iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
De-identified means information has been processed to reduce the chance that it can be connected to a particular person. It does not necessarily mean names are the only identifiers removed, that every identifying clue is gone, or that re-identification is impossible. Whether a record can still point to someone depends on what it contains, who receives it, and what other information is available to make a match.
There is no single definition in the sources here that applies to every dataset, law, or jurisdiction. The clearest specific example is the U.S. HIPAA standard for protected health information, which provides two ways to determine that information is de-identified.
What can make a record identifiable after names are removed?
Identification can come from a combination of details rather than a name or account number. A distinctive pattern in a record may become identifying when compared with information the recipient already has or can reasonably obtain. The relevant question is not only whether obvious identifiers were deleted, but whether the remaining data can reasonably be linked to a person in its intended context.
Quick wins for a faster PC:
Clear out junk files and repair common Windows errorsFree Scan →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →For example, dates, geographic details, unusual characteristics, or a unique sequence of events may narrow a record to one person when combined with other information. This is why removing names alone does not establish that a dataset is anonymous. The risk depends in part on the anticipated recipient and the information available to that recipient. HHS explains this context-sensitive approach in its guidance on de-identifying protected health information.
#1 Best Overall
What does de-identified mean under HIPAA?
HIPAA is a U.S. health-information framework, not a universal definition for every kind of personal data. Under the HIPAA Privacy Rule, health information is de-identified when it does not identify an individual and there is no reasonable basis to believe it can be used to identify one. HHS recognizes two methods for meeting that standard: Safe Harbor and Expert Determination.
| Method | What it requires | What supports the determination |
|---|---|---|
| Safe Harbor | Remove the specified categories of identifiers and have no actual knowledge that the remaining information could identify the individual. | The required identifier removals and the no-actual-knowledge condition. See HHS’s HIPAA Privacy Rule summary. |
| Expert Determination | An appropriately knowledgeable expert applies generally accepted statistical or scientific methods and concludes that the risk of identification is very small for the anticipated recipient, considering reasonably available information. | The expert documents the methods and results. HHS does not set one universal numerical cutoff for “very small.” See HHS de-identification guidance. |
Neither method is categorically safer or preferable in every situation. They are different HIPAA pathways, and which one fits depends on the information and its intended use. The table describes HIPAA’s specific health-information framework; it should not be treated as a test that every organization or dataset must use.
Safe Harbor: a defined removal checklist plus a knowledge condition
Safe Harbor requires removing listed identifiers, including names, certain small-area geographic details, specified date elements, and other identifying information. It also requires that the organization have no actual knowledge that information left in the dataset could identify the person. That second condition matters: completing a removal checklist is not enough if the organization knows the remaining details can identify someone.
Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteWindows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallRank #2
Expert Determination: a documented, recipient-aware assessment
Under Expert Determination, an appropriately knowledgeable expert considers the data, the anticipated recipient, and reasonably available information, then applies generally accepted statistical or scientific methods to find the identification risk very small. The expert must document the analysis and its results. HHS has not defined a universal percentage for “very small,” so a particular risk threshold should not be presented as a HIPAA-wide numeric rule.
Does de-identified mean re-identification is impossible?
No. De-identification reduces risk; it does not guarantee that the risk is zero. HHS says that information prepared under either HIPAA method can retain a small, nonzero risk of linkage to a patient. In its health-information guidance, HHS puts it this way: “Although the risk is very small, it is not zero, and there is a possibility that de-identified data could be linked back to the identity of the patient to which it corresponds.”
Risk is tied to circumstances, not just the dataset in isolation. A recipient’s access to other data, the purpose of sharing, and the information reasonably available for comparison can affect whether a match is feasible. HHS also notes that technology, social conditions, and the availability of information change over time; a risk assessment should not be treated as permanently valid regardless of those changes.
Why hashing does not automatically make data anonymous
Hashing transforms an input into a coded value, but a stable hash can still allow records to be matched or users to be tracked. The Federal Trade Commission (FTC) warns that hashed identifiers may still identify users; see its July 2024 article, “No, hashing still doesn’t make your data anonymous.” A hash should therefore not be treated as an anonymity switch without considering how it is used and what other information can be linked to it.
The Tool Desk
Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →What responsible de-identification involves beyond changing the data
Technical measures are only part of the picture. In its business guidance for mobile health app developers, the FTC recommends reasonable measures to reduce re-identification risk, keeping pace with technological developments, publicly committing not to re-identify data, requiring downstream recipients to make contractual commitments not to do so, and providing oversight. The FTC’s practical criterion is: “A key to effective de-identification is to ensure that the data cannot be reasonably re-identified.”
These are FTC recommendations for businesses, not additional steps in HIPAA’s formal two-method test. Their practical point is that access, recipient behavior, and governance can affect privacy risk even after data has been altered. See the FTC’s Mobile Health App Developers best practices.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.How to read a claim that data is de-identified
When a company or researcher describes information as de-identified, the label alone does not tell you the method or the residual risk. Useful questions include:
- What was removed or transformed? Find out whether the process addressed only direct identifiers or also combinations of details that could distinguish someone.
- What standard or assessment was used? If the claim is about HIPAA, ask whether it relies on Safe Harbor or Expert Determination. Outside HIPAA, ask what the organization means by the term rather than assuming the HIPAA methods apply.
- Who will receive the data, and what else can they access? The intended recipient and reasonably available linking information affect identification risk.
- What limits apply to recipients? Look for commitments against re-identification, downstream contractual restrictions, and oversight.
- Will the assessment be revisited? New data sources, technical capabilities, or social conditions can change the practical risk of linking records.
NIST describes de-identification as a privacy-risk reduction practice and discusses different ways to share government data, including public release, synthetic data, query interfaces, and protected enclaves. These are options for different sharing contexts, not interchangeable guarantees of anonymity. See NIST’s overview of de-identification and NIST SP 800-188, De-Identifying Government Datasets: Techniques and Governance.
Do these 3 things before closing this tab:
1Scan for outdated or missing drivers - takes under a minute2Repair Windows errors before they cause bigger problems3Fix the driver behind crashes, sound loss and screen glitchesWhether a particular dataset meets HIPAA’s requirements or another law’s rules depends on its facts and applicable law. The HIPAA methods and FTC business recommendations described here do not establish compliance for any specific dataset.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

