BlurThis

Guide

HIPAA screenshot redaction: cover PHI before you share

By Shaibaz, graphic designer and creator of BlurThis

Practical checklist to black-bar MRNs, DOBs, and names on medical screenshots. Not legal advice. On-device cover before Slack.

Clinic desk laptop with black bars over fake patient-table rows
Illustration by BlurThis

This page is not legal advice, not a HIPAA compliance program, and not a substitute for your privacy office or a business associate agreement. It is a pixel habit for clinic and vendor snips: before a chart, EHR toast, or patient portal capture leaves your laptop, black-bar every name, MRN, date of birth, and address so protected health information is not sitting in Slack pixels.

HHS publishes the Privacy Rule summary and the minimum necessary guidance for covered entities. Those pages are the official starting point if you need the actual rule. What follows is how a screenshot usually fails that instinct in real clinics: someone captures a worklist to show a spinner, and five other patients travel with the PNG. Barring fields is hygiene. It is not a compliance certificate.

Cover PHI on a chart snip before anyone else sees it

UI mockup with private fields coveredOpen larger image in a new tab
  1. Crop to the error or the control that is broken. Drop the worklist rail and the schedule grid if you can.
  2. Duplicate the file. Do not store the unbarred original in a casual channel. Keep it only where your organization already stores ePHI, if you must keep it at all.
  3. Paint opaque black bars over names, MRNs, encounter IDs, dates of birth, addresses, phones, emails, insurance member IDs, and claim numbers.
  4. Cover diagnoses, meds, and lab values if the audience does not need them. Cover provider names next to a patient when the combo identifies care. Cover the browser URL if it contains a patient token.
  5. Zoom to 100%. Export PNG. Send that file. Wait out notification banners, or bar them after the fact. In BlurThis, use Black bar and Download PNG. Soft Blur is for faces in hallway photos, not for readable chart text.
Frosted blur over fake digits next to a solid black bar on a chart snipOpen larger image in a new tab

What you should see in the vendor ticket: a broken button and barred identifiers. What you should not see: a wristband photo with a readable MRN next to a face.

Practical PHI checklist before you share

  • Patient name in headers, tabs, wristband photos, and titles
  • MRN / medical record number, encounter ID, and account numbers
  • Date of birth, age when unique with other fields, and SSN
  • Address, phone, email, and emergency contacts
  • Insurance member IDs and claim numbers
  • Diagnoses, meds, and lab values if the audience does not need them
  • Provider names next to a patient when the combo identifies care
  • Other patients in worklist sidebars and schedule grids
  • Browser URL if it contains patient tokens or portal paths
  • Notification banners that landed mid-capture

Crop to the error or UI bug when you can. When the layout must stay, bar every identifier around it. Support-style checklists for tickets also appear in customer support screenshot redaction. This page stays on health-record chrome.

Why a black bar beats a light blur on chart text

Short identifiers survive polite blur and mosaic. Treat MRNs and dates of birth like OTPs: opaque rectangles, a little padding, PNG export. Blur vs black bar is the general rule. Medical strings are the same class of secret. Soft blur on a face in a ward photo is a different job from covering a chart row.

Where screenshots leak in clinics and vendors

Slack channels, vendor Jira, Zoom screen shares, and “quick” phone photos of a monitor all create copies. Assume the PNG will leave the building. Share the barred file for debugging. Keep any full original only where your organization already stores ePHI with access control, not in a random channel.

On-device editing means the chart image does not need to hit a consumer upload site on the way to a bar. That is a hygiene choice. It does not make you “HIPAA compliant.” HHS’s minimum necessary discussion is about limiting PHI to what a purpose requires. A screenshot of five extra patients is the opposite of that instinct. Pair any browser cover with your employer’s approved tools when policy requires them.

Is redacting a screenshot enough for HIPAA compliance?

No. Pixel covers help stop accidental disclosure in a chat paste. They do not replace BAAs, access controls, audit logs, workforce training, or your organization’s policies. When unsure, ask privacy or compliance, not a blog post. This is not legal advice. Barring an MRN is not a certification that a disclosure was lawful.

Can I leave the MRN if I bar the name?

Often no. An MRN alone can still identify a patient inside a system. Bar both unless a controlled internal process explicitly needs one field and already knows the patient. That process is yours to define with counsel. The screenshot habit is: bar both.

What about faces in a ward photo?

Soft blur or draw over faces, and bar wristbands and room numbers. Hallway backgrounds pick up whiteboards. Check those too. A face plus a room board is still a patient.

Should clinicians use consumer “AI redact” uploads?

Avoid sending ePHI to tools without a BAA and clear data handling. A local browser canvas that never uploads is a better fit for a quick cover before an internal paste. Still follow employer policy. If policy forbids consumer editors, use the approved stack only.

If a glyph still reads at zoom

Enlarge the bar. Recapture if a banner with another patient name arrived mid-snip. If the PNG already hit Slack, follow your incident process. A blog checklist cannot close that loop. Notifications mid-capture: notifications in screenshots.

Portal chrome that reprints the patient

EHR portals put the patient name in the tab title, the top banner, the print header, and sometimes the favicon badge count. A snip of “just the labs table” still carries that banner. Collapse side panels that list the last five patients you opened. Bar the tab strip if the OS shows window titles in the capture. Those repeats are still identifiers even when the table cells look clean.

Fax confirmations and portal “message sent” toasts often include a phone number or MRN. Wait for the toast to clear, or bar it. If your employer requires an approved redaction tool, use that tool. This page describes the pixel habit: opaque covers on identifiers, PNG out, original off the chat. It does not replace a BAA, a retention policy, or counsel.

For a browser canvas that keeps the file in the tab while you bar fields, open BlurThis. Still follow workplace rules when the image is part of the designated record set.

Recap

Related guides

Back to all guides