De-identified Information
De-identified information is health information that has had identifiers removed or altered so it can no longer reasonably be linked back to a specific individual. Because it can no longer identify a person, it is generally treated differently under HIPAA than protected health information. However, in some cases de-identified information can be re-identified if a code, algorithm, or pseudonym is used to link it back to the original records.
Under the HIPAA Privacy Rule, de-identified information is health information from which identifiers have been removed or manipulated such that there is no reasonable basis to believe it can be used to identify an individual. HHS guidance generally describes two recognized approaches to de-identification: an Expert Determination method and a Safe Harbor method involving removal of specified identifiers (readers should verify the specific identifiers and requirements against the current HHS de-identification guidance and the applicable CFR text). Information that meets the Privacy Rule's de-identification standard is generally not treated as PHI and therefore falls outside many Privacy Rule use and disclosure restrictions, though this is a specific regulatory standard that differs from general or colloquial uses of the term 'de-identification.' Note that HHS acknowledges de-identified information may be re-identified through a code, algorithm, or pseudonym; the conditions under which a re-identification code may be assigned and retained are governed by the Privacy Rule and should be confirmed against current guidance. This scope is limited to HIPAA; state law, the HITECH Act, or other frameworks may impose additional or differing requirements. Related but distinct concepts, such as a 'limited data set,' are not synonymous with de-identified information.
Why it matters
De-identification is one of the primary mechanisms that allows health information to be used and shared for purposes such as research, analytics, and product development without triggering the full set of use and disclosure restrictions the HIPAA Privacy Rule imposes on protected health information (PHI). Once information meets the Privacy Rule's de-identification standard, it is generally no longer treated as PHI, which meaningfully expands what covered entities and business associates can do with it. This makes correct de-identification a high-stakes compliance decision: information that is believed to be de-identified but does not actually meet the standard remains PHI and continues to carry the Privacy Rule's obligations.
The stakes are heightened by the fact that de-identification is a specific regulatory standard, not a colloquial one. Simply stripping obvious identifiers such as names or addresses does not necessarily satisfy the HIPAA de-identification standard, and organizations that treat any partially masked dataset as 'de-identified' may be misclassifying PHI. HHS recognizes only defined approaches to de-identification, and readers should confirm the specific methods and identifier lists against current HHS de-identification guidance and the applicable CFR text.
Re-identification risk further complicates the picture. HHS acknowledges that de-identified information can be re-identified using a code, algorithm, or pseudonym assigned to link data back to the original records. The conditions under which such a re-identification code may be assigned and retained are governed by the Privacy Rule, and mishandling those codes can undermine the de-identified status of the data. Because state law, the HITECH Act, or other frameworks may impose additional or differing requirements, organizations should not assume that meeting the HIPAA standard resolves all obligations.
Who it's relevant to
Inside De-identified Information
Common questions
Answers to the questions practitioners most commonly ask about De-identified Information.