De-identification (HIPAA)
De-identification is the process defined in the US HIPAA Privacy Rule (45 CFR 164.514(a) to (c)) by which protected health information is rendered not individually identifiable, so that it ceases to be PHI and may be used and disclosed without the Privacy Rule's restrictions. Two methods are recognised. Under the Safe Harbor method, all 18 listed identifiers of the individual and of relatives, employers and household members are removed, and the covered entity has no actual knowledge that the remaining information could identify the individual. Under the Expert Determination method, a qualified statistician or scientist applies generally accepted principles and determines, and documents, that the risk of re-identification by an anticipated recipient is very small.
The Privacy Rule also permits the covered entity to assign a re-identification code to de-identified data, provided the code is not derived from information about the individual and the mechanism for re-identification is not disclosed (45 CFR 164.514(c)); this is why key-coded clinical trial data can be treated as de-identified in the US when the recipient has no access to the key. A related but distinct concept is the limited data set (45 CFR 164.514(e)), which retains dates and some geographic data and may be shared for research, public health and healthcare operations under a data use agreement. HHS guidance of 2012 explains both methods in detail.
De-identification must not be equated with anonymisation under the GDPR. The GDPR test is contextual and considers all means reasonably likely to be used by anyone, not only the anticipated recipient, so a Safe Harbor dataset that retains year of birth, three-digit ZIP codes and rich clinical detail will often remain personal data in the EU, particularly for rare diseases; and key-coded data that HIPAA deems de-identified is pseudonymised personal data under the GDPR because the key exists. Expert Determination is methodologically closer to the EDPB approach, and its documented risk analysis can support a GDPR anonymisation assessment, but the conclusion must be re-evaluated under EU criteria. In transatlantic data-sharing agreements, iliomad recommends stating both the HIPAA status and the GDPR status of each dataset explicitly rather than using "de-identified" as a shorthand for "not regulated".
