FHIR Anonymizer
Redact names, identifiers, contact details, birth dates and narrative from a FHIR sample in your browser before sharing it. Explains what it does not remove.
- Redact names, identifiers, addresses, telecom, birth dates and narrative from FHIR samples.
- Meant for scrubbing examples before sharing them, not for preparing research datasets.
How to use the Anonymizer
- Paste a FHIR resource or Bundle, drop a
.jsonfile, or load the sample. - Click Anonymize. The output shows the scrubbed JSON and how many values were redacted.
- Copy or download the result, or open it in another tool with Open result with….
Processing happens in your browser. Your data isn't uploaded.
What it removes
Wherever these element names appear, at any depth and in any resource, their value is replaced with the string "[REDACTED]":
| Element | Typical content |
|---|---|
name | Patient, practitioner and contact names |
telecom | Phone numbers, email addresses |
address | Street, city, postal code |
birthDate, deceasedDateTime | Dates of birth and death |
identifier | MRNs, SSNs, insurance member numbers |
photo | Embedded images |
contact | Next of kin and emergency contacts |
communication | Language preferences |
text | Narrative HTML, which usually repeats demographics |
Worked example
{
"resourceType": "Patient",
"id": "example",
"identifier": [{ "system": "http://hospital.example.org/mrn", "value": "00123456" }],
"name": [{ "family": "Shaw", "given": ["Amy"] }],
"gender": "female",
"birthDate": "1987-02-20"
}
becomes:
{
"resourceType": "Patient",
"id": "example",
"identifier": "[REDACTED]",
"name": "[REDACTED]",
"gender": "female",
"birthDate": "[REDACTED]"
}
What it does not do — read before using real data
This tool is for quickly scrubbing a sample before you paste it into a bug report, a support ticket or a chat. It isn't a de-identification process for research or data release:
- Other dates are kept:
Encounter.period,Observation.effectiveDateTime,Condition.onsetDateTime,meta.lastUpdated. Dates of service are identifiers under HIPAA Safe Harbor. - Resource ids and references are kept. If your system uses the MRN as the Patient id,
Patient/00123456stays in every reference. - Free text is kept apart from narrative
text:note,valueStringandCodeableConcept.textcan contain names. - Attachments, extensions and
fullUrls are kept. - Elements named
textare redacted everywhere, includingCodeableConcept.text(for example the readable name of a diagnosis). - The output isn't valid FHIR, because
name,identifierand the others become strings instead of arrays and objects. Other tools may reject it.
Always review the output before sharing it. For a proper approach, including date shifting, pseudonymized ids and Safe Harbor, read De-identifying FHIR Data.
FAQ
Does using this make my data HIPAA compliant?
No. HIPAA de-identification requires either removing all 18 Safe Harbor identifier types, including dates and identifying numbers this tool doesn't touch, or a documented Expert Determination. This tool reduces obvious identifiers in a sample, nothing more.
Is my data sent anywhere?
No. The redaction runs in JavaScript in this page and nothing is uploaded.
Which FHIR versions does it work with?
All of them. It works on element names, which are the same for these identifying elements in R4, R4B and R5, so any version's JSON is handled the same way.
How do I de-identify data for research instead?
Use a pipeline tool with configurable rules, such as Microsoft's open-source FHIR Tools for Anonymization, and decide on Safe Harbor or Expert Determination first. De-identifying FHIR Data walks through dates, references, free text and pseudonymization.
FHIR Toolbox is a free collection of HL7 FHIR tools by Omindra Labs. The tools process your data in your browser; it is not uploaded for normal tool operations.