HomeBlog › Redact an EOB or Medical Bill

How to Redact an Insurance EOB or Medical Bill Before Sharing It

An Explanation of Benefits (EOB) or itemized medical bill carries far more than the dollar amount someone actually needs to see. Alongside the balance sits your member ID, group number, claim number, provider's national identifier, and rows of diagnosis and procedure codes that describe exactly what was treated. Before you forward a copy for reimbursement, a legal dispute, or proof of expenses, this guide covers what to redact, what the codes actually reveal, and how to remove them locally without uploading the document anywhere.

Key takeaways

  • Redact your member/policy ID, group number, and claim number unless the recipient is the payer that issued them — a reimbursement administrator, your insurer, or the provider's billing office.
  • Diagnosis codes (ICD-10) and procedure codes (CPT/HCPCS) describe the medical condition and treatment in coded form — treat them as sensitive as a written diagnosis, because they decode into one.
  • Medicare stopped printing Social Security numbers on beneficiary cards and paperwork in 2019 under a federal mandate, replacing them with a randomly generated identifier — a case study in a national program treating a claim number as an identity risk.
  • An EOB is not a bill — it is your insurer's record of what a provider charged, what the plan covered, and what you may owe. Reading it before you forward it also helps you catch billing errors.
  • SladdPDF redacts and strips metadata locally in your browser, with no upload. Free with no page limit.

Why an EOB or medical bill ends up shared

An EOB or itemized bill rarely stays between you and your insurer. People forward a copy to an HSA or FSA administrator to substantiate a reimbursement claim, to a divorce attorney or family court to document shared medical expenses, to a disability or workers' compensation carrier as supporting evidence, or to a landlord or lender as proof of a hardship. In nearly every case, the recipient needs to confirm one thing — that a specific expense happened and roughly what it cost — not read the full clinical picture behind it.

Before forwarding an EOB or medical bill, work out exactly what the recipient is trying to confirm — an expense, a date of service, a paid amount — and treat every other field as removable.

What's actually printed on an EOB or medical bill

An EOB and an itemized medical bill are different documents from different senders, but they share most of the same identifying fields. An EOB comes from your insurance plan after it processes a claim; a bill comes from the provider or a billing service. Between them, a typical set of pages includes: your name and date of birth, member/policy ID and group number, a claim number, the provider's name and National Provider Identifier (NPI), dates of service, diagnosis codes (ICD-10-CM), procedure or service codes (CPT or HCPCS), the amount billed, the plan's allowed amount, what insurance paid, and what you owe. Older paperwork, or documents tied to Medicare, may still reference a legacy Health Insurance Claim Number that was built directly from a Social Security number.

What to redact, and what to keep

What belongs in the copy you send depends on who is receiving it and why. The table below covers two of the most common cases.

FieldSubmitting to an HSA/FSA administratorSharing with a lawyer, ex-spouse, or advocate
Patient nameKeepKeep
Date of service and amountKeepKeep
Member/policy ID, group numberKeep only if the administrator's form requires itRedact
Claim numberKeep only if required to match the reimbursement to the claimRedact unless the dispute concerns that specific claim
Date of birthRedact unless the form asks for itRedact unless age is relevant to the case
Diagnosis codes (ICD-10)Redact unless the plan requires proof of medical necessityRedact unless the diagnosis itself is at issue
Procedure/CPT codesKeep if the plan needs to confirm what the expense was forRedact unless the specific treatment is at issue
Provider name and NPIKeepKeep
Legacy Medicare claim number / SSN-based IDRedactRedact

When a form or administrator's requirements are unclear, ask what they actually need to see rather than sending the full page and hoping it's fine.

Why Medicare stopped printing SSNs on claim paperwork

For decades, a Medicare beneficiary's Health Insurance Claim Number (HICN) was built directly from their Social Security number, and it appeared on the Medicare card itself and on every EOB, bill, and piece of correspondence tied to a claim. That design turned routine paperwork — exactly the kind of document people photocopy, fax, and mail — into a steady leak of SSNs.

The Medicare Access and CHIP Reauthorization Act of 2015 (MACRA) required the Centers for Medicare & Medicaid Services to remove Social Security numbers from all Medicare cards. Under the resulting SSN Removal Initiative, CMS replaced the HICN with a randomly generated Medicare Beneficiary Identifier (MBI) that carries no embedded personal data, mailing new cards to more than 61 million beneficiaries between 2018 and 2019.

A federal law forced Medicare to stop building beneficiary identifiers out of Social Security numbers, precisely because that number showed up on the routine claim paperwork people share and dispose of every day — the same category of document as an EOB.

The lesson generalizes past Medicare: any claim number, member ID, or account number tied to your identity is worth treating as sensitive on a document you're about to hand to someone else, even when it doesn't look like an SSN at a glance.

Diagnosis and procedure codes are protected health information

An ICD-10 diagnosis code is not a neutral reference number — it decodes, often via a single public lookup, into a specific medical condition. A CPT or HCPCS procedure code does the same for treatment. Under the HIPAA Privacy Rule, both are treated as protected health information (PHI) alongside the more obviously sensitive fields like name and date of birth, and the U.S. Department of Health and Human Services' Office for Civil Rights lists diagnosis and treatment details among the categories that must be removed or generalized before health information counts as de-identified.

