ISSN-registered · Peer-reviewed · Open Access
JournalsAboutContact
Scientific Writing

The Identifiers Inside the File: De-identifying Clinical Images, DICOM Exports and Scans

DE By Directive Editorial Team, Directive Publications ·9 Sep 2026 ·7 min read
The Identifiers Inside the File: De-identifying Clinical Images, DICOM Exports and Scans

You have consent, you have cropped the photograph so the face is out of frame, and you have exported the CT slice as a JPEG because the DICOM file was too large to email. All three actions are about the picture. The identifier is not in the picture.

A phone photograph carries an EXIF block recording the camera, the capture time and, if location services were on in the ward, the coordinates of the building. A DICOM file carries the patient's name, medical record number, date of birth, accession number and institution in header tags that no crop touches.

A PACS screenshot carries all of that again as pixels burned into a corner, where no metadata scrubber can reach. And a thin-slice head CT can be rendered back into a recognisable face. This post is about the identifiers that survive the crop.

Consent covers permission; it does not clean the file

Consent is covered in our guide to patient consent for case reports and clinical photographs, and everything below assumes you have it. It settles whether you may publish, not what is inside the file.

An identifier hides in three places, and a crop reaches only one

Each layer needs a different action.

LayerExampleWhat removes it
File metadataEXIF GPS tag, DICOM patient name, filenameStrip, then verify in a second tool
Burned-in pixelsCorner overlay, wristband, stamped rulerRe-crop, or replace and flatten
AnatomyHead volume; rare condition plus age plus hospitalPublish one slice, not the volume

Photographs and phone captures carry more than the wound

A photograph from a phone or department camera arrives with EXIF, and often IPTC and XMP too: capture timestamp, camera serial number, device owner's name, and GPS coordinates precise enough to name the building. The frame matters too: a monitor showing a name, a reflection in glass.

DICOM headers carry identity, and "anonymise" means different things in different viewers

A DICOM file is a header plus pixels, and the header is designed to carry identity. Block A below lists the tags by category — categories to check, not an exhaustive list. The authority is the DICOM standard's own Attribute Confidentiality Profiles (PS3.15, Annex E), which also cover vendors' private tags.

The trap is the word "anonymise". In one viewer it rewrites the tags in the exported file. In another it only stops displaying them on screen, and the tags stay in the file you email. Builds and versions of one product differ over private tags.

Screenshots and secondary captures are the worst case

Exporting a DICOM as a JPEG, photographing a reporting monitor, or capturing a PACS window does not carry the DICOM header across. That is not the same as a clean file: the new file has metadata of its own, which the exporting or capturing software may populate, so it goes through Block A like any other image.

It also turns every identifier on screen into ordinary pixels — the demographics bar, the patient banner, the accession number behind it — which no metadata tool finds.

Burned-in annotation: the overlay, the ruler and the banner

Modalities burn text into the image data with no screenshot involved. Ultrasound and endoscopy systems stamp a banner with patient and operator details, reporting workstations write demographics into a corner, and rulers carry a printed department name. A whole-slide scan can carry the slide label and its accession number as an associated image.

Read every edge of every panel at full magnification. Text illegible in a thumbnail can be legible at full size in the published PDF.

Volumetric head and face imaging can be rendered back into a face

Where the image is a volume rather than a slice — head CT, facial MRI, cone-beam dental imaging — the anatomy is itself an identifier. Published work has demonstrated this for MRI: Schwarz and colleagues, in the New England Journal of Medicine in 2019, surface-rendered research MRI head volumes and matched them to photographs of the same participants using face-recognition software. The demonstration is in MRI, but surface rendering is an ordinary reconstruction on a volumetric CT, so treat any head or face volume the same way.

Attach no probability to that. It does not mean every head study is identifiable, and it does not mean none is. For a case report, publish the slice that supports your point, not the volume.

Do not paint a black box over a name and call it removed

Two approaches look like removal and are not. The first is a box drawn in a viewer, or in a layered file saved with its layers intact: it is a separate object above the name, and anyone can move it. The second is the reflex to clone, heal or content-aware fill over the region, which crosses into image manipulation — the boundary is set out in our guide to image integrity in research.

Removal means a re-crop that puts the region outside the frame, or an opaque block flattened into the file.

What we do not do: we do not inspect your image metadata

Our pre-review check confirms that a submission is complete, in scope, and consistent with our formatting and reporting requirements. It does not include opening your image files and reading their headers. Nobody in the editorial office strips EXIF on ingest, runs a de-identification tool over your figures, or checks your panels for burned-in annotation.

If an identifier is in a file you send us, we are not the ones who will find it. This one is yours to close. What your jurisdiction requires is a question for your institution; the checklist below is about what makes a patient identifiable to a reader.

