Pixel Safe info@pixelsafeimaging.com
DICOM de-identification & re-identification

Send studies off-site.
Keep the key in-house.

Research collaborations, AI vendors and outside readers all need your imaging. None of them need your patients. Pixel Safe de-identifies studies on the way out, re-identifies the results on the way back, and never lets the linkage leave your network.

Or point it at a folder and get a de-identified set back. Same engine, one direction, nothing to stand up on the far end.

The round trip

Most tools only go one way.

De-identifying is the easy half. The hard half is getting the results back and knowing which patient they belong to — without ever having shipped that answer out of the building.

01  OUT

De-identify

Headers rewritten, identifiers replaced with per-project pseudonyms. The same patient maps to the same pseudonym on every future study, so a cohort stays a cohort.

02  AWAY

Work happens off-site

The receiving side gets images and nothing else. There is no identity in the payload to leak, subpoena, or lose.

03  BACK

Re-identify on return

Results come home under the pseudonym. Pixel Safe restores the real identity from a mapping that never left your network, and records every delivery.

Starting simpler

Most projects don’t need the round trip.

Plenty of work is one direction only: here is a set of studies, give them back clean. Point Pixel Safe at a folder and that’s what happens — no return leg to design, nothing to stand up on the far end.

It is the same engine either way. The same header rules, the same reading of the pixels, the same re-check of the output before a single study is released. The round trip adds a way home for the results; it doesn’t change what happens to the images. Start with the folder, and the return leg is there when a project needs it.

Burned-in PHI

Some PHI never touches the header.
It’s burned into the pixels.

Ultrasound captures, secondary captures, screen grabs from a modality console — a name rendered into the image itself passes every header check ever written, because there is nothing in the header to find.

Pixel Safe reads the picture. Text found in the pixels is located and blanked, and studies it cannot clear are held rather than released. Blanking by modality and station is available where the layout is known and fixed; where it isn’t, the image is read directly.

Verification

It doesn’t trust its own scrubbing.

Scrubbing is table stakes. Going back and re-reading the output is the part that catches what the scrub missed — so that’s what it does, on every study, before anything is released.

364studies in
29,844images read
322released
4held back
Synthetic validation benchmark. The 4 held were single-image studies with burned-in PHI — the kind that clears every header check. The number worth noticing is not 322. It is 4.
Scope

What it handles.

Stated plainly, so you can tell in a minute whether it fits what you’re trying to do.

HANDLESDICOM studies — headers, private tags, and burned-in pixel text
HANDLESReversible pseudonyms with the mapping held inside your network
HANDLESDICOM objects embedded inside clinical messages, reassembled and identified by their actual bytes
HANDLESDICOM structured reports — narrative text inside the report is scrubbed, then re-read before release
HANDLESVolume work — hundreds of thousands of studies, across multiple processing nodes
Talk to us

Bring one study. See what comes back.

The fastest way to judge this is on your own data, not a slide deck. Send a note and we’ll work out whether it fits what you’re trying to do.

Or write to info@pixelsafeimaging.com directly.