BlurThis

Home/Blog/

HIPAA screenshot redaction: cover PHI before you share

Practical checklist to black-bar MRNs, DOBs, and names on medical screenshots. Not legal advice — on-device cover before Slack.

Laptop and papers on a clinical office desk
Photo from Unsplash

HIPAA screenshot redaction starts with a boring habit: before a medical chart, EHR toast, or patient portal snip leaves your laptop, black-bar every name, MRN, DOB, and address so protected health information (PHI) is not sitting in Slack pixels. Use Markup, Paint, Preview, or a browser tab — opaque covers, not soft blur on chart text. This page is practical hygiene — not legal advice.

How to redact a HIPAA-sensitive screenshot (step by step)

Prefer Black bar for MRNs, DOBs, phone numbers, emails, and insurance IDs. Soft Blur is for faces in hallway photos — not for readable chart text. Export PNG and keep the unbarred original out of chat.

On your phone or computer

Windows: Win + Shift + S → Paint. Filled black rectangles over MRNs, DOBs, names, and insurance IDs. Soft blur on chart text is the wrong tool.

Mac: Preview → Markup with a filled shape over the same fields. Avoid translucent highlighters on PHI strings.

On phone portal captures, Photos Markup or Android gallery solid shapes — opaque black, save a copy, never forward the unbarred original.

Or finish in a browser (optional)

Want to do it in a tab with no install? BlurThis is one free option. The file stays on your device. Other browser tools work too if they paint on the page and do not upload the image.

  1. Open the editor in your browser. No account needed for BlurThis.
  2. Drop the screenshot, tap Upload from PC or Mobile, or paste with Ctrl / ⌘ + V on a computer.
  3. Pick Box or Draw. Use Black bar for phone numbers, emails, and OTPs. Use Blur for faces when a soft cover is enough.
  4. Drag over each private spot. Pinch or use + / − to zoom. Leave a little padding so no letter peeks out.
  5. Tap Download PNG. Send that file. Keep the original out of the chat or ticket.

Practical PHI checklist before you share

  • Patient name in headers, tabs, wristband photos, and titles.
  • MRN / medical record number, encounter ID, and account numbers.
  • Date of birth, age when unique with other fields, and SSN.
  • Address, phone, email, and emergency contacts.
  • Insurance member IDs and claim numbers.
  • Diagnoses, meds, and lab values if the audience does not need them.
  • Provider names next to a patient when the combo identifies care.
  • Other patients in worklist sidebars and schedule grids.
  • Browser URL if it contains patient tokens or portal paths.
  • Notification banners that landed mid-capture.

Crop to the error or UI bug when you can. When the layout must stay, bar every identifier around it. Support-style checklists for tickets also appear in customer support screenshot redaction.

Why a black bar beats a light blur on chart text

Short identifiers survive polite blur and mosaic. Treat MRNs and DOBs like OTPs: opaque rectangles, a little padding, PNG export. Blur vs black bar is the general rule; medical strings are the same class of secret.

Where screenshots leak in clinics and vendors

Slack channels, vendor Jira, Zoom screen shares, and “quick” phone photos of a monitor all create copies. Assume the PNG will leave the building. Share the barred file for debugging; keep any full original only where your organization already stores ePHI with access control — not in #random.

On-device editing means the chart image does not need to hit a consumer upload site on the way to a bar. Pair that with your employer’s approved tools when policy requires them.

FAQ: Is redacting a screenshot enough for HIPAA compliance?

Pixel covers help stop accidental disclosure in a chat paste. They do not replace BAAs, access controls, audit logs, or your organization’s policies. When unsure, ask privacy / compliance — not a blog post.

FAQ: Can I leave the MRN if I bar the name?

Often no. An MRN alone can still identify a patient inside a system. Bar both unless a controlled internal process explicitly needs one field and already knows the patient.

FAQ: What about faces in a ward photo?

Soft blur or draw over faces, and bar wristbands and room numbers. Hallway backgrounds pick up whiteboards — check those too.

FAQ: Should clinicians use consumer “AI redact” uploads?

Avoid sending ePHI to tools without a BAA and clear data handling. A local browser canvas that never uploads is a better fit for a quick cover before an internal paste — still follow employer policy.