Get Compliance Tools

HIPAA Safe Harbor Method: PHI De-Identification Guide

Last updated: March 2026 | Regulatory Deep Dive

Regulatory Background

De-identification is the process of removing or obscuring direct and indirect identifiers from health information so that the remaining information cannot reasonably identify an individual. Under HIPAA Privacy Rule § 164.502(d), de-identified information is no longer subject to HIPAA requirements and may be used and disclosed freely. The rule provides two methods for de-identifying health information: the Safe Harbor method (deterministic approach) and the Expert Determination method (statistical approach). The Safe Harbor method is the more straightforward and commonly used approach, providing organizations with clear, objective criteria for de-identification.

Purpose and Application

De-identification allows healthcare organizations to:

Key Context: De-identification is one of the few ways under HIPAA to use PHI without patient authorization or other HIPAA safeguards. However, the de-identification must be done correctly following HIPAA's specific requirements. Improper de-identification that leaves the information re-identifiable violates HIPAA.

HIPAA Safe Harbor De-Identification Method

Overview

The Safe Harbor method is a "whitelist" approach: organizations must remove or obscure 18 specific categories of identifiers. If all 18 categories are removed, the remaining information is presumed de-identified under HIPAA without further analysis. This is the most straightforward method and does not require statistical expertise or external review.

18 Identifiers That Must Be Removed or Obscured

1. Names

2. Geographic Information

3-4. Dates

5. Phone, Fax, Email

6. Social Security Numbers (SSN)

7. Medical Record Numbers (MRN)

8. Health Insurance Account Numbers

9. Account Numbers

10. Certificate/License Numbers

11. Vehicle Information

12. Device Serial Numbers

13. Web URLs

14. Internet Protocol (IP) Addresses

15. Biometric Data

16. Full-Face Photographs

17. Unique Identifying Numbers, Codes, Characteristics

18. Any Other Identifying Information

Important Note: Safe Harbor de-identification is an all-or-nothing approach: if even one identifier category remains that could reasonably identify the individual, the data is not properly de-identified. Organizations must systematically verify that all 18 categories have been removed.

Limited Data Sets and Data Use Agreements

Limited Data Set Option

As an alternative to full de-identification, HIPAA allows disclosure of a "limited data set" containing certain identifiers, provided a Data Use Agreement is signed by the recipient:

Permitted Identifiers in Limited Data Sets

All Other Identifiers Must Still Be Removed

Data Use Agreement Requirements

Before disclosing a limited data set, the organization must have a signed Data Use Agreement with the recipient that:

Implementation Guidance

De-Identification Process

  1. Identify Data Source: Identify all records or data elements that will be de-identified
  2. Document Mappings: Document which data element maps to which Safe Harbor category
  3. Remove Identifiers: Systematically remove or obscure each of the 18 categories
  4. Use Arbitrary Identifiers: If tracking is needed, use arbitrary identifiers (Patient 001) not traceable to original records
  5. Verify Completeness: Verify that all 18 categories have been addressed
  6. Document Process: Document the de-identification process and verification
  7. Quality Assurance: Have independent review to verify de-identification completeness

Automation and Tools

Special Considerations

Documentation Requirements

Maintain documentation of de-identification efforts:

Frequently Asked Questions

Can we retain the last 4 digits of MRN for tracking purposes?

No. The HIPAA Safe Harbor method requires complete removal of all Medical Record Numbers and account numbers. The intent is that the remaining de-identified data cannot be linked back to the individual's medical record. If you retain any portion of the MRN (last 4 digits, first 3 digits, etc.), it may be traceable back to the individual. Instead, use an arbitrary, randomly generated identifier (e.g., "Research_001", "Case_5729") that has no relationship to the individual or their medical record number. This arbitrary identifier can then be used to track records through your de-identification and analysis process without compromising de-identification.

What if a rare diagnosis or procedure could identify the patient?

This is addressed in Safe Harbor category 18 ("any other identifying information"). If a rare diagnosis, unusual procedure, or combination of clinical characteristics could reasonably identify the individual, that information must be removed or obscured. For example, if you have records of the only patient with a specific rare disease in a small geographic area, the combination of disease, location, and treatment could identify the patient. In such cases, you might: (1) Aggregate information with other similar cases, (2) Remove the specific diagnosis code and replace with a broader category, (3) Remove the location information, or (4) Omit the rare clinical element entirely if not essential to your research or use purpose.

Can we use zip code + 3 for geographic data?

Yes, but only with careful consideration. HIPAA allows retention of the first three digits of a zip code IF the area they define contains 20,000+ residents. You must verify that your specific zip code + 3 area meets this population threshold. For example, if your zip code + 3 is "03101" (Portsmouth, NH area), you must verify that the geographic area covered by that code has 20,000+ residents. If the area is smaller, you must aggregate to a higher geographic level (state-level or county-level) or remove geographic information entirely. Many urban areas support zip code + 3, but rural areas often do not. The burden is on the organization to verify population thresholds for each zip code + 3 used.

Is de-identified data still subject to HIPAA?

No. Once information is properly de-identified according to HIPAA's Safe Harbor method, it is no longer subject to HIPAA Privacy and Security Rules. De-identified information can be used and disclosed freely without patient authorization, Business Associate agreements, or other HIPAA safeguards. However, the burden is entirely on the organization to ensure the de-identification is done correctly. If the de-identification is incomplete or incorrect, and the information remains identifiable, the organization may be found in violation of HIPAA. Additionally, other laws may apply to even de-identified data (state privacy laws, IRB requirements for research, etc.), so organizations should verify that their intended use complies with all applicable laws beyond HIPAA.