That standard is written for the covered entities (providers, insurers) that HIPAA regulates — it doesn't bind you personally when you forward your own EOB. But it's the right bar to hold yourself to: if a code on the page would let a stranger work out a diagnosis, redact it unless the recipient specifically needs it. Our guide to HIPAA redaction and the 18 Safe Harbor identifiers covers the full list in detail for anyone redacting health records more broadly.

A black box over a claim number is not redaction

A rectangle drawn over a PDF in a markup tool or a Preview annotation typically just sits on top of the page — the member ID, diagnosis code, or claim number underneath is still stored in the file. Most EOBs and bills are generated as PDFs with a real text layer, so a covered field can often be lifted straight out with copy-paste, no image tools required. We cover the mechanics in why a black box is not redaction.

A black rectangle covers what a reader sees on screen; it does not remove what the file stores. Real redaction deletes the underlying text or flattens the page into a fresh image with nothing recoverable beneath the mark.

How to redact an EOB or medical bill locally, step by step

An EOB or medical bill bundles exactly the fields identity thieves and medical-billing scammers look for — member IDs, claim numbers, diagnosis codes — which makes it a poor fit for any "free online redaction" tool that requires an upload. SladdPDF runs entirely in your browser: the file is processed locally with JavaScript and WebAssembly, nothing is sent to a server, and it keeps working offline once the page has loaded.

  1. Load the document in your browser. Open sladdpdf.com and load the PDF of the EOB or itemized bill. The file stays on your device.
  2. Decide what the recipient actually needs. A dollar amount, a date of service, a provider name — work out the minimum before you start marking anything.
  3. Redact identifiers tied to the policy. Cover the member/policy ID, group number, and claim number unless the recipient is the payer or administrator who issued them.
  4. Redact diagnosis and procedure codes you don't need to disclose. Treat an ICD-10 or CPT code the same as a written diagnosis — because it decodes into one.
  5. Export in Secure mode. Choose Secure mode when exporting. It rasterizes each page to a flat image, so the text and hidden objects underneath the redactions are destroyed and unrecoverable.
  6. Remove the metadata. Enable metadata removal on export so the Author and Title fields and the creation-tool trace are cleared before you send the file.
  7. Verify before sending. Open the exported PDF and try to select and copy text over the redacted areas to confirm the underlying data is actually gone.

If you're assembling a packet of financial documents alongside a medical bill, our guides to redacting a tax return, W-2, or 1099 and redacting a bank statement cover those document types specifically. For a general introduction to redaction, start with how to redact a PDF for free.

This article is general guidance, not legal or medical advice.

Redact your EOB or medical bill without uploading it anywhere

SladdPDF runs 100% locally in your browser — the document never leaves your device. Free with no page limit; Pro unlocks 300 DPI export.

Redact a PDF now

Frequently asked questions

What should I redact from an EOB before sending it to my FSA or HSA administrator?

Keep the patient name, date of service, provider name, and the amount, since your administrator needs those to approve reimbursement. Redact the member ID, group number, and claim number unless the form specifically requires them, and redact diagnosis codes unless the plan needs proof of medical necessity.

Is an EOB the same thing as a medical bill?

No. An Explanation of Benefits comes from your insurance plan and shows what a provider billed, what the plan covered, and what you may owe — it is a statement, not a request for payment. A medical bill comes from the provider or a billing service and is the actual invoice. They share most of the same identifying fields, so the same redaction approach applies to both.

Are diagnosis codes on a medical bill considered sensitive?

Yes. An ICD-10 diagnosis code or a CPT procedure code decodes into a specific medical condition or treatment, often through a single public lookup. Under the HIPAA Privacy Rule, both are treated as protected health information alongside more obvious identifiers like name and date of birth, so they're worth redacting from any copy you don't need to disclose in full.

Why did Medicare stop putting Social Security numbers on cards and paperwork?

A 2015 federal law, the Medicare Access and CHIP Reauthorization Act, required the Centers for Medicare & Medicaid Services to remove Social Security numbers from Medicare cards after decades of using an SSN-based claim number. CMS replaced it with a randomly generated Medicare Beneficiary Identifier and mailed new cards to more than 61 million beneficiaries between 2018 and 2019, specifically to reduce identity-theft risk from routine claim documents.

Is drawing a black box over a claim number on a PDF good enough?

No. A rectangle drawn over text in most PDF viewers or markup tools sits on top of the page — the claim number, member ID, or diagnosis code underneath is still stored in the file and can often be recovered with copy-paste. Real redaction deletes the underlying data or flattens the page into a fresh image, which is what SladdPDF's Secure mode does.

Sources
  1. U.S. Department of Health & Human Services, Office for Civil Rights: Guidance Regarding Methods for De-identification of Protected Health Information — hhs.gov
  2. Centers for Medicare & Medicaid Services: New Medicare Card / SSN Removal Initiative — cms.gov
  3. Medicare Access and CHIP Reauthorization Act of 2015 (MACRA), Pub. L. 114-10, § 501 — congress.gov
  4. Medicare.gov Glossary: Explanation of Benefits (EOB) — medicare.gov