Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

For data covered by HIPAA, do not rely on a label such as “anonymous” or on the removal of names. Ask which of HIPAA’s two recognized methods was used—Safe Harbor or Expert Determination—and request evidence that the method was applied to the specific dataset and release. Both methods reduce identification risk; neither guarantees that re-identification is impossible.

HIPAA is not a universal test for every health dataset. First establish what law or policy governs the data, who created it, which version is being shared, and who will receive it.

What does “de-identified” mean under HIPAA?

HIPAA’s de-identification standard applies to protected health information (PHI) within the Privacy Rule’s scope. The regulation recognizes two routes: Safe Harbor and Expert Determination. A creator’s statement that data is “de-identified” is not enough to show which route was used or whether its requirements were met. Review the HHS Office for Civil Rights guidance and the HIPAA Privacy Rule regulation for the governing standard.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Safe Harbor

Safe Harbor requires removal of specified identifiers and that the covered entity have no actual knowledge that the remaining information could identify an individual, alone or in combination with other information. Ask for evidence addressing both parts—not just a list of fields removed.

Expert Determination

Under Expert Determination, a person with appropriate knowledge and experience in generally accepted statistical and scientific principles and methods documents that the risk is very small that the anticipated recipient could identify an individual using the data alone or with other reasonably available information. Ask for the analysis and its assumptions, not simply the expert’s conclusion.

These methods are alternatives, not a checklist in which every dataset must satisfy both. A dataset may use either route, but the claim should identify which one applies and what evidence supports it.

How do the two methods differ?

Question Safe Harbor Expert Determination
What is assessed? Whether the specified identifier categories have been handled and the covered entity has no actual knowledge that the remaining information could identify someone. Whether identification risk is very small for the anticipated recipient and reasonably available information.
What evidence should be available? Documentation or review showing how each identifier category and relevant exception was handled, plus the no-actual-knowledge condition. The expert’s qualifications and documented methods and results, including the data, recipient, and assumptions covered.
How is risk addressed? Through specified removals and the no-actual-knowledge condition. Through a contextual analysis that may account for the data, recipient, outside information, and mitigations.
What should not be assumed? That removing names alone is enough. That HIPAA supplies a single numerical cutoff that automatically establishes very small risk.

Expert Determination can allow a different balance of data utility and disclosure risk than the prescribed Safe Harbor removals. But a dataset’s usefulness does not itself establish that it meets the legal standard. HHS says there is no universal numerical level of identification risk that defines “very small” for Expert Determination; the analysis must be supported by its methods and context. See the HHS guidance on Expert Determination.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What to check if the dataset claims Safe Harbor

Safe Harbor addresses more than names. Compare the dataset and its supporting review against the regulatory categories below. The list summarizes the identifiers specified in 45 CFR § 164.514(b)(2); it is not a substitute for checking the full rule and its exceptions.

  • Names.
  • Geographic subdivisions smaller than a state, subject to the limited exception for initial three-digit ZIP Code areas.
  • Dates directly related to an individual, except year; for individuals older than 89, ages and date elements that would indicate such an age must be aggregated into a single category of age 90 or older.
  • Telephone numbers and fax numbers.
  • Email addresses.
  • Social Security numbers.
  • Medical record numbers and health plan beneficiary numbers.
  • Account numbers and certificate or license numbers.
  • Vehicle identifiers and serial numbers, including license plate numbers.
  • Device identifiers and serial numbers.
  • Web URLs and Internet Protocol (IP) addresses.
  • Biometric identifiers, including finger and voice prints.
  • Full-face photographs and comparable images.
  • Any other unique identifying number, characteristic, or code, subject to the rule’s specific provisions.

The review must look at values wherever they appear, not only at column headings. HHS says the identifier requirements apply to free-text fields too. Check narrative notes, document contents, filenames, embedded files, and other places where recognizable details might be present. A spreadsheet with no obvious identifier columns can still contain identifying information in its cells or attachments.

What to request for an Expert Determination

Ask for the documentation required by the rule: the expert’s methods and results. To understand whether the conclusion fits your intended use, request enough detail to identify the scope and assumptions, including:

  • The expert’s relevant qualifications.
  • The dataset, version, and release covered by the assessment.
  • The intended recipient and the access or environment assumptions used.
  • The methods applied, the results, and any mitigations made to reduce risk.
  • When the assessment was completed and what changes in data, recipient, or release conditions would require it to be reconsidered.

HHS guidance points to factors including whether data features are replicable or stable, what external information is available, and how easily records can be distinguished. These factors help explain the assessment; they do not create a universal checklist or numeric threshold. The conclusion should be about a defined release and context, not an unsupported promise that the data is anonymous in every setting.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How release context can change the assessment

Identification risk depends partly on what a recipient can reasonably access and combine with the dataset. Ask whether other datasets could be linked to it, whether multiple versions are available, who can access the data, and whether release conditions affect the recipient’s capabilities. A determination for one recipient or environment does not automatically establish the same risk after the data or access conditions change.

A data-use agreement or other safeguards can limit access or add protections, but an agreement alone does not satisfy Safe Harbor or Expert Determination. HHS treats safeguards as distinct from meeting the requirements of a de-identification method. See the HHS de-identification guidance.

Can de-identified health data be re-identified?

Yes. Properly applied, either method leaves some residual risk. HHS OCR’s guidance, published November 26, 2012, states: “Both methods, even when properly applied, yield de-identified data that retains some risk of identification.” It adds that the risk is very small, not zero, and that linking data back to a patient is possible. The meaningful question is therefore whether the appropriate standard was met for the defined data and disclosure—not whether anyone can guarantee zero risk.

What a credible de-identification claim should say

Look for a statement that names the method and its scope. For example: “HIPAA Safe Harbor was applied to version X,” supported by a review of the specified categories and the no-actual-knowledge condition; or “An expert documented a very-small-risk determination for recipient and use Y,” with methods and results available for review. A bare claim of “fully anonymous” does not explain the standard, evidence, or context.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

For legal reliance, confirm the current regulation and the facts governing the dataset, recipient, and release. HIPAA may not apply to every health-related dataset, and satisfying HIPAA’s de-identification standard does not answer every privacy-law question. HHS’s HIPAA Privacy Rule overview provides background on the rule’s scope.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.