US Federal Law United States

HIPAA De-identification: Safe Harbor, Expert Determination

The two HIPAA de-identification methods under 45 CFR 164.514: the 18 Safe Harbor identifiers, expert determination standards, re-identification risk, and limited data sets.

Regulation

HIPAA Privacy Rule, 45 CFR 164.514(a)-(c); OCR Guidance Regarding Methods for De-identification of PHI (2012)

Max Penalty

Improperly de-identified data remains PHI; its disclosure is an impermissible disclosure carrying full civil penalty exposure and breach notification duties

Enforcing Authority

HHS Office for Civil Rights (OCR)

Official Source

www.hhs.gov

Executive Summary

  • Properly de-identified health information is not PHI and leaves HIPAA entirely; 45 CFR 164.514 provides exactly two routes: Safe Harbor and Expert Determination.
  • Safe Harbor requires removing all 18 enumerated identifier categories (names, geography smaller than state with a zip-code carve-down, all date elements except year, and more) plus no actual knowledge the remainder could identify someone.
  • Expert Determination requires a qualified statistician or scientist to document that re-identification risk is very small given anticipated recipients, methods, and available data.
  • The limited data set is the middle path: dates and some geography retained, disclosed only for research, public health, or operations under a data use agreement.
  • De-identification failures are breaches in disguise: data that flunks the standard is PHI, and its release triggers notification and penalty exposure retroactively.

De-identification is HIPAA’s exit door, and the rule guards it with mathematics rather than intent. Safe Harbor is mechanical and brittle: eighteen identifier categories out, plus an honest answer to whether what remains could still point at someone. Expert determination is flexible and evidentiary: a documented statistical case that re-identification risk is very small for these recipients, in this world of linkable data. Pick wrong, or scrub carelessly, and the dataset you shipped was PHI all along, with breach clocks running from a release you thought was free.

Route 1Safe Harbor: remove 18 identifier categories + no actual knowledge
Route 2Expert Determination: documented very-small risk
Middle pathLimited data set + data use agreement (still PHI)
Rule45 CFR 164.514
Failure modeImproper de-identification = impermissible disclosure

Making de-identification defensible

Match method to use case. Year-only dates kill most research value; if dates matter, the limited data set or expert determination usually beats Safe Harbor, the compliance roadmap situates the decision.

Test outputs, not process. Small-cell checks, free-text and metadata scans, and linkage testing catch what field deletion misses.

Paper the pipeline. The expert determination memo, DUAs, and re-identification prohibitions are six-year artifacts; vendor de-identification work needs BAA authority first.

Watch the adjacent regimes. State health-data laws and FTC anonymization claims run on broader definitions; OCR enforcement trends cover the federal side.

Analytics fed by web and portal data raises the same identifiability questions: see what your site collects with a free scan.

Frequently Asked Questions

What exactly must Safe Harbor remove?

The 18 categories in 164.514(b)(2): names; geographic subdivisions smaller than a state (the first three zip digits survive only if the zone exceeds 20,000 people, otherwise 000); all date elements except year (admission, discharge, birth, death), with ages 90+ aggregated; telephone and fax numbers; email addresses; SSNs; medical record numbers; health plan numbers; account numbers; certificate and license numbers; vehicle identifiers including plates; device identifiers and serials; URLs; IP addresses; biometric identifiers; full-face photos and comparable images; and any other unique identifying number, characteristic, or code. Plus the second prong everyone forgets: the covered entity must have no actual knowledge the remaining information could identify the individual, a rare diagnosis in a small town can fail that test with all 18 boxes checked.

How does Expert Determination work?

A person with appropriate knowledge of statistical and scientific methods for rendering information not individually identifiable applies those methods and documents that the risk is very small that the information could be used, alone or with other reasonably available information, by an anticipated recipient to identify the subject. The analysis is context-specific: it weighs who receives the data, under what controls, and what external datasets exist for linkage, meaning the same dataset can pass for one recipient and fail for another. The determination is a written, retained artifact (six years), typically with an expiration or re-evaluation trigger since external data availability changes. There is no certification body; qualification is demonstrated by training and experience, and OCR's 2012 guidance describes the accepted approaches.

What is a limited data set and when is it the better tool?

A dataset stripped of 16 direct identifiers but retaining dates, city, state, and zip, disclosed only for research, public health, or health care operations, under a data use agreement binding the recipient to safeguards, no re-identification or contact attempts, and flow-down to agents. It is the workhorse for research and analytics where dates drive the science (survival analysis, epidemiology, readmission studies) and Safe Harbor's year-only rule would destroy utility. But it remains PHI: breach notification applies, minimum necessary applies, and the DUA is mandatory. Choose Safe Harbor or expert determination when you need data outside HIPAA entirely; choose the limited data set when you need dates and can keep the data inside a controlled relationship.

Can we use de-identified data for AI training or sale?

Once information is properly de-identified under either method it is no longer PHI, and HIPAA does not restrict its use, training models, benchmarking, licensing to third parties. Three cautions before treating that as a green light. First, the de-identification itself is a use of PHI that must be permissible, and a business associate needs BAA authority to de-identify. Second, re-identification converts everything back: a recipient who links the data to identities is creating PHI, and your contracts should prohibit attempts. Third, other regimes may still apply, state laws like Washington's My Health My Data define consumer health data more broadly, and the FTC polices deceptive claims about anonymization. 'HIPAA de-identified' is a specific technical status, not a universal privacy clearance.

What are the classic re-identification failure modes?

Quasi-identifier convergence: the combination of zip, birth date, and sex famously identifies a large share of the US population, which is exactly why Safe Harbor attacks dates and small geography. Small cells: any subgroup of one, the only 94-year-old in the county with a given diagnosis, fails regardless of removed fields. Longitudinal linkage: visit sequences and rare event patterns can match public records or claims datasets. Derived identifiers: free-text notes carrying names, embedded accession numbers, image metadata, and pixel data (faces, tattoos) that survive structured-field scrubbing. Robust programs test outputs empirically, small-cell suppression, free-text scanning, linkage testing against public data, rather than trusting field deletion alone, because the standard is identifiability, not field count.

Regulatory Crosswalk

GDPR anonymization/pseudonymizationNIST SP 800-188FERPA de-identification

Organizations subject to this regulation often operate under these overlapping frameworks. BD Emerson maps controls across frameworks to reduce duplicated compliance effort.

Evaluate your compliance posture now

BD Emerson's automated scanner audits your public-facing properties against your applicable regulations in minutes, not weeks.