Master Patient Index (MPI) - The Deduplicator: How American Hospitals Keep Patient Identities Straight in a World of John Smiths, Misspelled Names, and Merged Records |
Short Executive Summary |
This chapter explores the Master Patient Index (MPI)---the foundational identity management system within the Hospital Information System that ensures every patient is uniquely and accurately identified across all encounters, facilities, and time. In a healthcare system without a national patient identifier, the MPI is the critical 'deduplicator' that links a patient's scattered records into a single, coherent lifetime health history. Through detailed U.S. case studies---from a large integrated health system managing millions of patient identities to a community hospital grappling with duplicate records and a regional health information exchange that must match patients across multiple organizations---we examine how the MPI works, why it is so challenging, and the consequences of failure. The chapter covers the core concepts: the enterprise MPI (EMPI) versus the local MPI, probabilistic and deterministic matching algorithms, the use of demographic data (name, date of birth, address, phone number, etc.) and biometrics, the governance and stewardship required to maintain data quality, and the emerging role of artificial intelligence and blockchain in identity management. It concludes that the MPI is not merely a technical tool; it is the essential 'source of truth' for patient identity, upon which all other clinical, administrative, and financial functions of the HIS depend. A flawed MPI means flawed care, flawed billing, and flawed outcomes. |

|
Master Patient Index (MPI) - The Deduplicator |
A Detailed Popular-Science Exploration |
1. The Identity Crisis in American Healthcare |
Imagine a patient named John Smith. He is born in Chicago, moves to Dallas for a job, and later retires to Phoenix. Over his lifetime, he has been treated by dozens of doctors, admitted to several hospitals, and had lab work done at multiple independent laboratories. In each of these encounters, his name has been spelled slightly differently---'Jon Smith,' 'John Smithe,' 'J. Smith'---and his date of birth may have been recorded incorrectly on one occasion. His address has changed multiple times. He has two different phone numbers. |
In a fully functional health information system, all of these records would be linked to a single, unique patient identifier---a 'golden record' that would follow him throughout his life. In the United States, we do not have a national patient identifier. Each hospital, clinic, and health system must create its own system for identifying patients. This is the challenge that the Master Patient Index (MPI) is designed to solve. |
The MPI is the foundational identity management system within the HIS. It is the 'source of truth' for patient identity. It ensures that every patient has a unique, persistent identifier (the Medical Record Number, or MRN) that is linked to all of their data---demographics, visits, lab results, medications, allergies, and more. |
The MPI is not a simple database; it is a complex system that must manage duplicates, handle name variations, correct errors, and merge records when a patient is found to have multiple identities. It is the 'deduplicator' that ensures that a patient's complete health history is available to clinicians, regardless of where the care was provided. |
This chapter will take you inside the MPI of a modern American healthcare organization. We will explore how it works, the challenges of patient matching, the consequences of MPI failure, and the future of identity management. |

|
2. The Evolution of Patient Identification in the U.S. |
The history of patient identification reflects the evolution of healthcare itself. |
The pre-digital era (pre-1960s): Patient identification was simple---and simplistic. Patients were often identified by name and sometimes by a rudimentary chart number. There was no standardized system. Records were kept locally, and there was no expectation that they would follow the patient. |
The early digital era (1960s-1990s): As hospitals began to adopt computerized systems, they created local patient identifiers (MRNs). However, each hospital had its own MRN system. There was no cross-institutional identification. A patient would have a different MRN at each hospital they visited. |
The MPI era (1990s-2000s): The emergence of enterprise-wide HIS and the need for integrated care drove the development of the Master Patient Index. Health systems with multiple hospitals and clinics created an Enterprise MPI (EMPI) that linked the local MRNs from each facility to a single, enterprise-wide identifier. |
The interoperability era (2000s-present): With the rise of Health Information Exchanges (HIEs) and the push for interoperability, the need for cross-organizational patient matching has become critical. The MPI must now be able to match patients across different organizations, using probabilistic matching and other sophisticated techniques. |
The AI era (emerging): Artificial intelligence is being used to improve patient matching, using machine learning to identify patterns that are not easily captured by traditional algorithms. |

