DOI: 10.4258/hir.2026.32.3.204 ISSN: 2093-369X

De-Identification of Magnetic Resonance Imaging to Protect Patient Privacy in Research Use: A Comprehensive Review

Seonguk Kang, Junbeom Jang, Uk-Su Choi, Jeong-Ho Hong, Sang Won Park

Objectives: Brain magnetic resonance imaging (MRI) contains identifiable facial and cranial features, creating privacy risks that can limit secondary research use. This review examines current MRI de-identification technologies, quantitative validation methods, and governance frameworks to identify practical strategies for preserving data utility while protecting patient privacy. Methods: A descriptive narrative review was conducted across technical and policy domains. Studies of facial deidentification were analyzed according to the tools used, validation procedures, and downstream analytic performance. The reviewed approaches included traditional defacing, refacing, and deep-learning-based anonymization. Evaluation frameworks used the structural similarity index measure (SSIM), Dice similarity coefficient (DSC), intraclass correlation coefficient (ICC), and the paired t-test to quantify both privacy preservation and analytic fidelity. A parallel policy analysis compared the Health Insurance Portability and Accountability Act (HIPAA), the General Data Protection Regulation (GDPR), Japan’s Act on Anonymized Medical Information, Taiwan’s Personal Data Protection Act, and South Korea’s Personal Information Protection Act and 2024 Health Data Use Guidelines to assess policy convergence and institutional consistency. Results: Visual inspection studies reported that FreeSurfer preserved cortical anatomy but incompletely removed facial features, whereas FSL_deface overmasked some nonfacial regions. Artificial intelligence (AI)-based recognition tests achieved 28%–38% accuracy on defaced data, confirming measurable residual re-identification risk. Quantitative assessments identified segmentation degradation, including a DSC decrease from 0.970 to 0.918, and regional volumetric variability, including a hippocampal ICC of 0.742, with <i>p</i> < 0.05. Generative adversarial network-based refacing improved perceptual similarity, with SSIM values >0.7, but retained subtle facial geometry. The governance analysis indicated that HIPAA and GDPR provide established standards, whereas South Korea’s Data Review Board oversight remains discretionary and nonuniform, limiting reproducibility across institutions. Conclusions: MRI de-identification requires integrated pipelines that combine AI-based facial masking and metadata cleansing with standardized evaluation metrics and enforceable review protocols.

More from our Archive