DocketPDF
All case studies
Case study 05
Healthcare records — Two clinics

Redaction that is actually gone

A records request is answered by removing things. Drawing a black box over them is not removing them — and the practice found that out the hard way.

Brookline Family Medicine6 minute readAugust 2026
The organisation

A two-site family medicine practice with nine clinicians and about eleven thousand active patients, answering roughly two hundred records requests a month.

The problem

Records were produced by drawing filled rectangles over text, which left the text in the file and selectable.

What changed

Redaction is burned into the page content and the file is flattened on export.

The result

About 1,900 pages a month produced this way, with no recoverable redaction found on any sampled batch.

1,900pages redacted a month
0recoverable redactionson every sampled batch since the change
~200requests a monthpatients, attorneys, insurers

The organisation

Brookline Family Medicine runs two clinics with nine clinicians between them and about eleven thousand active patients. Records requests are handled by a two-person health information team reporting to the practice manager, who is also the privacy officer.

The practice answers roughly two hundred requests a month. About half come from patients, a third from attorneys, and the rest from insurers and other practices.

The problem

A records request is answered by removing things. A patient is entitled to their own record. An attorney is entitled to what the authorisation covers and nothing else. An insurer is entitled to less again. Every production is the same source record with a different set of removals applied.

The removals are the whole job, and they were being done by drawing filled black rectangles over text in a general PDF tool. That looks correct on screen and prints correctly. It also leaves every character of the covered text in the file, where it can be selected, copied, or extracted by anybody who thinks to try.

Nobody at the practice knew this. It was found when an attorney's paralegal — not adversarially, and to her credit immediately by telephone — mentioned that she had copied a name out from under a redaction while trying to select a paragraph. The practice had by then produced an unknown number of records that way over an unknown period.

What they tried first

The immediate response was to stop producing electronically: print the record, redact with a marker, scan the result, send the scan. This was defensible and it was awful. The output was a photograph of a redacted photocopy — unsearchable, frequently unreadable where the original was a fax, and roughly four times the file size. Requesters began telephoning to ask what a page said, which created a second workload and, in a few cases, a second disclosure risk over the phone.

The team also tried flattening the existing rectangle-based output, on the theory that flattening would merge the rectangle into the page. It does — but flattening a rectangle drawn over text renders the page as it appears, which is only reliable if the tool actually rasterises or rewrites the content stream. In their tool it did not always, and the team could not tell from looking at the file which pages were safe. A control that cannot be verified is not a control.

What changed

Redaction is now burned in. The marked region is removed from the page's content — the characters are deleted, not covered — and the page is rewritten. The document is then flattened on export.

The test the practice runs is the only one that matters: open the produced file and search it for the redacted term. If the search returns nothing, the removal happened. That test is now part of the procedure rather than an assumption about the software.

Because the record keeps its text layer everywhere it was not redacted, the produced file is searchable — which was the thing the print-and-scan period had cost, and the thing requesters had been telephoning about.

How it was put in

The privacy officer wrote the verification step first and the procedure around it second, which is the reverse of how the previous method had been adopted.

The two-person team was trained in an afternoon. The harder part was retrospective: the practice had to decide what to do about productions already made. It took legal advice, notified where the advice said to notify, and documented the change of method with a date. The date is the reason the practice keeps the case study internally.

Sampling was set at the start rather than added later. The compliance officer runs the search test on a sample of every batch, records the result, and has the log to show for it.

The result

About nineteen hundred pages a month are produced this way. On sampled batches since the change, the search test has not found a survivor.

The requester-side effect was immediate and unplanned: follow-up calls asking what a page said fell away, because the produced file is searchable and legible. The health information team estimates that recovered most of a day a week between them.

The practice manager's summary is that the software change was small and the procedural change was not. The burned-in redaction made a correct answer possible; writing down the verification step is what made it reliable.

We were producing records with the names still in the file and no idea. Finding that out was not a good afternoon. Fixing it was one setting — and then three weeks of writing down how we would know it stayed fixed.
Sample quotation · Replace with a real, consented one before publishing

What they use

  • Redaction burn-in
  • Flattened export
  • Extract pages
  • Merge
  • OCR
  • Bates numbering
  • Export PDF