|
3. What Is a Master Patient Index |
The Master Patient Index (MPI) is a central database that contains a unique record for every patient who has ever been treated by a healthcare organization. It is the 'source of truth' for patient identity. |
The MPI record: Each MPI record includes: |
The unique identifier (MRN): A persistent, internal identifier that is unique to the patient. |
Demographic data: Name, date of birth, gender, address, phone number, email, social security number (sometimes), and other identifiers (e.g., driver's license number). |
Aliases: Previous names, misspellings, and variations of the name. |
Links to local records: The local MRNs that are used in each facility (e.g., the MRN from the main hospital, the MRN from the clinic, the MRN from the lab). |
Audit trail: A record of every change made to the MPI record, including when it was made and by whom. |
The enterprise MPI (EMPI): |
In a multi-facility health system, the EMPI is the central index that links all the local MRNs across all the facilities. The EMPI creates a 'golden record' that represents the patient across the entire enterprise. |

|
4. The Patient Matching Challenge |
The core function of the MPI is patient matching---the process of identifying if two or more records refer to the same patient. This is a surprisingly difficult problem. |
Why is patient matching difficult |
Name variations: People change their names (through marriage, divorce, adoption). Names can be misspelled. A patient might use a nickname ('Bob' for 'Robert'). The name might be entered differently in different systems ('Jonathan' vs. 'Jon'). |
Date of birth errors: The date of birth may be entered incorrectly. The year, month, or day may be transposed. |
Address changes: People move frequently. An old address may not be updated in all systems. |
Social security number issues: SSNs are not always collected, and they can be mis-entered. |
Common names: There are many 'John Smiths' and 'Maria Garcias.' Distinguishing between two patients with the same name and similar demographics is challenging. |
Data entry errors: Typos are common. A '5' might be entered as a '6,' or a 'Smith' might be entered as 'Smyth.' |
Legacy data: Data from legacy systems may be of poor quality. |
Different systems: Different systems may use different data fields (e.g., one system uses 'middle initial,' another uses 'middle name'). |
The consequences of matching errors: |
Duplicate records (under-match): The same patient has two separate records. This means that the patient's health history is split across two records. A clinician might miss a critical piece of information (e.g., an allergy, a previous diagnosis) that is in the other record. |
Overlay (over-match): The records of two different patients are merged into a single record. This is much more dangerous. A patient might receive the wrong medication, be treated for the wrong condition, or have their insurance denied. |
Financial consequences: Duplicate records can lead to duplicate billing or missed charges. |
Regulatory consequences: Patient matching errors can lead to HIPAA violations and regulatory fines. |

|
5. Patient Matching Algorithms: Probabilistic vs. Deterministic |
There are two main approaches to patient matching. |
Deterministic Matching: |
This method uses exact matches on specific fields. For example, if the first name, last name, and date of birth all match exactly, the records are considered a match. |
The advantages: It is simple and computationally inexpensive. |
The disadvantages: It is not very effective. A single typo (e.g., 'Smith' vs. 'Smyth') will cause the match to fail. |
Probabilistic Matching: |
This method uses statistical algorithms to calculate the likelihood that two records refer to the same patient. It assigns weights to each field, based on how discriminating the field is. For example: |
- A matching date of birth is a very strong indicator (high weight). |
- A matching last name is a moderately strong indicator. |
- A matching address is also a moderately strong indicator. |
- A matching first name is less discriminating (because many people share first names). |
The algorithm calculates a total score. If the score is above a certain threshold, the records are considered a match. If the score is below a certain threshold, they are considered a non-match. If the score is in the 'gray zone,' the records are flagged for manual review. |
The advantages: It is more effective than deterministic matching. It can handle typos, name variations, and missing data. |
The disadvantages: It is more complex and computationally expensive. It requires careful tuning of the weights and thresholds. |
The Role of Machine Learning: |
Machine learning is increasingly used to improve patient matching. ML algorithms can learn from historical data to identify complex patterns that are not captured by simple probabilistic matching. They can also automatically adjust the weights and thresholds over time. |

