Strip PHI from DICOM studies without touching a command line.
Five DICOM PS3.15 profiles, a visual tag inspector, and a signed audit trail for every run. Built for the people who actually have to hand over a de-identified dataset by Friday.
One-time payment · perpetual licence · 30-day money-back guarantee
7-day trial, up to 50 files. No account, no credit card, no upload.
| Tag | Element | Before | After |
|---|---|---|---|
| (0010,0010) | PatientName | DOE^JANE^^^ | removed |
| (0010,0020) | PatientID | MRN-4471928 | ANON-0001 |
| (0008,0020) | StudyDate | 20260114 | 20251203 |
| (0008,0090) | ReferringPhysician | SMITH^ROBERT | removed |
| (0008,0080) | InstitutionName | ST MARY’S IMAGING | removed |
| (0008,1030) | StudyDescription | CHEST CT — J. DOE F/U | removed |
| (0020,000D) | StudyInstanceUID | 1.2.840.…4471.3 | 2.25.8817…0642 |
| (7FE0,0010) | PixelData | 2.4 MB | flagged for review |
Dates shifted by −42 days, so intervals between studies survive. UIDs remapped consistently across the batch, so the study stays intact.
What it does
Everything a de-identification run needs, and nothing that gets in the way.
Finds DICOM anywhere
Files are identified by their DICOM signature, not their extension. Folders full of extensionless exports are picked up without renaming a thing.
See it before you run it
Load any file into the tag inspector and see exactly which elements a profile removes, replaces or keeps — before you commit a whole batch.
Studies stay whole
Study, series and instance UIDs are remapped consistently across the entire batch. Files from one study remain linked after anonymisation.
Dates without dates
Shift every date by a fixed offset. Real dates are gone; the interval between a baseline and a follow-up is preserved for longitudinal work.
Originals are untouchable
Output always goes to a separate folder. The tool has no code path that writes to your source files. Nothing to undo, nothing to restore.
An audit trail that holds up
Every run writes a CSV log of what changed, tag by tag — with PHI masked inside the log itself, so the audit record is not a new disclosure risk.
Your rules, when the standard is not enough
Build custom profiles with your own tag rules, save them, and reuse them across projects and colleagues.
Nothing leaves the machine
No cloud, no upload, no telemetry. Images are read and written locally. The only network call the software ever makes is to check your licence.
Works offline after activation
Activate once with an internet connection. After that it runs on isolated clinical and research networks indefinitely.
Profiles
Five standard profiles from DICOM PS3.15 Annex E.
Pick the one that matches your release agreement. Start with Basic if you are not sure — it is the baseline the others modify.
| Profile | What it does |
|---|---|
| Basic | PS3.15 Table E.1-1 baseline. Removes or empties every PHI-bearing tag. |
| Retain Long | Basic, but keeps dates, times and ages — for longitudinal studies where the interval carries the meaning. |
| Retain Patient | Basic, but keeps sex, age, size and weight — for clinical research that needs the demographics. |
| Clean Descriptors | Additionally strips free-text fields — study and series descriptions, comments, history — where dictated PHI hides. |
| Clean Graphics | Additionally strips structured report content and graphic annotations that may carry PHI. |
Read this before you buy
What this software does not do.
Burned-in pixel text is detected, not erased.
Ultrasound frames, secondary captures and screenshots often carry patient details burned directly into the image pixels. DICOM Anonymizer Pro flags images that likely contain such text and reports them at the end of a run — but it does not redact pixels. Flagged files need a human review, and redaction by other means, before release.
Treat the warning as advisory. It can miss burned-in text and it can flag images that contain none. Header de-identification is thorough and deterministic; pixel detection is a heuristic, and we would rather you knew that now than found out later.
The software does not certify your output as compliant. Responsibility for meeting HIPAA, GDPR and your institution’s own requirements stays with you.
Pricing
One licence, one machine, no subscription.
$69
per machine · one-time
- Perpetual licence for version 1.x — it keeps working, forever, offline.
- All five standard profiles plus the custom rule editor.
- Free updates within version 1.
- Email support from the people who wrote it.
- Activate on a new machine if you replace your workstation — just ask.
Trial runs 7 days or 50 files, whichever comes first. Your licence key arrives by email within minutes of payment and activates from inside the application.
Paddle.com Market Ltd is the merchant of record for this order and handles payment, tax and invoicing. Prices are shown in your local currency at checkout and any applicable VAT or sales tax is added there — the total is shown before you confirm. No subscription, no auto-renewal.
Requirements
Specifications
- Operating system
- Windows 10 version 1809 or later, Windows 11, Windows Server 2019 / 2022 / 2025. 64-bit only.
- Not supported
- Windows Server 2016 and earlier, Windows 8.1 and earlier, 32-bit Windows, Server Core.
- Install
- Per-user installer, no administrator rights required. Approximately 160 MB on disk.
- Standards
- DICOM PS3.15 Annex E de-identification profiles. Reads and writes standard Part 10 files.
- Network
- Internet required once, to activate. Offline thereafter. No image data is ever transmitted.
- Licence key format
- MAJW-XXXX-XXXX-XXXX-XXXX