Redacta
Redacta pseudonymises medical documents before AI processing. It detects patient identifiers and replaces them with labelled tokens, preserving clinical meaning while protecting privacy.
How It Works
When a user shares medical text, scan it for patient identifiers and replace them with pseudonymised tokens. The output should be clinically readable but contain no real patient data.
What Gets Detected
Structured Identifiers (regex-based)
Apply these pattern rules automatically:
NHS Numbers (UK)
- Format: 3-3-4 digits (e.g.
943 476 5919) or 10 consecutive digits
- Replace with:
[NHS_NUMBER]
- Validation: check digit using Modulus 11 algorithm when possible
Dates of Birth / Dates
- Formats: DD/MM/YYYY, DD-MM-YYYY, DD.MM.YYYY, YYYY-MM-DD, "3rd February 1985", "Feb 3, 1985"
- Context: dates near keywords like "DOB", "born", "date of birth", "age", "d.o.b"
- Replace with:
[DATE_OF_BIRTH] (when contextually a DOB) or [DATE] (other dates)
- Preserve clinical dates when clearly not patient-identifying (e.g. "appointment on 15 March")
UK Postcodes
- Format: A9 9AA, A99 9AA, A9A 9AA, AA9 9AA, AA99 9AA, AA9A 9AA
- Replace with:
[POSTCODE]
Phone Numbers
- UK formats: 07xxx, 01xxx, 02xxx, +44
- US formats: (xxx) xxx-xxxx, xxx-xxx-xxxx, +1
- Replace with:
[PHONE_NUMBER]
Email Addresses
- Standard email pattern
- Replace with:
[EMAIL]
Hospital / MRN Numbers
- Context: numbers near "hospital number", "MRN", "patient ID", "unit number", "case number"
- Replace with:
[HOSPITAL_NUMBER]
UK National Insurance Numbers
- Format: 2 letters + 6 digits + 1 letter (e.g. AB123456C)
- Replace with:
[NI_NUMBER]
Contextual Identifiers (agent reasoning)
Use your understanding of clinical documents to detect:
Patient Names
- Look for names in: salutations ("Dear Mrs Jones"), headers ("Patient: John Smith"), references in body text
- Distinguish patient names from clinician names — do NOT redact doctor/nurse/consultant names unless explicitly asked
- Replace with:
[PATIENT_NAME]
- If multiple patients mentioned, use:
[PATIENT_NAME_1], [PATIENT_NAME_2]
Patient Addresses
- Full or partial addresses (house number + street, or referenced near "address", "lives at", "resides")
- Replace with:
[ADDRESS]
- Postcodes are handled separately above
Ages
- Specific ages that could identify when combined with other data: "82-year-old", "aged 47"
- Replace with:
[AGE]
- Context matters: "children aged 5-12" (general) vs "a 73-year-old woman" (specific patient)
Output Format
Return two sections:
1. Pseudonymised Document
The full document with all identifiers replaced by tokens. Preserve all formatting, paragraph breaks, and clinical content.
2. Redaction Report
A summary of what was found and replaced:
Redaction Report
================
Items pseudonymised: 7
- [NHS_NUMBER] × 1 (line 3)
- [PATIENT_NAME] × 2 (lines 1, 5)
- [DATE_OF_BIRTH] × 1 (line 2)
- [POSTCODE] × 1 (line 8)
- [PHONE_NUMBER] × 1 (line 9)
- [AGE] × 1 (line 4)
Clinical content preserved: ✓
Clinician names preserved: Dr. Sarah Chen, Mr. James Wright
Rules
- Never output the original patient identifiers in your response — only the pseudonymised version
- Preserve all clinical content — medications, diagnoses, procedures, test results, clinical observations
- Preserve clinician names by default — only redact if the user explicitly asks
- Preserve hospital/practice names by default — these are institutional, not patient data
- When uncertain, err on the side of redacting — false positives are safer than false negatives
- Dates: appointment dates, procedure dates, and follow-up dates should be preserved unless they could identify the patient (e.g. a specific date of birth)
- Consistency: the same identifier should get the same token throughout the document (e.g. every instance of the patient's name becomes
[PATIENT_NAME])
Example
Input:
Dear Mrs Patricia Hartley,
DOB: 14/03/1952 (age 73)
NHS Number: 943 476 5919
Hospital Number: RXH-2847561
I am writing to inform you of the results of your recent investigations.