Run this check on every file after editing, not before

Run it once per image, after all cropping, resizing, labelling and export are finished; anything done afterwards can reintroduce what the check removed.

Block A — what is in the file

  • Photographs, scans, and any file exported or captured from a viewer. Strip EXIF, IPTC and XMP, including GPS coordinates, camera or phone serial number, device owner name, editing history and capture timestamp. Confirm by re-opening the exported file, not the original, and reading its metadata in something that shows the EXIF, IPTC and XMP blocks — a file manager's properties panel shows only part of what is stored, so an empty panel proves nothing.
  • DICOM. Confirm the identity-bearing tags are removed or replaced in the file itself, not merely hidden by the viewer. Categories to check: patient name; patient ID and other patient IDs; birth date; accession number; study and series description free text; institution name and address; referring and performing physician; station name; device serial number; private tags; and the study date where it narrows identification. These are categories, not a complete list.
  • Any file. Rename it. IMG_MRN4471.jpg identifies a patient in the filename alone, and filenames travel with the attachment.

Block B — what is in the pixels

  • Burned-in demographics in a corner or a banner: name, ID, date of birth, study date, operator.
  • A name, ID or barcode visible on a monitor, wristband, drape, chart, requisition or specimen pot.
  • Rulers or scale bars printed with a department, hospital or manufacturer name.
  • Ultrasound, endoscopy and fluoroscopy overlay banners.
  • Pathology slide labels and accession stickers, including the label image inside a whole-slide file.
  • Tattoos, jewellery, distinctive scars, and background features identifying a person or a place.

Action for every item in Block B: re-crop and re-export, or replace the region and flatten the file. Never draw a box on a movable layer or rely on a viewer's annotation tool. Declare any obscured region in the legend.

Block C — what is in the anatomy

  • Volumetric head, face or dental imaging that can be surface-rendered.
  • Unique anatomy, or an implant carrying a traceable serial number.
  • A rare condition, plus a stated age, plus a named institution — together identifying a person even from a technically perfect file.

Action for Block C: publish the single slice or cropped region rather than the volume, and widen the age band or omit the institution where the combination is narrow. Where an image cannot be de-identified there are two honest options and no third: explicit consent to publish an identifiable image, disclosed as our consent guide sets out, or not publishing it.

Verify, do not assume

1. Strip the metadata and export the file you intend to submit.

2. Re-open that exported file in a different tool from the one you used, and read its metadata.

3. If an identifier is still there, the export setting did not do what its label said: metadata stripping on save is a property of that tool and that version, not of the format.

The wider principles sit in our Research Integrity policy. See also our guides to writing a case report, preparing figures and tables and preparing supplementary materials; the same check applies to anything you upload.

Frequently Asked Questions

I cropped the patient's face out of the photograph. Is that enough to de-identify it?
No. A crop changes only what is visible in the frame, and it leaves the file's metadata untouched, so EXIF, IPTC and XMP blocks with the capture time, device serial number and GPS coordinates all survive it. It also does nothing about identifiers elsewhere in the remaining frame, such as a wristband, a requisition, a monitor showing a name, or a distinctive tattoo or scar. Run the file-level check after cropping, not instead of it.
Does exporting a DICOM file as a JPEG or PNG remove the patient's details?
The DICOM header does not travel with the export, so the tags holding the name, ID, birth date and accession number are not in the new file. It does not touch anything that was displayed as pixels, which is why a screen capture or a monitor photograph is the worst case: the demographics bar and the patient banner become part of the picture, and no metadata tool will find them. The exported file also acquires its own metadata, which the exporting software may populate, so it still needs checking. Read every edge of the image at full magnification before you submit it.
Can a head CT identify a patient even without a name in the file?
It can. Published work has demonstrated that volumetric head imaging can be surface-rendered into a recognisable face: Schwarz and colleagues, writing in the New England Journal of Medicine in 2019, matched rendered research MRI volumes to photographs of the same participants using face-recognition software. That does not mean every head study is identifiable, and it does not mean none is. For a case report the practical answer is to publish the single slice or cropped region that supports your point rather than the whole volume.
Is it acceptable to cover a name in the image with a black rectangle?
Only if the covering is permanent. A box drawn in a viewer, or in a layered file saved with its layers intact, is a separate object sitting above the name and anyone can move it aside. Either re-crop so the region falls outside the frame, or place an opaque block over it and flatten the file to a single layer before export, then state in the figure legend that a region has been obscured. Do not clone, heal or content-aware fill over the region, because that crosses from de-identification into image manipulation.
DE
Directive Editorial Team
Directive Publications

The editorial team at Directive Publications — an international open-access publisher of peer-reviewed medical and scientific journals.

Publishing your research?

Directive Publications is an open-access publisher — every article peer-reviewed, Crossref-registered, and free to read under CC BY 4.0.

Submit a manuscript →Read our Scientific Writing policy →