Anonymization

Face de-identification (head defacing)

Propose redaction boxes over the face, ears, jaw, and back of the skull on a CT/MR head slice.

Problem

Head CT and MR scans contain facial surface data that can be reconstructed to identify a patient. Metadata anonymization doesn’t address this, because the features are in the pixel data itself. You want a starting set of redaction boxes over the identifiable regions of a head slice, which you then review before export.

Steps

  1. Open your head CT/MR DICOM file (⌘O) and switch to Anon mode (⌘3 in the Mac app, ⌘⇧A in the browser).

  2. Run Auto Deface. In the Redaction regions section, click Auto Deface. It reads the pixel data of the slice shown in the viewport, thresholds the foreground to estimate the head’s bounding box, and uses Patient Orientation (0020,0020) to find the anterior side. If the modality is not CT or MR, a confirmation prompt asks before it runs. Floating-point pixel data is refused with an error.

  3. Review the proposals. Five boxes are added to the list, which shows them as numbered regions:

    • the face (anterior band of the head)
    • the left ear
    • the right ear
    • the jaw and dental arch (a wider anterior band)
    • the back of the skull (posterior band)

    With no other regions drawn, the heading reads Redaction regions (5). Proposed boxes can be deleted but not moved or resized. Draw extra boxes with the redact tool where coverage is short.

  4. Apply & Export. Click Apply & Export. The exported file is the active instance, anonymized with the selected profile, with the pixels inside every box set to zero. In a multi-frame file the boxes are zeroed in every frame; other files of the series are not exported.

Result

The exported instance has black rectangles at the proposed positions. The boxes come from one slice and a fixed geometric heuristic. They are not a segmentation of the face, and they do not cover other slices of a series stored one slice per file. Review them against your data before you export.