HIPAA Safe Harbor Method: PHI De-Identification Guide
Regulatory Background
De-identification is the process of removing or obscuring direct and indirect identifiers from health information so that the remaining information cannot reasonably identify an individual. Under HIPAA Privacy Rule § 164.502(d), de-identified information is no longer subject to HIPAA requirements and may be used and disclosed freely. The rule provides two methods for de-identifying health information: the Safe Harbor method (deterministic approach) and the Expert Determination method (statistical approach). The Safe Harbor method is the more straightforward and commonly used approach, providing organizations with clear, objective criteria for de-identification.
Purpose and Application
De-identification allows healthcare organizations to:
- Use health information for research without obtaining patient authorization
- Share health information with vendors and other parties without HIPAA restrictions
- Publicly publish health information for teaching, marketing, or analysis
- Conduct epidemiological and public health research
- Develop and test analytics and AI models
HIPAA Safe Harbor De-Identification Method
Overview
The Safe Harbor method is a "whitelist" approach: organizations must remove or obscure 18 specific categories of identifiers. If all 18 categories are removed, the remaining information is presumed de-identified under HIPAA without further analysis. This is the most straightforward method and does not require statistical expertise or external review.
18 Identifiers That Must Be Removed or Obscured
1. Names
- Patient name and all direct references to patient identity
- Provider name and all references to treating providers
- Family member names who appear in the record
- All names in free-text clinical notes must be removed or replaced with generic identifiers
2. Geographic Information
- All geographic subdivisions smaller than a state (cities, counties, zip codes)
- Exception: First three digits of zip code may be retained IF the area has 20,000+ residents
- Addresses must be removed entirely unless aggregating to state level
- Geographic location of patient's home, workplace, school, etc. must be removed
3-4. Dates
- Birth Date: Entire birth date must be removed or obscured (month/day/year)
- Service Dates: Specific dates of service must be removed except for year
- Exception: Age may be retained; patients age 90+ must be reported as "90 years old"
- Other Dates: All other dates except year must be removed (discharge date, test dates, etc.)
5. Phone, Fax, Email
- Patient phone numbers must be removed
- Patient fax numbers must be removed
- Patient email addresses must be removed
- All electronic contact information must be removed or replaced
6. Social Security Numbers (SSN)
- All SSNs must be removed
- Partial SSNs (last 4 digits, first 5 digits) must be removed
- Cannot be replaced with identifier that could lead to SSN
7. Medical Record Numbers (MRN)
- All MRN identifiers must be removed
- Cannot be replaced with another number traceable to individual
- May use arbitrary identifiers (e.g., "Patient 001") if not traceable to original record
8. Health Insurance Account Numbers
- All insurance ID numbers, policy numbers, and claim account numbers must be removed
- Includes Medicare, Medicaid, private insurance, and other plan identifiers
9. Account Numbers
- All financial account numbers (bank accounts, credit cards) must be removed
- Billing account numbers associated with the individual must be removed
10. Certificate/License Numbers
- Driver's license numbers must be removed
- Professional license numbers must be removed
- Other state or federal certificate numbers must be removed
11. Vehicle Information
- Vehicle identification numbers (VIN) must be removed
- License plate numbers must be removed
- Any vehicle identifiers must be removed
12. Device Serial Numbers
- Medical device serial numbers unique to individual must be removed
- Implantable device serial numbers must be removed
13. Web URLs
- Any uniform resource locator (web address) that contains identifying information must be removed
14. Internet Protocol (IP) Addresses
- All IP addresses must be removed
- Cannot replace with identifier traceable to individual
15. Biometric Data
- Fingerprints must be removed
- Facial recognition data must be removed
- Retinal scans and other biometric identifiers must be removed
- Voice recordings that could identify individual must be removed
16. Full-Face Photographs
- Full-face photographs of individual must be removed or obscured
- Partial photographs not showing sufficient facial features may be retained with caution
17. Unique Identifying Numbers, Codes, Characteristics
- Medical Record Number: Covered under category 7
- Accession Numbers: Lab or imaging accession numbers must be removed
- Unique Identifiers: Any other unique numbers, codes, or characteristics that could identify the individual
- Re-identification Risk: Remove any data element that, in combination with other data, could reasonably identify the individual
18. Any Other Identifying Information
- This catch-all category requires removal of any other elements that could reasonably identify the individual
- Examples: unusual diagnoses, rare procedures, celebrity status, local notoriety
- Clinical context in conjunction with identifiers may make data re-identifiable
Limited Data Sets and Data Use Agreements
Limited Data Set Option
As an alternative to full de-identification, HIPAA allows disclosure of a "limited data set" containing certain identifiers, provided a Data Use Agreement is signed by the recipient:
Permitted Identifiers in Limited Data Sets
- Date of Birth: Month and year (day may be included)
- City and State: Geographic information at county level or higher
- Street Address: May be included if necessary for research
- Dates: All dates related to the individual except date of birth
- Telephone Number: May be included if necessary for contacting individual