|
6. The MPI and the EHR: A Critical Link |
The MPI is the foundation of the EHR. Every other module---the clinical documentation module, the lab module, the pharmacy module, the billing module---uses the MPI to identify patients. |
How it works: |
1. A patient arrives at a hospital or clinic. |
2. The registration clerk searches the MPI for the patient's existing record. They may use name, date of birth, and other identifying information. |
3. If a match is found, the patient is linked to their existing MPI record. Their existing MRN is used. |
4. If no match is found, a new MPI record is created, and a new MRN is assigned. |
5. Every subsequent encounter (visit, lab test, medication order) is linked to the MPI record via the MRN. |
7. MPI Governance and Data Quality |
The MPI is only as good as the data that is entered into it. Data quality and governance are essential. |
Data quality standards: |
Standardized fields: The MPI should use standardized fields (e.g., first name, last name, date of birth, gender) with consistent formatting. |
Data validation: The system should validate data as it is entered (e.g., ensuring that the date of birth is a valid date). |
Duplicate prevention: The system should try to prevent duplicates from being created in the first place, by searching for existing records before creating a new one. |
Data cleansing: The system should periodically check for duplicates and merge them. It should also identify and correct errors in the data. |
MPI governance: |
Ownership: A designated individual or team should be responsible for the MPI. |
Policies and procedures: Clear policies and procedures should be in place for patient registration, data entry, duplicate management, and record merging. |
Training: Staff must be trained on proper data entry procedures. |
Auditing: The MPI should be audited regularly to ensure data quality and accuracy. |
Data stewardship: A data steward should be responsible for maintaining the quality of the data. |

|
8. The Patient's Role in Identity Management |
Patients can also play a role in managing their own identity. |
Patient portals: Patients can view and update their own demographic information through the patient portal. This can help to correct errors and to keep the data up to date. |
Patient self-identification: When a patient arrives for a visit, they can be asked to verify their identity (e.g., by showing a driver's license). This helps to ensure that the correct record is being accessed. |
Patient consent: In some cases, patients may be asked to consent to the linking of their records across different organizations (e.g., through an HIE). |

|
9. Biometrics and the Future of Patient Identification |
Biometrics---the use of unique physical characteristics---is emerging as a promising solution to the patient matching problem. |
Types of biometrics: |
Fingerprints: A widely used and cost-effective method. |
Facial recognition: Becoming more common, particularly with the proliferation of smartphone cameras. |
Iris scanning: Very accurate but more expensive. |
Palm vein scanning: Used in some healthcare settings. |
The advantages of biometrics: |
Uniqueness: Biometric traits are unique to each individual. |
Stability: Biometric traits are stable over time. |
Ease of use: Biometric identification can be quick and convenient. |
The challenges of biometrics: |
Privacy concerns: Patients may be concerned about the collection and storage of biometric data. |
Cost: Implementing a biometric system can be expensive. |
Technical limitations: Biometric systems can sometimes fail (e.g., if a finger is dirty or a face is partially obscured). |
Security: Biometric data must be protected from theft. |

|
10. U.S. Case Study: Kaiser Permanente's Enterprise MPI |
Kaiser Permanente is one of the largest integrated health systems in the United States. It serves over 12 million members across multiple states. |
Scale: Kaiser's EMPI contains records for over 12 million patients. |
Integration: The EMPI is fully integrated with Kaiser's Epic EHR, its patient portal, and its other systems. |
Matching: Kaiser uses a sophisticated probabilistic matching algorithm, combined with manual review for 'gray zone' cases. |
Data quality: Kaiser has a strong focus on data quality, with a dedicated team for MPI governance and data stewardship. |
Outcomes: Kaiser's EMPI has a very high match rate and a low incidence of duplicate records. This is a key enabler of Kaiser's integrated care model. |

|
11. U.S. Case Study: A Community Hospital's MPI Improvement Project |
A 200-bed community hospital in the Midwest was struggling with a high rate of duplicate records. |
The problem: The hospital had over 10,000 duplicate records, representing about 5% of its patient population. This was causing patient safety issues (missed allergies, wrong medications), billing errors, and clinician frustration. |
The solution: The hospital implemented an MPI improvement project, which included: |
Data quality audit: A comprehensive audit of the MPI data to identify and correct errors. |
Algorithm tuning: The hospital's probabilistic matching algorithm was tuned to improve its sensitivity. |
Staff training: Registration staff were retrained on proper data entry procedures. |
Duplicate review and merging: A dedicated team was assigned to review and merge duplicate records. |
New registry design: A new patient registration form was designed to collect more complete and accurate data. |
Outcomes: The hospital reduced its duplicate rate from 5% to less than 1%. Patient safety improved, billing errors decreased, and clinician satisfaction improved. |

