Anonymization

Date jitter (preserve intervals)

Shift every DICOM date by one offset so the intervals between studies survive de-identification.

Date shifting moves every date in a DICOM file by the same number of days. The calendar dates no longer match the real ones, but the gap between a baseline scan and a follow-up stays exactly the same. Research protocols use it when an analysis needs real intervals, such as time to response or time between treatments, and the real dates would identify the patient. DICOM PS3.15 calls this the Retain Longitudinal Temporal Information with Modified Dates option.

Problem

A patient has a baseline scan and a follow-up 30 days later. The HIPAA and Teaching profiles replace every date with the dummy value 19000101, so after de-identification both scans carry the same date and the 30-day interval is gone. You want every date moved by one offset instead, so the interval survives.

What dcmage shifts

The shift applies to every DA value and to the date part of every DT value in the file, including values inside sequences and in multi-value elements. It starts from the original value and takes the place of the profile’s dummy date.

  • Patient Birth Date moves with the other dates, so the patient’s age at each scan stays correct.
  • In a DT value, the time and any timezone offset after YYYYMMDD stay as they are.
  • TM values keep their original time of day.
  • Tags the profile removes, such as Death Date, stay removed.
  • Partial dates (YYYY or YYYYMM) and invalid values are left unchanged. Check them in the tag tree before you export.

Choose the offset

Type a whole number of days into the date shift field. A positive number moves dates forward and a negative number moves them back. An empty field counts as 0, which means no shift.

Or click Auto. dcmage then derives the offset from the file’s Patient ID (0010,0020) with HMAC-SHA-256, keyed by a random secret that is created once per installation. The result is between 1 and 365 days, forward or back, and is never 0. If the file has no Patient ID, Auto uses the file name.

Auto gives the same offset for the same Patient ID, so a patient’s studies stay consistent even when you de-identify them one file at a time. That holds under two conditions:

  1. You use the same installation. The secret is stored locally by the browser or the Mac app. Another computer, another browser, or cleared site data creates a new secret and different offsets.
  2. You click Auto before anything replaces the Patient ID. Auto reads the value that is in the tag tree at that moment. After an earlier Apply has pseudonymized the ID, Auto derives the offset from the new value.

dcmage does not save the offset between sessions and does not write it to the audit log. If you need to document or reverse the shift, record the offset in your study records.

Steps

  1. Open the DICOM file (⌘O).
  2. Switch to Anon mode with the Anon button in the top bar. The shortcut is ⌘3 in the Mac app and ⌘⇧A in the browser.
  3. Choose a confidentiality profile.
  4. In Date shift (preserve intervals), type the number of days or click Auto.
  5. Click Apply to stage the changes, or Apply & Export to write a new de-identified file. The original file does not change.

Test the shift

Check the result before you share the file.

  1. After Apply, shifted rows show as modified in the tag tree. Filter for (0008,0020) and compare the new Study Date with the original.
  2. Open Export → Export DICOM Changes… (⌘E). The pre-export diff lists every Before and After value. Confirm that each date moved by the same number of days, and look for dates that did not move, such as partial dates.
  3. For a longitudinal set, de-identify two studies of the same patient with Auto, load both, and use Compare in the Files tab. The number of days between the two Study Dates should match the original interval.

Retain original dates

The Retain original dates checkbox keeps DA, DT and TM values as they are, but only when the offset is 0. A non-zero offset always wins, and Patient Birth Date is never retained. With the box ticked and the offset at 0, the panel shows a warning and Apply & Export asks you to confirm, because the exported file will still carry the real dates.

Limits

  • De-identification runs on one file at a time. Batch de-identification of a whole cohort is not available.
  • dcmage does not write Longitudinal Temporal Information Modified (0028,0303) or the De-identification Method attributes (0012,0063) and (0012,0064). Add them in the tag editor if the receiving system expects them.
  • Shifting dates is one part of de-identification. The rest of the profile still has to remove names, IDs and other identifiers, and a shifted date can still identify a patient when combined with other data.

Result

Every full date in the file moves by the same number of days, the intervals between studies stay the same, and times of day do not change. With Auto, the same patient gets the same offset on the same installation.

See also Limited dataset with shifted dates and the Anonymize a study guide.