Free DICOM de-identification tools in clinical research: functioning and safety of patient privacy

PurposeTo compare non-commercial DICOM toolkits for their de-identification ability in removing a patient's personal health information (PHI) from a DICOM header.Materials and MethodsTen DICOM toolkits were selected for de-identification tests. Tests were performed by using the system’s default de-identification profile and, subsequently, the tools' best adjusted settings. We aimed to eliminate fifty elements considered to contain identifying patient information. The tools were also examined for their respective methods of customization.ResultsOnly one tool was able to de-identify all required elements with the default setting. Not all of the toolkits provide a customizable de-identification profile. Six tools allowed changes by selecting the provided profiles, giving input through a graphical user interface (GUI) or configuration text file, or providing the appropriate command-line arguments. Using adjusted settings, four of those six toolkits were able to perform full de-identification.ConclusionOnly five tools could properly de-identify the defined DICOM elements, and in four cases, only after careful customization. Therefore, free DICOM toolkits should be used with extreme care to prevent the risk of disclosing PHI, especially when using the default configuration. In case optimal security is required, one of the five toolkits is proposed.Key Points• Free DICOM toolkits should be carefully used to prevent patient identity disclosure.• Each DICOM tool produces its own specific outcomes from the de-identification process.• In case optimal security is required, using one DICOM toolkit is proposed.

[1]  Oleg S. Pianykh What Is DICOM , 2012 .

[2]  Thomas Neubauer,et al.  Improving Patients Privacy with Pseudonymization , 2008, MIE.

[3]  Oleg S. Pianykh,et al.  Digital Imaging and Communications in Medicine (DICOM) , 2017, Radiopaedia.org.

[4]  David A. Clunie,et al.  Image Data Sharing for Biomedical Research—Meeting HIPAA Requirements for De-identification , 2012, Journal of Digital Imaging.

[5]  Matthijs Oudkerk,et al.  Implementation of an anonymisation tool for clinical trials using a clinical trial processor integrated with an existing trial patient data information system , 2011, European Radiology.

[6]  Rita Noumeir,et al.  Pseudonymization of Radiology Data for Research Purposes , 2007, Journal of Digital Imaging.

[7]  Régis Beuscart,et al.  DicomWorks: Software for Reviewing DICOM Studies and Promoting Low-cost Teleradiology , 2007, Journal of Digital Imaging.

[8]  M. Grgic,et al.  Overview of the DICOM standard , 2008, 2008 50th International Symposium ELMAR.

[9]  C. Parisot The DICOM standard , 1995, The International Journal of Cardiac Imaging.

[10]  Paul Nagy,et al.  Mastering DICOM with DVTk , 2007, Journal of Digital Imaging.

[11]  Paul Nagy,et al.  Benefits of Using the DCM4CHE DICOM Archive , 2007, Journal of Digital Imaging.

[12]  J. Wardlaw,et al.  An open source toolkit for medical imaging de-identification , 2010, European Radiology.

[13]  Thomas Neubauer,et al.  A methodology for the pseudonymization of medical data , 2011, Int. J. Medical Informatics.