|
12. U.S. Case Study: A Regional HIE's Patient Matching Challenges |
A regional Health Information Exchange (HIE) in a large metropolitan area faces the challenge of matching patients across dozens of different healthcare organizations. |
The challenge: The HIE must match patients from hospitals, clinics, and labs that use different EHR vendors, different data formats, and different data quality standards. |
The solution: The HIE uses a sophisticated probabilistic matching engine that combines demographic data from all participating organizations. The engine also uses a 'master patient index' that is maintained by the HIE. |
The challenges: |
Data quality: The quality of the data from different organizations varies significantly. |
Governance: The HIE must have clear policies and procedures for patient matching, and all participating organizations must agree to them. |
Privacy: The HIE must protect patient privacy while still enabling data sharing. |
Outcomes: The HIE's matching engine has a high match rate, enabling clinicians to access a more complete patient record across the region. |

|
13. MPI and the 'Golden Record' Concept |
The goal of the MPI is to create a 'golden record' for each patient---a single, authoritative, and complete record that represents the patient's identity across all encounters and all systems. |
The golden record includes: |
The unique patient identifier: The MRN. |
The most accurate demographic data: The data that is considered to be the most reliable. |
Links to all local records: The MRNs from each facility where the patient has been treated. |
Maintaining the golden record: The golden record must be continuously updated as new data is received and as errors are corrected. |

|
14. MPI and the 'Identity Resolution' Process |
Identity resolution is the process of determining whether two or more records refer to the same patient. It is a core function of the MPI. |
The identity resolution process: |
1. Search: A search is performed for an existing patient record. |
2. Candidate selection: A set of candidate records is identified that may match the search criteria. |
3. Score calculation: A score is calculated for each candidate record, using a probabilistic matching algorithm. |
4. Decision: Based on the score, the system decides whether the candidate is a match, a non-match, or a possible match (requiring manual review). |
5. Action: If the match is confirmed, the patient is linked to their existing record. If a possible match is identified, the record is sent for manual review. |

|
15. MPI and Data Governance: The Stewardship of Identity |
Data governance is the framework of policies, procedures, and responsibilities that ensure the quality and integrity of the MPI data. |
Key governance elements: |
Data standards: Defining the format and content of the demographic data. |
Data quality rules: Defining the rules for data validation and duplicate detection. |
Data stewardship: Assigning a person or team to be responsible for the quality of the data. |
Auditing: Regularly auditing the data for accuracy and completeness. |
Training: Training staff on the importance of data quality and on proper data entry procedures. |
Change management: Managing changes to the MPI system and to the data. |

|
16. The Cost of MPI Failure |
The consequences of MPI failure are significant. |
Clinical consequences: |
Missed allergies: A patient's allergy list is not available to the clinician. |
Medication errors: The clinician prescribes a medication that is contraindicated. |
Missed diagnoses: The clinician does not see a previous diagnosis or a critical lab result. |
Duplication of tests: Redundant tests are performed. |
Patient safety events: The patient experiences a preventable adverse event. |
Financial consequences: |
Duplicate billing: The hospital bills for the same service twice, leading to a denial. |
Missed charges: The hospital fails to bill for a service that was provided. |
Increased administrative costs: Staff spend more time on resolving duplicate records and correcting errors. |
Reputational consequences: |
Patient dissatisfaction: Patients are frustrated by administrative errors. |
Loss of trust: Patients may lose trust in the healthcare organization. |

|
17. The Future of MPI: AI, Blockchain, and the National Patient Identifier Debate |
The MPI is evolving rapidly, driven by new technologies and policy discussions. |
AI-powered matching: AI will continue to improve patient matching, using advanced machine learning models to identify patterns that are not captured by traditional algorithms. |
Blockchain for identity management: Some researchers are exploring the use of blockchain to create a decentralized, secure, and patient-controlled identity management system. |
Biometrics: Biometrics will become more widely adopted, providing a more reliable and convenient way to identify patients. |
The national patient identifier debate: The U.S. is one of the few developed countries that does not have a national patient identifier. There is an ongoing debate about whether to create one. Proponents argue that it would solve many of the problems of patient matching. Opponents argue that it would create privacy and security risks. |

