For healthcare

Patient documents, de-identified before they travel

Hospitals and diagnostics collect Aadhaar for registration and insurance, then attach it to records that move to insurers, TPAs, referral partners and research datasets. Here the driver is not KYC compliance — it is that a medical record tied to a national identifier is about the most sensitive object in Indian data protection.

Talk to our technical team → — for integration questions, a security review or a volume estimate.

Where patient documents go

Insurance claims
Discharge summaries and bills sent to an insurer or TPA, with the registration Aadhaar attached.
Referrals
Reports forwarded to another hospital or a specialist, frequently by email.
Research and analytics
Datasets built from records where de-identification was assumed rather than performed.
Patient copies
Documents handed back, then shared onward by the patient with whoever asks.

What we do and do not do here

Being precise about the boundary is the point. A vendor that claims full anonymisation of medical records from pattern matching is describing something that does not work, and you would find that out on your own data.

Registration is where the identifier enters the record

A hospital rarely needs an Aadhaar number clinically. It collects one at registration — for insurance, for a government scheme, or simply because the form has a field — and from that moment it is attached to a medical record that will travel.

Registration desk
The card is photographed or scanned and attached to the patient file, often at speed and without anyone deciding it should be permanent.
The HIS
Once attached, it is in every subsequent visit's record, every discharge summary export and every backup.
Scheme claims
Government and insurance claims require identity evidence, so the document is attached again to an outbound submission.
Diagnostics partners
Referred tests carry patient identity to a separate organisation with its own systems and retention.
Redacting at registration means the identifier is verified, used for the claim, and not carried through the clinical record for the next decade.

Health-tech platforms have a harder version of this

Be precise about what this does. It removes identity and financial identifiers, reliably. It does not remove patient names, and it does not touch clinical content. If your protocol needs full anonymisation, this is one component of it, not the whole.

Questions we get asked

Can you de-identify medical records for research?

Partially, and it is worth being exact about which part. We remove identity and financial identifiers reliably — Aadhaar, PAN, phone, email and the rest. We do not remove patient names, and we do not touch clinical content. If your protocol requires full anonymisation including names, this is one component of that, not the whole of it.

Is patient data stored on your servers?

No document is ever written to disk. It is processed in memory for the duration of the request and released. The only record kept is metadata: which key, which endpoint, file type, size, duration, count and status code.

Where is it processed?

AWS ap-south-1, Mumbai. Nothing crosses an international border.

Do you need the document type to redact a medical record?

No, and that is the point. Patient uploads are unstructured — a photographed prescription, a PDF report, a hospital bill. Redaction matches identifiers rather than recognising layouts, so there is no per-document-type work.

Can we use this to build a research dataset?

As one component. It removes identity and financial identifiers reliably. It does not remove names and does not touch clinical content, so it is not full anonymisation on its own — and we would rather say so than let you find out during an ethics review.

Related

Talk to us about your document volume

Tell us how many documents a month you process and what your peak looks like. We will size a plan, provision a key with a test quota, and answer a security questionnaire if you need one.