05/08/2026
How to De-identify Support Facts Before Using AI for Care Documentation
A privacy-first guide to removing direct and indirect identifiers from support facts before using AI to draft care documentation for human review.
Guide record
How this guide is reviewed
CaresLink reviews guides for plain language, practical operational use, and consistency with official sources linked on the page.
- Published
- 05/08/2026
- Reviewed
- 5 August 2026
New in CaresLink AI Documents
Move from a blank template to a privacy-reviewed draft.
Start with structured support facts or notes in a supported language. CaresLink helps you review obvious identifiers and subjective wording before producing a case-note draft, a checking version, missing facts, and follow-up prompts.
The automated review cannot guarantee complete de-identification. Every output is a draft that must be checked before it is copied into your organisation's record system.
See the completed case note exampleAI can help turn structured support facts into clearer draft wording, but the privacy step comes first. Before care-related facts are sent to an AI product, the user should remove information that identifies a person and consider whether the remaining details could still identify them in context.
This guide provides a general operational workflow for aged care, home care, and NDIS teams. It does not decide whether information is legally de-identified, whether a particular AI product is appropriate, or whether an organisation has met its privacy, record-keeping, clinical, or regulatory responsibilities.
Removing a name is only the first step
The OAIC describes de-identification as a contextual risk-management process. Removing direct identifiers is essential, but a combination of location, time, service details, family circumstances, or an unusual event may still make a person reasonably identifiable to someone who knows the setting.
That is why an automated check cannot guarantee complete de-identification. A useful workflow combines automated prompts, data minimisation, an approved access environment, and deliberate human review before information leaves the organisation's controlled process.
Direct identifiers, indirect identifiers, and wording risks
| Review type | Examples to look for | Safer drafting action |
|---|---|---|
| Direct identifiers | Name, NDIS number, Medicare number, phone, email, date of birth, exact address, internal client ID | Remove before AI drafting; do not replace one identifier with another unique code |
| Indirect identifiers | Exact venue, small town, room number, rare event, precise time combined with unusual circumstances | Generalise only when the detail is not necessary; otherwise keep the work inside the approved record process |
| Other people | Family member names, worker names, emergency contacts, identifiable third parties | Replace with role-based wording such as the participant, a family member, or the support worker |
| Subjective or clinical labels | Anxious, aggressive, non-compliant, high risk, deteriorating | Record observable actions or words instead, or leave the point for an authorised reviewer |
| Organisational secrets | Passwords, portal screenshots, claim files, access tokens, private vendor material | Do not enter them into the AI workflow |
Replacing a participant's name with Client A or an internal code may still leave a traceable link. For an external drafting step, remove unnecessary identifiers rather than carrying the provider's internal lookup key into another system.
A five-step privacy-first workflow
Start with the minimum necessary facts for the drafting task. More context is not automatically better.
Remove direct identifiers before sending anything to an AI service.
Review indirect identifiers in context. Ask who could recognise the person from the remaining combination of facts.
Separate observable facts from conclusions. Record what was seen, heard, said, or done rather than asking AI to make a diagnosis or risk judgement.
Preview the exact structured facts that will be sent, then require a human to confirm the content and their authority to use it.
Example: reduce identifying detail without inventing facts
| Before privacy review | Drafting input after review | Why it changed |
|---|---|---|
| Jordan Lee attended Chatswood Chase at 2:07 pm | The participant attended a local shopping centre in the afternoon | Name, exact venue, and exact time were not needed for this wording task |
| Jordan's daughter Amelia called 0412 345 678 | A family member contacted the support worker | The family member's name and phone number were removed |
| Jordan was very anxious and non-compliant | The participant stated three times that they wanted to return home and sat near the exit | A judgement was replaced with confirmed observable facts |
| NDIS 123456789 | Removed from AI drafting input | A government-related identifier was not needed for drafting |
Do not use an example transformation as permission to delete information from a required provider record. The question here is what the AI needs for drafting, not what the provider's final record must contain.
De-identified drafting input is not the completed record
NDIS record-keeping guidance says provider records can require minimum identifying information, including the participant name and NDIS number. Those identifiers belong in the provider-approved record system when required. They do not need to be sent to an external drafting tool merely to improve wording.
A practical sequence is to create wording from reviewed, de-identified facts, check the draft against the source facts, then place accepted wording into the organisation's record system and complete the required identifiers, author, dates, approvals, and links there.
The AI draft should remain clearly labelled as a draft until the responsible worker or reviewer has confirmed accuracy, purpose, record type, and the organisation's storage process.
Review the AI output as well
AI output can introduce errors, unsupported wording, or new personal information. Compare every sentence with the confirmed input, scan the output for identifiers, and remove any event, diagnosis, intention, risk conclusion, outcome, or follow-up that was not supplied.
The final reviewer should also confirm that the wording fits the intended record type. A progress note, case note, handover, incident record, and clinical record do not serve the same purpose.
When not to use AI for the task
The facts cannot be reduced enough for the intended AI environment without losing information needed for safe action.
The organisation has not approved the product, access pathway, retention settings, or purpose.
The task requires a clinical conclusion, legal interpretation, reportable-incident decision, risk classification, or emergency response.
The user cannot verify the source facts or does not have authority to handle the information for this purpose.
The content contains an active incident, allegation, safeguarding concern, medication issue, or urgent change that must follow a separate organisational procedure first.
How CaresLink applies this workflow
The CaresLink NDIS Case Note AI Companion asks signed-in users to work with structured facts, review obvious privacy and neutral-wording prompts, and confirm the reviewed version before generation. It creates user-reviewed draft wording only and cannot guarantee complete de-identification.
CaresLink is not a participant record system. Transfer any accepted wording into the provider-approved record system, add required identifiers there, and complete the organisation's normal review and incident pathways.
Frequently asked questions
Is replacing the participant's name enough?
No. Review direct identifiers and combinations of indirect details such as exact location, time, family circumstances, and a distinctive event. Re-identification risk depends on the context in which information is used or released.
Should an NDIS number be included in AI drafting input?
Not when it is unnecessary for the wording task. A completed provider record may require the identifier, but it can be added inside the provider's approved record system after the draft is reviewed.
Can software confirm that text is completely de-identified?
No automated review can make that determination for every context. Treat detection as assistance and keep a human responsible for the final privacy review.
Does de-identification make any AI product suitable for care documentation?
No. The organisation should still review the product, intended purpose, access controls, data handling, retention, staff training, and human oversight. Seek appropriate privacy or professional advice for higher-risk uses.
Disclaimer
These resources are provided for general operational documentation and educational purposes only. They do not constitute legal, clinical, medical, compliance, or professional advice. Organisations should review and adapt all documents according to their own policies, procedures, registration requirements, funding arrangements, and regulatory obligations.