|
18. The Human Element: The MPI as a Patient Safety Tool |
The MPI is not just a technical system; it is a patient safety tool. It is essential for ensuring that the right care is delivered to the right patient. |
The MPI in the emergency department: When a patient arrives in the ED, the clinician needs quick access to the patient's medical history. The MPI ensures that the patient's record is available. |
The MPI in the OR: Before surgery, the surgical team must verify the patient's identity. The MPI is the source of that verification. |
The MPI in the pharmacy: The pharmacist must verify that the medication is being dispensed to the correct patient. The MPI is the source of that verification. |

|
Detailed Concluding Summary |
This chapter has provided a comprehensive, plain-English exploration of the Master Patient Index (MPI)---the foundational identity management system that ensures every patient is uniquely and accurately identified across all encounters, facilities, and time in the U.S. healthcare system. We began by framing the MPI as the essential 'deduplicator' and 'source of truth' for patient identity, upon which all clinical, administrative, and financial functions of the HIS depend. |
We traced the evolution of patient identification from the pre-digital era of simple, local identification to the modern era of enterprise MPIs and cross-organizational matching. We defined the MPI and the Enterprise MPI (EMPI), describing the MPI record with its unique MRN, demographic data, aliases, links to local records, and audit trail. |
We dove deep into the patient matching challenge, explaining why it is so difficult due to name variations, date of birth errors, address changes, data entry errors, common names, and legacy data issues. We described the serious consequences of matching errors, including duplicate records (under-match), overlays (over-match), and the resulting clinical, financial, and regulatory consequences. |
We explored the two main matching algorithms: deterministic matching (exact matches) and probabilistic matching (statistical scoring). We detailed the advantages and disadvantages of each and introduced the emerging role of machine learning to improve matching accuracy. We discussed the MPI's critical link to the EHR and every other clinical and administrative module. |
We emphasized the importance of MPI governance and data quality, outlining standards for standardized fields, data validation, duplicate prevention, data cleansing, and the roles of ownership, policies, training, auditing, and data stewardship. We noted the patient's role in identity management through patient portals and self-verification. We explored the promise of biometrics (fingerprints, facial recognition, iris scanning, palm vein scanning) for future patient identification, while acknowledging the challenges of privacy, cost, technical limitations, and security. |
We presented three U.S. case studies: Kaiser Permanente's successful EMPI, with its sophisticated matching algorithm, strong governance, and high match rate; a community hospital that reduced its duplicate record rate from 5% to less than 1% through an MPI improvement project involving data audits, algorithm tuning, staff training, and duplicate review; and a regional Health Information Exchange that overcame the challenges of matching patients across multiple organizations with disparate EHRs and data quality standards. |
We discussed the concept of the 'golden record' as the single, authoritative patient identity. We detailed the identity resolution process of search, candidate selection, score calculation, decision, and action. We explored the cost of MPI failure, with clinical consequences (missed allergies, medication errors, missed diagnoses), financial consequences (duplicate billing, missed charges, increased administrative costs), and reputational consequences (patient dissatisfaction, loss of trust). |

|
Finally, we looked to the future of MPI: AI-powered matching, blockchain for decentralized identity management, wider adoption of biometrics, and the ongoing national patient identifier debate. We emphasized the MPI as a patient safety tool, essential in the ED, the OR, and the pharmacy. |
In conclusion, the MPI is not merely a technical tool; it is the essential 'source of truth' for patient identity. In a healthcare system without a national patient identifier, the MPI is the critical infrastructure that ensures that every patient is correctly identified, that their records are complete and accessible, and that care is delivered safely and effectively. A flawed MPI means flawed care, flawed billing, and flawed outcomes. A well-designed and well-governed MPI, by contrast, is the foundation upon which all other clinical and administrative functions depend---and upon which the promise of a connected, patient-centered healthcare system can be built. In the complex, fragmented, and data-rich world of American healthcare, the MPI is the unsung hero that keeps identities straight, records complete, and patients safe. |