HIPAA-friendly image redaction
HIPAA's Privacy Rule requires that protected health information (PHI) be stripped or de-identified before sharing for non-treatment purposes. Redacted helps you cover the obvious identifiers in a medical screenshot or scan without sending it anywhere.
The 18 HIPAA identifiers, briefly
HIPAA lists 18 categories of identifying information that must be removed for "Safe Harbor" de-identification. Redacted helps with the most visible ones:
- Names
- Addresses smaller than state level (street, city, postcode)
- Telephone and fax numbers
- Email addresses
- Social Security numbers
- Account and medical record numbers (when labelled)
- IP addresses
It does not, on its own, handle every category — biometric identifiers, photographs, and unique identifying characteristics often need manual review.
How to redact PHI in an image
- Drop or paste the medical image into Redacted.
- Click Detect text for the auto pass.
- Manually mask anything the detector didn't catch: dates, internal IDs, badge photos, MRZ lines.
- Use black-box masking on text — pixelation and blur can sometimes be partially recovered.
- Download the cleaned image.
Important: this is a tool, not a compliance product
Redacted is an in-browser editor. It's appropriate for:
- One-off sanitising of an image before pasting into a non-clinical chat
- Personal sharing of medical context with a friend, advisor, or forum
It is not a substitute for your organisation's HIPAA-compliant document handling, audit trails, or BAA-covered processors. Treat this as the "before" step in a manual workflow, not as a regulated pipeline.
Privacy
The image, the OCR result, and the PII detection all stay in your browser. There is no upload and no third-party request.
FAQ
Is Redacted HIPAA-compliant?
HIPAA compliance is a property of an organisation's overall workflow, not a single tool. Redacted does not move PHI to a server, which simplifies your local handling — but you're still responsible for what you do with the redacted output.
Are dates of birth detected?
Date detection is hit-or-miss. Always review and add a manual mask if needed.
Can I redact a hospital wristband photo?
Yes. Use a manual mask over the barcode and printed text.