How to de-identify a message

Last updated: 2026-07-10

The one rule

Say enough to find the conversation, not the patient.

If a colleague could identify the patient without calling you or opening the chart, the message says too much. Everything below is that rule in practice.

Full de-identification is impossible: a message your team can act on is never perfectly anonymous. So the goal is minimisation, not perfection. Send the least identifying detail that still does the job, and let the chart or a phone call carry the rest.

Why removing the name is not enough

Australian privacy law does not ask whether you typed a name. It asks whether the person is reasonably identifiable from what you sent, combined with what your reader already knows.

Your colleagues have the theatre list. So "the third case in theatre 3 this morning, entered PACU at 11:30am" identifies the patient just as precisely as a name would. Time, place and list position together are an identity to anyone with the roster. Swapping one identifier for three is not de-identification.

The five steps

Run these in your head before you send:

  1. Strip every direct identifier. No name or initials, date of birth, Medicare, IHI or UR number, address, phone number, or photo of a face, name band or paperwork. These belong in the medical record only.
  2. Reduce to one locator. Give your colleague the least context they need to know where to look ("my patient in PACU", "this morning's list"). Do not stack case number plus theatre plus arrival time.
  3. Keep the clinical detail generic. Send the request, not the diagnosis. "Cardiology review needed" rather than "ischaemic chest pain, known 3-vessel disease".
  4. Add one pointer. Say where the real detail lives: "details in the chart", or "call me for handover".
  5. Run the self-check. If this message leaked, could a stranger with the theatre list know who you mean, and what is wrong with them? If yes to both, trim it.

Before and after

Over-specified. Three locators stacked, plus the diagnosis:

Need a cardiology review for the third case on the list in theatre 3 from this morning, entered PACU at 11:30am, new AF with rapid rate.

Minimised. One locator, one pointer:

Are you free for a cardiology review when available? My patient in PACU from this morning's list. Details in the chart, or call me.

The minimised version is still instantly resolvable by your team, which is the point. It just does not describe a person to anyone else, and it stops being resolvable at all within days. It also drops the case number, which was fragile anyway: list order changes when admissions get reshuffled, but the chart does not. Never reference a patient by list position.

Why this protects you

Every extra detail is pure liability sitting in the record with zero added clinical value. Minimised messages mean that even in a worst case, a lost phone, a screenshot or a breach, there is little to reconstruct. What is not sent cannot leak.

Synapse Chat is a communication tool, not a clinical record. Anything clinically important still belongs in the patient's medical record: the message is a pointer, the chart is the content. See also De-identified by default.

Frequently asked

What is the one rule for de-identifying a message?

Say enough to find the conversation, not the patient. If a colleague could identify the patient without calling you or opening the chart, the message says too much.

What is "one locator, one pointer"?

A locator is just enough context for your colleague to know where to look, such as "my patient in PACU". A pointer is where the real detail lives, such as "details in the chart, or call me". One of each is usually all a message needs.

Is it possible to fully de-identify a clinical message?

No. A message your colleague can still act on is never perfectly anonymous, and one that is perfectly anonymous is clinically useless. The goal is minimisation, not perfection: send the least identifying detail that still does the job.