
Short answer: HIPAA de-identification is the process in 45 CFR 164.514(a)-(b) that turns PHI into data the Privacy Rule no longer covers. You either remove 18 categories of identifiers and have no actual knowledge that the rest could identify someone (Safe Harbor), or a qualified expert documents that re-identification risk is very small (Expert Determination).
Related guides:
- What is considered PHI under HIPAA?
- AI HIPAA compliance
- HIPAA compliant database: requirements and configuration checklist
Key takeaways
- De-identified PHI is no longer PHI. It falls outside the Privacy Rule, which makes it usable for analytics and AI model training.
- There are only two methods. Safe Harbor is a checklist of 18 identifier categories plus "no actual knowledge." Expert Determination is a documented judgement that risk is very small.
- Neither means zero risk. HHS says de-identified data still carries some risk, so recipients, linkage and small cells matter.
- A limited data set is not de-identified. It is still PHI, allowed only for research, public health or health care operations, and only under a data use agreement.
- Business associates need contract cover. A SaaS vendor can de-identify a customer's PHI only to the extent its business associate agreement allows it.
What does HIPAA de-identification actually mean?
It means health information that does not identify an individual and gives no reasonable basis to believe it could be used to identify one. That is the standard in 45 CFR 164.514(a), and paragraph (b) gives the only two ways to meet it.
Under 45 CFR 164.502(d), data that meets the standard is treated as not individually identifiable. HHS's de-identification guidance puts it directly: de-identified data is no longer protected by the Privacy Rule because it does not fall within the definition of PHI.
Three conditions keep that freedom honest:
- Creating it is a use of PHI. A covered entity may de-identify PHI itself or through a business associate, and HHS says a business associate may do so only to the extent its business associate agreement authorizes.
- Re-identified data is PHI again, and disclosing a re-identification code counts as disclosing PHI (164.502(d)(2)).
- Risk is very small, not zero. HHS notes both methods leave some risk of identification.
How does the Safe Harbor method work?
You remove 18 categories of identifiers, for the patient and for their relatives, employers and household members, and you must have no actual knowledge that what remains could identify them.

The categories in 164.514(b)(2)(i) group naturally like this:
| Group | Identifiers to remove |
|---|---|
| Names and contact | Names; telephone numbers; fax numbers; email addresses |
| Geography | All subdivisions smaller than a state, such as street address, city, county, precinct and ZIP code |
| Dates | All date elements except year for dates directly related to the individual, such as birth, admission, discharge and death |
| Government and health numbers | Social Security numbers; medical record numbers; health plan beneficiary numbers; account numbers; certificate or license numbers |
| Devices and online | Vehicle identifiers and serial numbers; device identifiers and serial numbers; URLs; IP addresses |
| Biometrics and images | Biometric identifiers such as finger and voice prints; full face photos and comparable images |
| Catch-all | Any other unique identifying number, characteristic or code, except a permitted re-identification code |
Two rules inside that list trip up most engineering teams:
- ZIP codes. You may keep the first three digits only if the area formed by all ZIP codes sharing them contains more than 20,000 people, based on current Census data. Otherwise the three digits become 000. HHS's guidance lists restricted prefixes from 2000 Census data but says not to rely on that list where newer data exists.
- Dates and ages. Only the year survives, so an admission date can appear as "2009." All ages over 89, and any date element (including year) revealing such an age, must be removed or grouped into a single category of 90 or older.
The second condition is easy to forget. Under 164.514(b)(2)(ii) you must not have actual knowledge that the remaining data could identify someone. HHS describes this as clear and direct knowledge, such as being told outright that a recipient can identify a patient.
How does Expert Determination work?
A person with appropriate knowledge of and experience with generally accepted statistical and scientific methods determines that the risk is very small that an anticipated recipient could identify an individual, alone or combined with other reasonably available information, and documents the methods and results (164.514(b)(1)).
What HHS's guidance clarifies about the method:
- No credential is required. No specific degree or certification program designates an expert, so choose someone whose experience you can defend.
- No fixed number defines "very small." OCR sets no universal numerical threshold or universal value for k. The expert sets a level appropriate to the anticipated recipient.
- Context drives risk. HHS describes replicability, data source availability and distinguishability as risk factors, and suppression, generalization and perturbation as ways to reduce it.
- Controls on the recipient can help. The expert may consider limiting distribution through a data use agreement, but that agreement does not replace the analysis.
- Expiry is optional. The rule requires no expiration date, though HHS notes some experts issue time-limited determinations.
In our experience, this method suits teams that need dates, finer geography or rich clinical detail for model training, because an expert can keep fields Safe Harbor would strip.
Can you keep a link back to the patient?
Yes, through a re-identification code that meets 164.514(c). The code must not be derived from or related to information about the individual, must not be translatable into an identity, must not be used or disclosed for any other purpose, and the re-identification mechanism must not be disclosed.
That rules out a common shortcut. HHS's guidance says a code derived from a secure hash function without a secret key is an identifying element, so an unkeyed hash of a medical record number is not a safe pseudonym. A random token, with the lookup table held only by the covered entity or its business associate, is the usual pattern.
When is a limited data set the better option?
When you need dates, town or city, state or ZIP code for research, public health or health care operations, and you can sign a data use agreement. A limited data set under 164.514(e) is still PHI.

