Guide for patients & caregivers

How to Share a Medical Story Online Safely

A privacy-first checklist for sharing a symptom story online: remove identifiers, keep the timeline useful, and turn similarities into clinician questions.

By SameCase EditorialUpdated 8 min read

For patients & caregivers

Turn this guidance into a clearer case summary

Describe the situation without an account, name, or email. Free text can still carry re-identification risk. SameCase compares it with clearly labelled teaching cases and turns the comparison into questions for your own clinician, not a diagnosis.

The short answer

A medical story can be useful when it preserves the sequence of what changed, what was checked, what remains unclear, and what you want to ask. It becomes risky when it includes details that let someone recognize you or another person, or when an online resemblance is treated as a diagnosis. Share only what is needed for the purpose, use a channel whose privacy and audience you understand, and keep urgent decisions with your local care team.

SameCase is designed around that boundary. Patient entry does not require an account, name, or email. Its public library uses clearly labelled constructed teaching cases, not public patient submissions. If you opt in to clinician input, the individual narrative remains behind a human privacy review before currently verified doctors can see it. Automated checks reduce risk but cannot guarantee that free text is anonymous.

Check urgency before sharing

If symptoms are severe, sudden, rapidly worsening, or otherwise feel like an emergency, use local emergency or urgent-care services. Do not wait for an online match, a message, a reply, or a better-written timeline. An online worksheet is an appointment aid, not triage and not a substitute for examination, testing, or treatment.

For a non-urgent appointment, decide what you want the story to accomplish. You might be preparing for a visit, organizing a second-opinion request, asking a clinician a focused question, or learning how a teaching case is structured. A clear purpose helps you avoid pasting an entire record or disclosing details that do not change the question.

Build a minimum-useful timeline

Start with your usual baseline, then describe the first meaningful change and the order in which later features appeared. Use relative timing when exact dates are not necessary: “two weeks later,” “after the medicine changed,” or “on the second day.” Include observable patterns, duration, triggers, relief, functional impact, relevant medicines or supplements, and what has already been assessed. Mark information as unknown or pending rather than guessing.

Keep the story proportionate to the audience. A clinician may need the original report through a governed medical-record route; a public discussion usually needs only a broad summary. Do not copy a whole report, portal export, message thread, or image when a short description answers the purpose. Never change a clinical fact just to make the story seem more typical: remove, generalize, or withhold the case instead.

  • What changed, when it changed, and how the pattern is evolving.
  • What has already been examined or tested, with pending and unavailable items labelled.
  • Medicines, supplements, allergies, exposures, and prior conditions only when relevant to the question.
  • The one or two questions you want a qualified clinician to help answer.

Run a privacy scan before you share

Removing a name is not enough. Review the text, file names, images, screenshots, metadata, and links for direct identifiers and for combinations that could make a person recognizable. The United States HHS de-identification guidance lists examples such as names, contact details, record or account numbers, dates, locations, URLs, device identifiers, licence numbers, and full-face photographs. That guidance is not a worldwide legal test, so follow the law, consent rules, and institutional policy that apply to you.

Rare combinations deserve a second look: an exact date plus a small town, a named employer, a public incident, an unusual occupation, or a distinctive family detail can identify someone even when each detail seems harmless. Crop or replace images that show faces, wristbands, labels, room numbers, barcodes, or burned-in text. Inspect filenames and document properties separately. If you cannot make the risk acceptably small, do not publish the story.

  • Names, phone numbers, emails, addresses, record numbers, account numbers, URLs, and licence numbers.
  • Exact birth, admission, procedure, discharge, or appointment dates when they are not needed.
  • Small-area geography, named facilities, employers, relatives, or rare public events.
  • Faces, voices, screenshots, images, scan labels, filenames, and embedded metadata.

Choose the right channel and audience

A public forum, a private patient portal, a clinician-to-clinician referral, and a browser-only note are different channels with different audiences and controls. A public post can be copied, indexed, quoted, or combined with other posts. A private channel may still be governed by the receiving organization’s policy, and a local browser tool may be safer for drafting because its contents never leave the tab. Read the service’s privacy and sharing terms before sending health information.

SameCase patient entry is intentionally lightweight: no account, name, or email is required, and a secret retrieval code brings you back to the case. The code is not an identity credential, so protect it like a private link and do not place it in a public post. If you ask for doctor input, the platform’s privacy reviewer controls whether that individual description is shared; a submitted narrative is never automatically a public case.

Use a similar case as a question prompt

A similar case can help you notice a missing timeline detail, exposure, medicine change, record, or question. It cannot show that you have the same cause. Public cases are selective, often omit context, and are not a representative sample. Similar wording is not prevalence, probability, or proof.

When a story feels persuasive, write down both the overlap and the differences. Ask your clinician what would support or weaken the comparison, what information is missing, and which next step belongs in your own care pathway. Do not start, stop, borrow, or change treatment, order a test, or delay care because an online case looks familiar.

  • What exact feature made this case seem similar?
  • What is importantly different about timing, context, examination, or testing?
  • What information would change the clinician’s interpretation?
  • Who owns the next step, and when should the situation be reviewed again?

Copyable safe-sharing checklist

Use this checklist before submitting a story or sending a link. It is a privacy and communication aid, not legal clearance or medical advice.

  • Purpose and audience: Why am I sharing, and exactly who can see it?
  • Urgency: Is this safe to handle as preparation, or do I need local urgent care now?
  • Minimum necessary: Which details directly help answer the question, and which can be removed?
  • Timeline: Have I kept the sequence, functional impact, relevant medicines, and pending items clear?
  • Identifiers: Did I remove names, contact details, exact dates, small locations, record numbers, links, and rare combinations?
  • Files and media: Did I inspect screenshots, images, filenames, metadata, labels, faces, voices, and barcodes?
  • Consent and governance: Do I have the right to share this person’s information, and what local rules apply?
  • Access: Is a private link or retrieval code protected, and have I avoided putting it in a public post?
  • Questions: What are my top one to three questions for a qualified clinician?
  • Safety net: Who owns follow-up, by what date, and what change requires earlier or urgent care?

Evidence and limits of this guide

The sources below are public guidance from HHS, the National Institute on Aging, AHRQ, and SameCase’s own privacy and audience pages. HHS explains formal United States HIPAA de-identification methods and examples of identifiers; it does not provide a universal privacy standard for every country or every public platform. NIA and AHRQ support preparing questions, records, symptoms, and medicine information for a clinical visit. Their materials do not validate this exact checklist or prove that using it improves diagnosis, safety, or outcomes.

SameCase has not assigned a named clinician reviewer to this page. The platform’s automated privacy checks can miss context and cannot guarantee de-identification. Use the responsible care team’s instructions, your employer’s or institution’s governance, applicable consent requirements, and local privacy law. If sharing would create material risk, do not share it.

Sources and further reading

Keep learning