Mrs Hartley attended the cardiology outpatient clinic on 10 February 2026
under the care of Dr Sarah Chen.
Address: 14 Oakfield Road, Headingley, Leeds LS6 3PJ
Tel: 0113 278 4532
Output:
Dear [PATIENT_NAME],
DOB: [DATE_OF_BIRTH] (age [AGE])
NHS Number: [NHS_NUMBER]
Hospital Number: [HOSPITAL_NUMBER]
I am writing to inform you of the results of your recent investigations.
[PATIENT_NAME] attended the cardiology outpatient clinic on 10 February 2026
under the care of Dr Sarah Chen.
Address: [ADDRESS], [POSTCODE]
Tel: [PHONE_NUMBER]
What This Skill Does NOT Do
- Store or transmit patient data
- Guarantee 100% detection (always review output)
- Replace formal data protection processes
- Provide legal compliance certification
- Process images or PDFs (text input only in v1)
Privacy Note
This skill processes text locally within your AI agent session. No patient data is sent to external services. However, the text is processed by the underlying language model — ensure your model provider's data handling meets your organisation's requirements.
Built by PharmaTools.AI — applied AI for pharma and healthcare.
1---2name: redacta3description: Redacta pseudonymises medical documents — replacing patient identifiers (NHS numbers, dates of birth, postcodes, phone numbers, hospital numbers) with labelled tokens so clinical content can be safely processed by AI. Built by PharmaTools.AI.4---5
6# Redacta
7
8Redacta pseudonymises medical documents before AI processing. It detects patient identifiers and replaces them with labelled tokens, preserving clinical meaning while protecting privacy.
9
10## How It Works
11
12When a user shares medical text, scan it for patient identifiers and replace them with pseudonymised tokens. The output should be clinically readable but contain no real patient data.
13
14## What Gets Detected
15
16### Structured Identifiers (regex-based)
17
18Apply these pattern rules automatically:
19
20**NHS Numbers** (UK)
21- Format: 3-3-4 digits (e.g. `943 476 5919`) or 10 consecutive digits
22- Replace with: `[NHS_NUMBER]`
23- Validation: check digit using Modulus 11 algorithm when possible
24
25**Dates of Birth / Dates**
26- Formats: DD/MM/YYYY, DD-MM-YYYY, DD.MM.YYYY, YYYY-MM-DD, "3rd February 1985", "Feb 3, 1985"
27- Context: dates near keywords like "DOB", "born", "date of birth", "age", "d.o.b"
28- Replace with: `[DATE_OF_BIRTH]` (when contextually a DOB) or `[DATE]` (other dates)
29- Preserve clinical dates when clearly not patient-identifying (e.g. "appointment on 15 March")
30
31**UK Postcodes**
32- Format: A9 9AA, A99 9AA, A9A 9AA, AA9 9AA, AA99 9AA, AA9A 9AA
33- Replace with: `[POSTCODE]`
34
35**Phone Numbers**
36- UK formats: 07xxx, 01xxx, 02xxx, +44
37- US formats: (xxx) xxx-xxxx, xxx-xxx-xxxx, +1
38- Replace with: `[PHONE_NUMBER]`
39
40**Email Addresses**
41- Standard email pattern
42- Replace with: `[EMAIL]`
43
44**Hospital / MRN Numbers**
45- Context: numbers near "hospital number", "MRN", "patient ID", "unit number", "case number"
46- Replace with: `[HOSPITAL_NUMBER]`
47
48**UK National Insurance Numbers**
49- Format: 2 letters + 6 digits + 1 letter (e.g. AB123456C)
50- Replace with: `[NI_NUMBER]`
51
52### Contextual Identifiers (agent reasoning)
53
54Use your understanding of clinical documents to detect:
55
56**Patient Names**
57- Look for names in: salutations ("Dear Mrs Jones"), headers ("Patient: John Smith"), references in body text
58- Distinguish patient names from clinician names — do NOT redact doctor/nurse/consultant names unless explicitly asked
59- Replace with: `[PATIENT_NAME]`
60- If multiple patients mentioned, use: `[PATIENT_NAME_1]`, `[PATIENT_NAME_2]`
61
62**Patient Addresses**
63- Full or partial addresses (house number + street, or referenced near "address", "lives at", "resides")
64- Replace with: `[ADDRESS]`
65- Postcodes are handled separately above
66
67**Ages**
68- Specific ages that could identify when combined with other data: "82-year-old", "aged 47"
69- Replace with: `[AGE]`
70- Context matters: "children aged 5-12" (general) vs "a 73-year-old woman" (specific patient)
71
72## Output Format
73
74Return two sections:
75
76### 1. Pseudonymised Document
77The full document with all identifiers replaced by tokens. Preserve all formatting, paragraph breaks, and clinical content.
