De-Identification of Health Data
The HIPAA-defined process of removing identifiers from PHI so the resulting data is no longer subject to the Privacy Rule.
Definition
Under HIPAA, health information is de-identified when it cannot reasonably be used to identify an individual. HHS recognizes two methods: the Safe Harbor method (removal of 18 specified identifiers and no actual knowledge that the residual data could re-identify) and the Expert Determination method (a qualified expert applies statistical/scientific methods and documents that re-identification risk is very small). De-identified data is not PHI and not subject to HIPAA.What this means in practice
MedTech teams that want to use clinical data for AI/ML training, analytics, or research typically need de-identified data. Choosing Safe Harbor is procedurally simpler but data-utility-poor; Expert Determination preserves more analytic value but requires documented expert work and ongoing risk monitoring.- •Calling pseudonymized data 'de-identified' - pseudonymization preserves a re-identification key.
- •Combining de-identified datasets that, together, re-identify (the mosaic effect).
- •Skipping the Expert Determination documentation - without it, the data isn't legally de-identified.
Frequently asked questions
Related terms
Grouped by themeEditor's picks
· Hand-selected related conceptsU.S. federal law governing the privacy and security of protected health information.
U.S. law that strengthened HIPAA enforcement and introduced breach-notification requirements.
Individually identifiable health information (PHI) and its electronic form (ePHI) - the data class HIPAA protects.
More in Cybersecurity
· Same categoryAAMI/ANSI standard establishing requirements for medical-device cybersecurity activities throughout the lifecycle.
AAMI Technical Information Report providing MedTech-specific guidance on cybersecurity risk management.
AAMI Technical Information Report on post-market security risk management for medical device manufacturers, the operational companion to TIR57.
Unauthorized remote control of an implanted neurostimulator (e.g., DBS) to alter stimulation parameters and harm a patient.
Primary references
3 sources- 1
HHS Guidance: De-Identification of PHIVerifiedHHS OCRhhs.gov
- 2
NIST SP 800-188 De-Identifying Government DatasetsVerifiedNISTcsrc.nist.gov
- 3
HSCC - Health Sector Coordinating CouncilVerifiedHSCChealthsectorcouncil.org
Inline markers like [1] jump to the matching reference above.