DICOM Anonymization Explained: What Your Scan Files Reveal
Every CT or MRI file carries your name, birth date and more in its header. Learn what DICOM anonymization removes, what it keeps, and how to do it yourself.
Have your own scan or report? Get a clear, plain-language explanation in minutes.
Your scan file is two things at once
When an imaging center hands you a CD, a USB stick or a download link, the folder inside contains dozens or hundreds of files with the .dcm extension. Each of those files is a DICOM object, and each one holds two very different kinds of content. The first is the picture: the pixel data of one slice or one frame of your CT, MRI or X-ray. The second is a header of metadata that describes who was scanned, where, when and how.
The picture rarely identifies anyone. The header identifies you completely. DICOM anonymization (also spelled anonymisation, and called de-identification in the HIPAA context) is the process of removing or replacing that identifying metadata while leaving the diagnostic image untouched.
What personal data a DICOM header actually contains
The header is organised as tags, and the DICOM standard defines which tags may carry personal information. In a typical hospital export you will find:
- Patient identity: full name, patient ID or medical record number, date of birth, sex, sometimes age, weight, height and ethnic group.
- Who ordered and performed the exam: referring physician, performing physician, operator names, the institution's name and address, the scanner's station name.
- When and why: study date and time, accession number, study and series descriptions, requested procedure text, and free-text patient comments.
- Hidden copies: some manufacturers repeat the patient name inside vendor-specific private tags, and some ultrasound and screen-capture images have the name burned into the picture itself.
Our DICOM upload guide walks through these metadata groups in more detail if you want to see what a real file looks like.
Why the header matters more than the image
People share scans for good reasons: a second opinion from another radiologist, a specialist abroad, a research study, a patient forum, or an AI reading service. Every one of those recipients receives the header along with the pixels. Under HIPAA in the United States that header is protected health information (PHI). Under the GDPR in Europe it is health data, one of the special categories that carry the strictest rules.
The practical consequence is simple. A raw DICOM folder posted to a forum, attached to an e-mail or uploaded to an unknown website discloses your name, birth date and hospital to whoever handles it. An anonymized folder does not, and the reader can still see every slice at full diagnostic quality.
Anonymization is not about hiding the scan. It is about separating the medical content, which you want to share, from your identity, which you usually do not need to share.
Anonymization, de-identification and pseudonymization
The three words overlap but mean different things. De-identification is the HIPAA term: remove the eighteen Safe Harbor identifiers (names, all dates except the year, record numbers, device identifiers and so on) and the data stops being PHI. Anonymization is the GDPR term for irreversibly removing any link to the person. Pseudonymization replaces identifiers with a code and keeps a key somewhere; whoever holds the key can restore the identity, so the GDPR still treats pseudonymized data as personal data.
Hospitals running research databases usually pseudonymize, because they need to link scans to outcomes years later. A patient sharing one scan almost always wants plain anonymization: overwrite the tags, keep no key.
How DICOM anonymization works in practice
Overwriting the tags
A DICOM anonymizer opens each file, finds the tags listed in the standard's Basic Application Confidentiality Profile (part PS3.15 of the DICOM standard), and replaces their values. Mandatory tags such as patient name and patient ID receive a neutral placeholder so that strict viewers and PACS systems still accept the file. Optional tags such as physician names or institution address are blanked. The pixel data is never touched.
What a good anonymizer keeps
Some metadata must survive, otherwise the scan becomes unreadable. The study, series and image identifiers keep the slices grouped in the right order. Image position, orientation, pixel spacing and slice thickness allow 3D reconstruction and measurements. Modality, sequence parameters and window settings tell the viewer how to display the image. None of these identify you, and removing them would destroy the diagnostic value.
What it cannot do
Tag anonymization does not erase text that has been rendered into the pixels, which is common on ultrasound stills and secondary captures. It also cannot know about every vendor's private tags. If your files come from an ultrasound machine or contain screenshots, look at the actual images before sharing them, and if in doubt leave those series out.
Doing it yourself in the browser
You do not need hospital software for a single scan. Our free DICOM anonymizer online runs entirely in your browser: you pick the folder, the files are parsed on your own computer, the patient metadata is shown so you can check what will be replaced, and you download a ZIP of the anonymized files with the original folder structure preserved. Nothing is uploaded to a server at any point. The free DICOM viewer built into the same page lets you confirm you picked the right series before you anonymize.
Before you send the anonymized folder anywhere, a quick checklist:
- Open one anonymized file and confirm the name field now shows the placeholder.
- Scroll through ultrasound and screenshot series looking for burned-in text.
- Keep your original folder in a safe place; the anonymized copy is for sharing only.
- Send the written radiology report separately if the recipient needs it, and remove your details from that document too.
If your goal is an independent reading rather than a share with a person, you can upload the original or the anonymized files directly for an AI analysis of your CT or MRI. Our data security page describes how uploaded scans are stored and deleted.
When to talk to your doctor
Anonymization protects your privacy; it does not change what the images show. If you are sharing a scan because a finding worries you, the person best placed to explain it remains the doctor who ordered the exam or the radiologist who read it. Ask them whether comparison with older scans is needed, since anonymized files from different dates can still be matched by the reader as long as you say which is which. This article is general education about medical file formats and privacy law, not medical or legal advice for an individual case.
Get AI-powered analysis of your CT or MRI scan
Upload your DICOM files and receive a clear, patient-friendly report in minutes.
Analyze my scan