What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Before sharing health data for research, decide what protection standard applies, choose a documented de-identification method, and assess the data in the context of its recipient and likely access to other information. Under U.S. HIPAA, the two recognized methods are Safe Harbor and Expert Determination. Neither means zero re-identification risk, and removing names alone is not enough.
What “anonymize” means under HIPAA
Researchers often say “anonymize,” but HIPAA uses the term de-identification and sets out a specific U.S. legal standard. HHS describes two ways to meet it: Safe Harbor and Expert Determination. The regulation says health information is not individually identifiable when it does not identify a person and there is no reasonable basis to believe it can be used to identify them. That is not a promise that identification is impossible in every circumstance. See HHS OCR’s de-identification guidance and the HIPAA regulation text.
First confirm whether HIPAA applies to the organization and data in question. Then check whether human-subjects protections, institutional rules, agreements, or laws in other jurisdictions also govern the project. HIPAA de-identification does not by itself settle those separate requirements; HHS explains that HIPAA and human-subjects rules can operate independently (HHS overview of HIPAA privacy standards).
Choose between Safe Harbor and Expert Determination
Both are HIPAA routes, but they answer the release question differently. Safe Harbor applies prescribed removals and conditions; Expert Determination assesses the risk for a particular release context. Neither route is universally best: weigh the needed research detail against residual identification risk, the recipient, and whether a qualified assessment can be documented.
Recommended Free Tools
#1 Best Overall
- Certified to FIPS 197 - High-level information security standard approved by the U.S. Government
- Brute-Force Password Attack Protection - Data is automatically erased after 6 failed access attempts. The data and encryption key are securely destroyed and the crypto drive is reset
- Rugged Double-Layer Waterproof* Design - Protects the crypto drive against knocks, drops, break-in and submerging in water. The electronics are shielded by a hardended inner case. The rubberised silicone outer casing provides a final layer of protection
- Auto-lock - The crypto drive will automatically encrypt all data and lock when removed from a PC/Mac or when the screen saver or "computer lock" function is activated on the host PC/Mac
- Secure Entry - Data cannot be accessed without the correct high-strength alphanumeric 8-16 character password. A password hint option is available. The password hint cannot match the password
| Decision point | Safe Harbor | Expert Determination |
|---|---|---|
| What it requires | Remove the specified identifiers and satisfy the rule’s additional conditions. | A person with appropriate statistical and scientific expertise applies generally accepted principles to determine that identification risk is very small. |
| Who applies it | The covered entity applies the regulatory specification. | A qualified person makes the assessment and documents its methods and results. |
| How context matters | The rule includes the condition that the covered entity has no actual knowledge that remaining information could identify the person. | The assessment considers an anticipated recipient and information reasonably available to that recipient, including information combined with the data. |
| Likely effect on research detail | Removing or generalizing required fields can reduce analytic detail. | A tailored assessment can evaluate a particular release, but does not guarantee that all detail can be retained. |
| Documentation | Keep evidence that the specified removals and conditions were addressed. | Document the methods and results supporting the determination. |
This comparison follows HHS OCR guidance and the regulatory text.
What Safe Harbor requires you to remove
Safe Harbor is not just deleting names. It requires removal of the rule’s specified identifiers of the individual and specified relatives, employers, or household members, subject to the rule’s details and exceptions. The categories include:
Rank #2
- Certified to FIPS 197 - High-level information security standard approved by the U.S. Government
- Brute-Force Password Attack Protection - Data is automatically erased after 6 failed access attempts. The data and encryption key are securely destroyed and the crypto drive is reset
- Auto-lock - The crypto drive will automatically encrypt all data and lock when removed from a PC/Mac or when the screen saver or "computer lock" function is activated on the host PC/Mac
- Secure Entry - Data cannot be accessed without the correct high-strength alphanumeric 8-16 character password. A password hint option is available. The password hint cannot match the password
- SuperSpeed USB 3.0 - Transfer all your confidential files and folders faster than ever before. Works on both PC & Mac
- Names; geographic subdivisions smaller than a state, subject to the rule’s provisions; and most elements of dates directly related to an individual, other than year.
- Telephone and fax numbers; email addresses; Social Security numbers; medical record numbers; health plan beneficiary numbers; account numbers; and certificate or license numbers.
- Vehicle identifiers and serial numbers; device identifiers and serial numbers; web URLs; internet protocol addresses; and biometric identifiers, including finger and voice prints.
- Full-face photographs and comparable images; and any other unique identifying number, characteristic, or code, subject to HIPAA’s separate provisions for codes.
This is a reader-oriented summary, not a substitute for the complete rule. For example, the regulation has specific provisions for geographic detail, dates, and ages over 89. Check the full 45 CFR § 164.514 text before releasing data under Safe Harbor. The covered entity must also have no actual knowledge that the remaining information could identify the person.
