Doctify Local Assistant › De-identification De-identification

Patient identifiers removed on your computer

Before a search leaves your computer, Doctify strips names, dates, numbers and addresses locally, with a published de-identification model and rules. Then you check it.

Get early access

Free to join · No payment today

Example · sample data

Before Identifiers found
Emma ClarkeName was seen on 2 June 2025Date with chest pain. Lives at 12 Elm Road, SpringfieldAddress. MRN 4417-208MRN, phone 555-0142Phone.
NameDate → yearPhoneMRNAddress
After Ready for your review
[NAME] was seen in 2025 with chest pain. Lives at [ADDRESS]. MRN [ID], phone [PHONE].

You read and can edit this text before anything is searched.

Stanford AIMI model + Safe Harbor rules · on this computer

A published model, running locally

Doctify uses the Stanford AIMI de-identification model (stanford-deidentifier-base), described in Chambon PJ, Wu C, Steinkamp JM, Adleberg J, Cook TS, Langlotz CP. Automated deidentification of radiology reports combining transformer and “hide in plain sight” rule-based methods. J Am Med Inform Assoc. 2022. doi:10.1093/jamia/ocac219.

The model runs on your computer. It is downloaded once (about 110 MB, from Hugging Face); your notes are not part of that download. Until the model is ready, Doctify tells you and uses the rules alone.

Plus rules for what models miss

Alongside the model, rules follow the identifier categories of the HIPAA Safe Harbor list: names, phone and fax numbers, email addresses, record and ID numbers, addresses and postcodes, and dates. Some are removed, others generalised: a full date becomes its year, and an age over 89 becomes “90+”.

Following that list is not a guarantee. Automatic removal can miss something, which is why you always see, and can edit, the text before it is sent.

Where it is used

De-identification protects the one feature that sends clinical text by design: evidence search. It is included in Doctify Local Assistant at no extra cost. Read what else does and does not leave your computer on the privacy page.

How it works

De-identify, review, then send

  1. Pick text to searchA question or one or more of your notes.
  2. Model and rules run locallyIdentifiers are found and removed on your computer.
  3. You reviewThe de-identified text is shown and can be edited.
  4. Only then, sendNothing leaves until you click, and only to PubMed.
[ FAQ ]

Frequently asked
questions

Something else on your mind? Request early access and reply to our first email.

The Stanford AIMI de-identification model (stanford-deidentifier-base), published by Chambon et al. in JAMIA in 2022 (doi:10.1093/jamia/ocac219). It runs on your computer.
Doctify does not certify that. The rules follow the identifiers on the HIPAA Safe Harbor list, but automatic removal can miss something, so you review the text before it is sent.
No. De-identification runs on your computer. Only the model file is downloaded, once.
No. De-identification is included in Doctify Local Assistant.

More of Doctify Local Assistant

Or go back to the Local Assistant overview.

Check the evidence, keep the patient private.

Doctify Local Assistant is in early access. Request access: free, no payment today.