| Safe Harbor | Expert Determination | Limited data set | |
|---|---|---|---|
| Still PHI? | No | No | Yes |
| Dates | Year only | Expert decides | Allowed |
| Geography | State, plus 3-digit ZIP where permitted | Expert decides | Town or city, state, ZIP code |
| Allowed purposes | Not restricted by the Privacy Rule | Not restricted by the Privacy Rule | Research, public health, health care operations only |
| Data use agreement | Optional | Optional, and may support the expert's analysis | Required |
A limited data set must still exclude 16 direct identifiers, such as names, street address, contact details, record and account numbers, device identifiers, URLs, IP addresses, biometrics and full face images. The data use agreement must set the permitted uses and recipients, and require the recipient to use appropriate safeguards, report disallowed uses, bind its agents to the same terms, and not identify the information or contact the individuals.
The catch for product teams: training your own commercial AI model is not automatically research, public health or health care operations, so check the purpose first.
How do you choose the right method?
Start from the purpose and the fields the purpose genuinely needs, then pick the lightest method that keeps those fields.

- Can the work run on year-level dates and coarse geography? Safe Harbor is the simplest, most predictable method.
- Need finer dates, locations or rare clinical detail outside the Privacy Rule? Commission an Expert Determination scoped to the dataset and recipient.
- Research, public health or health care operations, with a data use agreement? A limited data set may fit, but the data stays PHI.
- None of the above? You likely need authorization or another permission; see HIPAA permitted uses and disclosures.
For a SaaS business associate, step zero is confirming each customer's business associate agreement permits de-identification and your planned use.
What does a defensible de-identification workflow look like?
A repeatable pipeline with named owners, versioned rules and retained evidence, so you can show how every dataset left the PHI boundary. A workable sequence:
- Inventory the source. Map tables, free-text fields, images and attachments to the 18 categories.
- Confirm authority. Record the basis, such as the business associate agreement clause permitting de-identification.
- Document the method. Safe Harbor rules, or the expert's report with methods, results and recipient assumptions.
- Transform inside the PHI boundary. Our HIPAA compliant database checklist covers that environment.
- Validate the output. Test for residual identifiers, out-of-policy dates and ZIP codes, and ages over 89.
- Separate the key. Store any re-identification table apart from the dataset, with its own access controls.
- Release under terms. HHS notes nothing stops you from asking recipients of de-identified data to sign a data use agreement.
- Retain the evidence. Keep the method record, validation results, approvals and release log.
Which pitfalls quietly re-identify data?
Most failures come from data that looks harmless in isolation. Watch for these:
- Free text. HHS says a Safe Harbor identifier must be removed wherever it appears in a record if it is recognizable as one. Clinical notes and support tickets routinely contain names and dates.
- Dates hidden elsewhere. File names, timestamps and event logs can leak date elements.
- ZIP codes. A full ZIP code, or a three-digit prefix covering 20,000 or fewer people, fails Safe Harbor.
- Small cells. HHS notes agencies set their own small cell policies, and OCR sets no universal threshold. A handful of patients with a rare condition in one region can point to individuals.
- Linkage. Combining your dataset with public records, another release or a recipient's own data can identify people.
- Recipient behaviour. A recipient that says it can identify patients gives you actual knowledge. Contract against re-identification and onward sharing.
- Unkeyed hashes. A hash without a secret key is treated as an identifier.
How SecureSlate helps
SecureSlate helps HealthTech and SaaS teams run de-identification as a governed process rather than a one-off script. Built-in HIPAA support, with multi-framework control mapping to SOC 2, ISO 27001, HITRUST and GDPR, covers the controls around your PHI environment. Custom controls let you add steps such as method approval, output validation and key separation, and audit management keeps the evidence for each release together. Vendor risk management tracks the analytics and AI vendors that receive data, risk management records re-identification risk decisions, and secrets detection helps keep PHI store credentials out of your code. The trust center and security questionnaire automation help you explain your approach to buyers.
Start your free SecureSlate trial
FAQ
Is de-identified data still PHI under HIPAA?
No. Data that meets the Safe Harbor or Expert Determination standard in 164.514(b) is not individually identifiable, so the Privacy Rule no longer applies to it. It becomes PHI again if it is re-identified.
Can we use de-identified PHI to train an AI model?
The Privacy Rule does not restrict uses of properly de-identified data. As a business associate, your agreement must also permit the de-identification, and linkage risk still needs managing.
Does Safe Harbor allow three-digit ZIP codes?
Yes, only where all ZIP codes sharing those three digits together cover more than 20,000 people under current Census data. Otherwise the prefix must be replaced with 000.
Is a limited data set the same as de-identified data?
No. A limited data set keeps elements such as dates and ZIP codes, remains PHI, is limited to research, public health or health care operations, and requires a data use agreement.
How long is an Expert Determination valid?
The rule sets no expiration date, though HHS notes some experts issue time-limited determinations. A new dataset or recipient generally calls for a fresh review.
Disclaimer (legal note)
This article is for general information only and is not legal, regulatory or professional advice. Requirements vary by framework, industry and jurisdiction. Consult qualified advisors for your specific obligations.
Need compliance without the complexity?
SecureSlate automates ISO 27001, SOC 2, GDPR, HIPAA, and more. Built for growing teams. See it in action.
Find compliance gaps in 30 seconds