When Expert Determination may fit better
Consider Expert Determination when the research needs fields or detail that are difficult to release under the prescribed Safe Harbor removals, and a person with appropriate statistical and scientific expertise can assess the specific disclosure. HHS describes the standard as a qualified person determining that the risk is “very small” that the information could identify someone, alone or combined with other reasonably available information, when used by an anticipated recipient (HHS OCR guidance, issued November 26, 2012).
Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Fix the driver behind crashes, sound loss and screen glitches3Clear out junk files and repair common Windows errorsRank #3
- Certified to FIPS 197 - U.S. Government Approved High Level Information Security Standard.
- Protection against brute force password attacks - Data is automatically erased after 6 unsuccessful access attempts. The data of the USB flash drive type c encryption with dual connectors is destroyed and the cryptographic drive is reset.
- Durable dual-layer waterproof design* — Protects the crypto reader from bumps, drops, run-in and immersion in water. The electronics are protected by a hardened internal case. Rubberized silicone outer case provides a final layer of protection.
- Auto-Lock —The cryptographic key automatically encrypts all data and locks when removed from a PC/Mac or when screen protection or "computer lock" is enabled.
- Secure Entry —Data on these flash drives cannot be accessed without the correct alphanumeric password of 8 to 16 characters. A password indication option is available for this flash drive. The hint cannot match the password.
The assessment is contextual, not a generic approval of a dataset. It should account for what the recipient is expected to receive, what other information is reasonably available, and how the records could be combined. A spreadsheet that deletes names, or an automated process that strips fields, is not by itself an Expert Determination. The qualified person must document the methods and results that support the conclusion.
How to prepare a release decision
- Define the release. Record who holds the data, who will receive it, why they need it, and whether it will be public, shared under an agreement, or accessed in a controlled environment. Recipient and access context are particularly important to Expert Determination.
- Confirm applicable rules. Establish whether HIPAA applies, then identify any additional IRB or Privacy Board, Common Rule, FDA, institutional, contractual, or jurisdictional requirements. Resolve whether approvals or permissions are needed independently of de-identification.
- Select the HIPAA route. Use Safe Harbor if its removals and conditions fit the data and research purpose. Consider Expert Determination when a qualified person can assess risk in the actual release context and document the basis for the decision.
- Review indirect identifiers and combinations. Examine values that may identify someone in combination, not just obvious direct identifiers. Consider how likely external information could connect a record to a person, particularly for the intended recipient.
- Minimize and protect. Keep only fields needed for the analysis. Restrict access and transfers, and, when using coded records, separate and govern access to any linkage mechanism.
- Document the decision. Record the method, responsible person, dataset version, transformations, assumptions, recipient context, and approval or release decision. For Expert Determination, preserve the expert’s methods and results.
- Reassess if the release changes. A different recipient, public posting, newly available linkage data, or changed dataset can alter the identification risk. Review the release decision when those conditions change.
Is removing names enough?
No. A record can lack names and still contain combinations of dates, locations, rare conditions, or other values that could point to an individual. The HIPAA standard explicitly considers information used alone or in combination with other reasonably available information. Review remaining fields in relation to the proposed recipient and release setting, rather than treating name removal as the finish line.
Rank #4
- FIPS 197 with XTS-AES 256-bit Encryption: Provides business-grade security with hardware-based encryption to protect your sensitive data
- Brute Force and BadUSB Attack Protection: Safeguards against unauthorized access attempts and malicious USB attacks with digitally-signed firmware
- Multi-Password Option with Complex/Passphrase modes: Offers flexible password configuration options to meet various security requirements and user preferences
- New Passphrase Mode: Enhanced security feature allowing users to create longer, more memorable password phrases for easier access without compromising protection
- Dual Read-Only (Write-Protect) Settings: Enables write protection functionality to prevent accidental data modification or deletion when needed
Can coded health data be shared?
Coding replaces direct identifiers with a code, but coded data should not automatically be treated as anonymous. HIPAA allows a code to be retained under specified conditions, including that it is not derived from or related to information about the individual and cannot otherwise be translated to identify them; the mechanism for re-identification must not be disclosed. Consult the regulatory text and the project’s applicable rules before treating coded data as de-identified. HHS OHRP also cautions that coded private information or biospecimens can raise separate human-subjects questions; its guidance discusses when investigators may or may not have access to identifiers or a key (OHRP coded information guidance, last reviewed December 30, 2022).
Does de-identification mean IRB review is unnecessary?
Not automatically. Whether a study requires IRB or Privacy Board review, or falls within a research exemption or other pathway, depends on the project and the rules that apply. HHS describes HIPAA privacy requirements and human-subjects protections as separate frameworks; determine the project’s status with the appropriate institutional officials rather than treating a HIPAA de-identification decision as a universal waiver (HHS overview of HIPAA privacy standards).
Quick Recap
Best Value
- FIPS 140-3 Level 3 (Pending) Certified Military-Grade Security
- OS/Device Independent
- XTS-AES Hardware Encryption
- Enforced Alphanumeric PIN
- Multi-PIN (Admin and User) Option
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

