession number and institution in header tags that no crop touches.
A PACS screenshot carries all of that again as pixels burned into a corner, where no metadata scrubber can reach. And a thin-slice head CT can be rendered back into a recognisable face. This post is about the identifiers that survive the crop.
Consent covers permission; it does not clean the file
Consent is covered in our guide to patient consent for case reports and clinical photographs, and everything below assumes you have it. It settles whether you may publish, not what is inside the file.
An identifier hides in three places, and a crop reaches only one
Each layer needs a different action.
| Layer | Example | What removes it |
|---|---|---|
| File metadata | EXIF GPS tag, DICOM patient name, filename | Strip, then verify in a second tool |
| Burned-in pixels | Corner overlay, wristband, stamped ruler | Re-crop, or replace and flatten |
| Anatomy | Head volume; rare condition plus age plus hospital | Publish one slice, not the volume |
Photographs and phone captures carry more than the wound
A photograph from a phone or department camera arrives with EXIF, and often IPTC and XMP too: capture timestamp, camera serial number, device owner's name, and GPS coordinates precise enough to name the building. The frame matters too: a monitor showing a name, a reflection in glass.
DICOM headers carry identity, and "anonymise" means different things in different viewers
A DICOM file is a header plus pixels, and the header is designed to carry identity. Block A below lists the tags by category — categories to check, not an exhaustive list. The authority is the DICOM standard's own Attribute Confidentiality Profiles (PS3.15, Annex E), which also cover vendors' private tags.
The trap is the word "anonymise". In one viewer it rewrites the tags in the exported file. In another it only stops displaying them on screen, and the tags stay in the file you email. Builds and versions of one product differ over private tags.
Screenshots and secondary captures are the worst case
Exporting a DICOM as a JPEG, photographing a reporting monitor, or capturing a PACS window does not carry the DICOM header across. That is not the same as a clean file: the new file has metadata of its own, which the exporting or capturing software may populate, so it goes through Block A like any other image.
It also turns every identifier on screen into ordinary pixels — the demographics bar, the patient banner, the accession number behind it — which no metadata tool finds.
Burned-in annotation: the overlay, the ruler and the banner
Modalities burn text into the image data with no screenshot involved. Ultrasound and endoscopy systems stamp a banner with patient and operator details, reporting workstations write demographics into a corner, and rulers carry a printed department name. A whole-slide scan can carry the slide label and its accession number as an associated image.
Read every edge of every panel at full magnification. Text illegible in a thumbnail can be legible at full size in the published PDF.
Volumetric head and face imaging can be rendered back into a face
Where the image is a volume rather than a slice — head CT, facial MRI, cone-beam dental imaging — the anatomy is itself an identifier. Published work has demonstrated this for MRI: Schwarz and colleagues, in the New England Journal of Medicine in 2019, surface-rendered research MRI head volumes and matched them to photographs of the same participants using face-recognition software. The demonstration is in MRI, but surface rendering is an ordinary reconstruction on a volumetric CT, so treat any head or face volume the same way.
Attach no probability to that. It does not mean every head study is identifiable, and it does not mean none is. For a case report, publish the slice that supports your point, not the volume.
Do not paint a black box over a name and call it removed
Two approaches look like removal and are not. The first is a box drawn in a viewer, or in a layered file saved with its layers intact: it is a separate object above the name, and anyone can move it. The second is the reflex to clone, heal or content-aware fill over the region, which crosses into image manipulation — the boundary is set out in our guide to image integrity in research.
Removal means a re-crop that puts the region outside the frame, or an opaque block flattened into the file.
What we do not do: we do not inspect your image metadata
Our pre-review check confirms that a submission is complete, in scope, and consistent with our formatting and reporting requirements. It does not include opening your image files and reading their headers. Nobody in the editorial office strips EXIF on ingest, runs a de-identification tool over your figures, or checks your panels for burned-in annotation.
If an identifier is in a file you send us, we are not the ones who will find it. This one is yours to close. What your jurisdiction requires is a question for your institution; the checklist below is about what makes a patient identifiable to a reader.
Run this check on every file after editing, not before
Run it once per image, after all cropping, resizing, labelling and export are finished; anything done afterwards can reintroduce what the check removed.
Block A — what is in the file
- Photographs, scans, and any file exported or captured from a viewer. Strip EXIF, IPTC and XMP, including GPS coordinates, camera or phone serial number, device owner name, editing history and capture timestamp. Confirm by re-opening the exported file, not the original, and reading its metadata in something that shows the EXIF, IPTC and XMP blocks — a file manager's properties panel shows only part of what is stored, so an empty panel proves nothing.
- DICOM. Confirm the identity-bearing tags are removed or replaced in the file itself, not merely hidden by the viewer. Categories to check: patient name; patient ID and other patient IDs; birth date; accession number; study and series description free text; institution name and address; referring and performing physician; station name; device serial number; private tags; and the study date where it narrows identification. These are categories, not a complete list.
- Any file. Rename it. IMG_MRN4471.jpg identifies a patient in the filename alone, and filenames travel with the attachment.
Block B — what is in the pixels
- Burned-in demographics in a corner or a banner: name, ID, date of birth, study date, operator.
- A name, ID or barcode visible on a monitor, wristband, drape, chart, requisition or specimen pot.
- Rulers or scale bars printed with a department, hospital or manufacturer name.
- Ultrasound, endoscopy and fluoroscopy overlay banners.
- Pathology slide labels and accession stickers, including the label image inside a whole-slide file.
- Tattoos, jewellery, distinctive scars, and background features identifying a person or a place.
Action for every item in Block B: re-crop and re-export, or replace the region and flatten the file. Never draw a box on a movable layer or rely on a viewer's annotation tool. Declare any obscured region in the legend.
Block C — what is in the anatomy
- Volumetric head, face or dental imaging that can be surface-rendered.
- Unique anatomy, or an implant carrying a traceable serial number.
- A rare condition, plus a stated age, plus a named institution — together identifying a person even from a technically perfect file.
Action for Block C: publish the single slice or cropped region rather than the volume, and widen the age band or omit the institution where the combination is narrow. Where an image cannot be de-identified there are two honest options and no third: explicit consent to publish an identifiable image, disclosed as our consent guide sets out, or not publishing it.
Verify, do not assume
1. Strip the metadata and export the file you intend to submit.
2. Re-open that exported file in a different tool from the one you used, and read its metadata.
3. If an identifier is still there, the export setting did not do what its label said: metadata stripping on save is a property of that tool and that version, not of the format.
The wider principles sit in our Research Integrity policy. See also our guides to writing a case report, preparing figures and tables and preparing supplementary materials; the same check applies to anything you upload.