- Email Address: May be included if necessary for contacting individual
All Other Identifiers Must Still Be Removed
- Names, initials, MRN, SSN, insurance numbers, account numbers, and other identifiers must be removed
- No substitution of limited data set identifiers with traceable identifiers
Data Use Agreement Requirements
Before disclosing a limited data set, the organization must have a signed Data Use Agreement with the recipient that:
- Permits use only for specified research, public health, or healthcare operations purposes
- Restricts re-disclosure without written authorization
- Restricts use for commercial purposes or to identify individuals
- Requires safeguards protecting the limited data set at least as strict as HIPAA
- Requires notice if re-identification is discovered
- Specifies term of agreement and return/destruction of data upon termination
Implementation Guidance
De-Identification Process
- Identify Data Source: Identify all records or data elements that will be de-identified
- Document Mappings: Document which data element maps to which Safe Harbor category
- Remove Identifiers: Systematically remove or obscure each of the 18 categories
- Use Arbitrary Identifiers: If tracking is needed, use arbitrary identifiers (Patient 001) not traceable to original records
- Verify Completeness: Verify that all 18 categories have been addressed
- Document Process: Document the de-identification process and verification
- Quality Assurance: Have independent review to verify de-identification completeness
Automation and Tools
- Use de-identification software that systematically removes identifiers
- Implement automated tools for common scenarios (removing names, dates, phone numbers)
- For complex documents, manual review may be necessary after automated de-identification
- Test de-identification tools on sample records before full implementation
- Maintain audit trail of all de-identification processing
Special Considerations
- Narrative Text: Clinical notes and narratives require careful review to remove all identifiers including references to specific people, locations, and events
- Images and Scans: Photos, X-rays, and images must be reviewed to remove patient identifiers (name labels, dates, accession numbers, etc.)
- Genetic Information: Genetic data may be highly identifiable; additional caution required
- Re-identification Risk: Even de-identified data might be re-identifiable in combination with other public data; assess context
Documentation Requirements
Maintain documentation of de-identification efforts:
- List of data elements removed and mapping to Safe Harbor categories
- Description of de-identification process and tools used
- Verification checklist confirming all 18 categories addressed
- Quality assurance procedures and results
- Approval by authorized personnel confirming de-identification completeness
Frequently Asked Questions
Can we retain the last 4 digits of MRN for tracking purposes?
No. The HIPAA Safe Harbor method requires complete removal of all Medical Record Numbers and account numbers. The intent is that the remaining de-identified data cannot be linked back to the individual's medical record. If you retain any portion of the MRN (last 4 digits, first 3 digits, etc.), it may be traceable back to the individual. Instead, use an arbitrary, randomly generated identifier (e.g., "Research_001", "Case_5729") that has no relationship to the individual or their medical record number. This arbitrary identifier can then be used to track records through your de-identification and analysis process without compromising de-identification.
What if a rare diagnosis or procedure could identify the patient?
This is addressed in Safe Harbor category 18 ("any other identifying information"). If a rare diagnosis, unusual procedure, or combination of clinical characteristics could reasonably identify the individual, that information must be removed or obscured. For example, if you have records of the only patient with a specific rare disease in a small geographic area, the combination of disease, location, and treatment could identify the patient. In such cases, you might: (1) Aggregate information with other similar cases, (2) Remove the specific diagnosis code and replace with a broader category, (3) Remove the location information, or (4) Omit the rare clinical element entirely if not essential to your research or use purpose.
Can we use zip code + 3 for geographic data?
Yes, but only with careful consideration. HIPAA allows retention of the first three digits of a zip code IF the area they define contains 20,000+ residents. You must verify that your specific zip code + 3 area meets this population threshold. For example, if your zip code + 3 is "03101" (Portsmouth, NH area), you must verify that the geographic area covered by that code has 20,000+ residents. If the area is smaller, you must aggregate to a higher geographic level (state-level or county-level) or remove geographic information entirely. Many urban areas support zip code + 3, but rural areas often do not. The burden is on the organization to verify population thresholds for each zip code + 3 used.
Is de-identified data still subject to HIPAA?
No. Once information is properly de-identified according to HIPAA's Safe Harbor method, it is no longer subject to HIPAA Privacy and Security Rules. De-identified information can be used and disclosed freely without patient authorization, Business Associate agreements, or other HIPAA safeguards. However, the burden is entirely on the organization to ensure the de-identification is done correctly. If the de-identification is incomplete or incorrect, and the information remains identifiable, the organization may be found in violation of HIPAA. Additionally, other laws may apply to even de-identified data (state privacy laws, IRB requirements for research, etc.), so organizations should verify that their intended use complies with all applicable laws beyond HIPAA.