78
79### 2. Redaction Report
80A summary of what was found and replaced:
81
82```
83Redaction Report
84================
85Items pseudonymised: 7
86
87- [NHS_NUMBER] × 1 (line 3)
88- [PATIENT_NAME] × 2 (lines 1, 5)
89- [DATE_OF_BIRTH] × 1 (line 2)
90- [POSTCODE] × 1 (line 8)
91- [PHONE_NUMBER] × 1 (line 9)
92- [AGE] × 1 (line 4)
93
94Clinical content preserved: ✓
95Clinician names preserved: Dr. Sarah Chen, Mr. James Wright
96```
97
98## Rules
99
1001. **Never output the original patient identifiers** in your response — only the pseudonymised version
1012. **Preserve all clinical content** — medications, diagnoses, procedures, test results, clinical observations
1023. **Preserve clinician names** by default — only redact if the user explicitly asks
1034. **Preserve hospital/practice names** by default — these are institutional, not patient data
1045. **When uncertain**, err on the side of redacting — false positives are safer than false negatives
1056. **Dates**: appointment dates, procedure dates, and follow-up dates should be preserved unless they could identify the patient (e.g. a specific date of birth)
1067. **Consistency**: the same identifier should get the same token throughout the document (e.g. every instance of the patient's name becomes `[PATIENT_NAME]`)
107
108## Example
109
110**Input:**
111```
112Dear Mrs Patricia Hartley,
113
114DOB: 14/03/1952 (age 73)
115NHS Number: 943 476 5919
116Hospital Number: RXH-2847561
117
118I am writing to inform you of the results of your recent investigations.
119Mrs Hartley attended the cardiology outpatient clinic on 10 February 2026
120under the care of Dr Sarah Chen.
121
122Address: 14 Oakfield Road, Headingley, Leeds LS6 3PJ
123Tel: 0113 278 4532
124```
125
126**Output:**
127```
128Dear [PATIENT_NAME],
129
130DOB: [DATE_OF_BIRTH] (age [AGE])
131NHS Number: [NHS_NUMBER]
132Hospital Number: [HOSPITAL_NUMBER]
133
134I am writing to inform you of the results of your recent investigations.
135[PATIENT_NAME] attended the cardiology outpatient clinic on 10 February 2026
136under the care of Dr Sarah Chen.
137
138Address: [ADDRESS], [POSTCODE]
139Tel: [PHONE_NUMBER]
140```
141
142## What This Skill Does NOT Do
143
144- Store or transmit patient data
145- Guarantee 100% detection (always review output)
146- Replace formal data protection processes
147- Provide legal compliance certification
148- Process images or PDFs (text input only in v1)
149
150## Privacy Note
151
152This skill processes text locally within your AI agent session. No patient data is sent to external services. However, the text is processed by the underlying language model — ensure your model provider's data handling meets your organisation's requirements.
153
154---
155
156Built by [PharmaTools.AI](https://pharmatools.ai) — applied AI for pharma and healthcare.