.dcm ยท .dcm .dicom

What a DICOM Scan Reveals About the Patient

A DICOM file (.dcm or .dicom) is a medical scan, and it is the densest personal data of any format this tool reads. The picture looks anonymous, but the file behind it routinely names the patient, their hospital number and date of birth, the doctor who referred them, the hospital, the machine, and - in clinical shorthand - what they were being investigated for. These files get emailed to specialists, posted to forums for a second opinion and attached to insurance claims, carrying all of that with them.

Scan a DICOM file

What a .dcm file reveals

The patient is named in full. File X-Ray reads the patient name, hospital ID, date of birth, sex, age and weight, and where present the home address and phone number, plus free-text history, medical alerts and allergies. It also surfaces the quasi-identifiers from the DICOM confidentiality profile that de-identifiers are meant to remove and routinely leave behind - ethnic group, religion, occupation, mother's maiden name - each of which identifies a person on its own or in combination.

The people and the place are recorded too. The referring, performing, reading and requesting physicians are named, along with the operator who ran the scanner, and the institution name and address, department and station place the patient at a specific facility. The scanner's make, model, software version and device serial number identify one physical machine, tying together every scan it has produced. Study, series and instance UIDs group every image from one appointment even after files are renamed.

The reason for the scan is diagnosis by implication. The study description, series description, body part examined, protocol name and the free-text "reason for study" and "reason for visit" fields state, in clinical language, what the patient was being investigated for. Combined with the study date and the institution, that is a medical record about an identifiable person - which File X-Ray calls out explicitly as an "identifiable medical record" whenever a named patient appears together with the facility or the scan date.

Two findings matter more than the field list. A DICOM file can declare itself de-identified and still carry the patient: that claim is an unenforced text field, and File X-Ray flags when identifying fields are still populated, or when the original name, ID and birth date were merely moved into the Original Attributes Sequence quarantine one level deeper rather than destroyed. And identity can be painted into the picture itself - as burned-in pixel text or a separate overlay plane - which survives metadata stripping entirely. Removing metadata does nothing to those; the only fix is to crop or paint over the image.

Key fields

Patient Name
The full name of the person scanned, stored in the file, not shown when the image is viewed, and travelling with every copy.
Patient ID
The hospital or clinic number, the key that ties this scan to the patient's whole medical record at that institution.
Date of Birth / Sex / Age / Weight
Patient demographics; with the name, the date of birth alone identifies one person conclusively.
Referring / Performing / Reading Physician
The doctors involved in the scan, each a named real person, and with the institution a specific practice.
Operator Name
The radiographer or technician who ran the scanner, naming a member of staff and the shift they worked.
Institution Name & Address
The hospital or clinic and its postal address, placing the patient at a specific facility on a specific date.
Study Description / Body Part / Reason for Study
What the scan was for, in clinical shorthand and plain text - effectively a statement of what the patient was being investigated for.
Study Date & Time
When the patient was scanned; with the institution it places a named person at a named hospital at a specific moment.
Device Serial Number
The scanner's serial, identifying one physical machine and tying together every scan it has ever produced.
De-identification Is Incomplete
A flag raised when the file declares patient identity was removed yet identifying fields are still populated - an unverified claim carried alongside the data.
Original PHI Retained After De-identification
A flag raised when the real name, ID and birth date sit in the Original Attributes Sequence quarantine, moved there rather than destroyed, and invisible to a top-level reader.
Burned-In Details / Overlay Plane
Identifying text declared as drawn into the image pixels, or a separate overlay layer, either of which survives metadata stripping - the only fix is to crop or paint over it.

This is a selection. The full field manual documents the fields read from each format.

Questions about DICOM metadata

Does a DICOM (.dcm) file contain patient information?

Almost always, yes. A single scan routinely stores the patient's full name, hospital ID, date of birth, sex, age and weight, the referring and performing doctors, the hospital and department, the scanner and its serial number, the scan date, and a description of what was being investigated. The image looks anonymous; the file behind it is not.

The scan image looks anonymous - is my DICOM file safe to share?

Not on the strength of the picture. The identifying data lives in the file's metadata and, sometimes, burned into the pixels or an overlay layer. A viewer showing an unlabelled image can be sitting on a full patient record. Check the file itself before sending it to a specialist, a forum or an insurer.

Is a DICOM marked 'anonymized' or 'de-identified' actually clean?

Not necessarily. The de-identification flag is an ordinary text field that nothing enforces, so a file can claim it and still carry the patient. Tools also often move the original name, ID and birth date into the Original Attributes Sequence instead of deleting them, so the real values sit one sequence deeper. File X-Ray checks for both and for identity declared burned into the image.

What is 'burned-in' patient data in a DICOM scan?

Scanners frequently print the patient's name, number and date into a corner of the image itself, or store them in a separate 1-bit overlay plane. Because that text is part of the picture rather than metadata, removing the metadata does nothing to it - the only remedy is to crop or paint over that part of the image.

Is sharing a DICOM file a legal or privacy risk?

Generally yes. A named patient together with a facility and a scan date is a medical record about an identifiable person, which in most jurisdictions is the category of data with the strongest legal protection. Sending the file sends all of it. File X-Ray reads DICOM entirely in your browser so you can check what a file exposes before it leaves your machine.

File X-Ray reads DICOM files entirely in your browser - the file never leaves your device. This format is inspected, not modified. Scan a file now.

All supported formats