Skip to main content
Category: De-identification and PHI Types

Expert Determination Method

Also known as: Expert Determination, Expert Determination de-identification
Simply put

The Expert Determination Method is one of two ways permitted under the HIPAA Privacy Rule to de-identify protected health information so that it is no longer considered PHI. Instead of removing a fixed list of identifiers, it relies on a qualified expert who uses statistical or scientific analysis to conclude that the risk of someone re-identifying the individuals is very small. This approach can allow organizations to keep more useful data than the alternative Safe Harbor method, but it depends on the expert's judgment and documentation.

Formal definition

The Expert Determination Method is one of two de-identification standards recognized under the HIPAA Privacy Rule (the other being the Safe Harbor method). Under this method, a person with appropriate knowledge of and experience with generally accepted statistical and scientific principles and methods for rendering information not individually identifiable applies such principles and methods to determine that the risk is very small that the information could be used, alone or in combination with other reasonably available information, to identify an individual who is a subject of the information; the expert must also document the methods and results of the analysis supporting that determination. This method is generally selected when Safe Harbor's removal of specified identifiers would strip too much data utility, as it permits retention of more granular data provided the residual re-identification risk is assessed as very small. Practitioners should note this is a Privacy Rule concept applicable to PHI in all forms and is distinct from the Security Rule's ePHI safeguards; the precise regulatory text, the definition of a qualifying expert, and specific standards should be verified against the current HIPAA Privacy Rule and current HHS OCR de-identification guidance, and state law may impose additional requirements.

Why it matters

For many healthcare organizations, the ability to use data for research, analytics, quality improvement, or secondary purposes hinges on whether that data can be properly de-identified. The Expert Determination Method matters because it offers a path to retain more granular, useful data than the Safe Harbor method's mechanical removal of a fixed set of identifiers. When stripping out those identifiers would render a dataset too limited for its intended purpose, Expert Determination can preserve analytic value while still supporting a conclusion that the information is no longer PHI under the HIPAA Privacy Rule.

The trade-off is that this method depends heavily on expert judgment and documentation rather than a checklist. Because the standard turns on an expert's conclusion that the re-identification risk is 'very small,' the defensibility of a de-identification determination rests on the qualifications of the expert, the soundness of the statistical or scientific methods applied, and the quality of the documentation supporting the analysis. Organizations that treat this as a one-time formality rather than a rigorous, documented assessment may find their determination difficult to defend if the underlying data environment or available external data changes.

It is also important to remember that a successful Expert Determination removes the information from the definition of PHI for HIPAA purposes, but does not necessarily satisfy other obligations. State law may impose additional requirements, and de-identification under the Privacy Rule is distinct from the Security Rule's safeguards for ePHI. Organizations should verify the precise regulatory standards and current HHS OCR de-identification guidance before relying on an Expert Determination.

Who it's relevant to

Privacy Officers and Compliance Teams
Privacy officers responsible for determining when data can be shared, used for secondary purposes, or released outside the organization need to understand both de-identification methods and when Expert Determination is the more appropriate choice. They should ensure that any determination is properly documented and that reliance on de-identified status is periodically revisited, since this is a Privacy Rule concept applicable to PHI in all forms.
Researchers and Data Analytics Teams
Teams that require granular data for research, analytics, or quality improvement often find Safe Harbor too restrictive because it removes too many identifiers. Expert Determination can allow retention of more data utility when simple identifier removal is insufficient, making it particularly relevant to those whose work depends on preserving analytic value in the data.
Statisticians and Qualified De-identification Experts
The method depends on a person with appropriate knowledge of and experience with generally accepted statistical and scientific principles for rendering information not individually identifiable. Such experts are responsible for applying sound methods, concluding whether the re-identification risk is very small, and documenting the methods and results supporting that conclusion.
Legal Counsel and Auditors
Legal and audit professionals evaluating the defensibility of an organization's data practices should scrutinize the expert's qualifications, the analysis performed, and the supporting documentation. They should also confirm the current regulatory standards and note that state law or other frameworks may impose additional requirements beyond the HIPAA Privacy Rule.

Inside Expert Determination Method

Statistical or Scientific Principles Basis
The Expert Determination Method relies on a qualified person applying generally accepted statistical and scientific principles and methods to render PHI not individually identifiable. It is one of the two de-identification pathways under the HIPAA Privacy Rule, the other being the Safe Harbor method.
Qualified Expert
A person with appropriate knowledge of and experience with generally accepted statistical and scientific principles and methods for rendering information not individually identifiable. The rule does not prescribe a specific degree or certification, so the expert's qualifications are typically established through education and experience.
Very Small Risk Standard
The expert must determine that the risk is very small that the information could be used, alone or in combination with other reasonably available information, to identify an individual who is a subject of the information.
Documentation of Methods and Results
The expert must document the methods and results of the analysis that justify the determination. This documentation supports the covered entity's or business associate's reliance on the de-identification and should be retained, though practitioners should verify current record-retention expectations against the applicable regulatory text.
Relationship to Covered Entities and Business Associates
The method is used by covered entities, and by business associates acting on their behalf under a business associate agreement, to determine that health information no longer meets the definition of PHI. Properly de-identified information is generally not subject to the Privacy Rule.
Scope Within HIPAA
This method is a Privacy Rule concept governing de-identification of PHI in all forms. It is distinct from Security Rule safeguards, which apply specifically to ePHI, and from the Breach Notification and Enforcement Rules.

Common questions

Answers to the questions practitioners most commonly ask about Expert Determination Method.

Does the Expert Determination Method mean the data is completely anonymous and can never be re-identified?
No. The Expert Determination Method does not guarantee absolute anonymity or eliminate all possibility of re-identification. The standard is that a qualified expert determines the risk of identifying an individual is very small, using generally accepted statistical and scientific principles and methods. It is a risk-based standard, not a zero-risk guarantee. Because re-identification techniques and available data sources evolve over time, a determination reflects the risk as assessed at a particular point under stated conditions, and readers should treat it as a risk minimization approach rather than a permanent state of anonymity.
Is Expert Determination the same thing as the Safe Harbor method, just done by a person instead of a checklist?
No. Both are recognized de-identification methods under the HIPAA Privacy Rule, but they are distinct approaches. Safe Harbor generally involves removing a specified list of identifiers and requires that the covered entity have no actual knowledge that the remaining information could identify an individual. Expert Determination instead relies on a person with appropriate knowledge and experience applying statistical and scientific methods to conclude that the re-identification risk is very small, and documenting the methods and results of that analysis. Expert Determination can allow retention of some data elements that Safe Harbor would require removing, provided the expert's analysis supports a very small risk. The two methods should not be conflated or combined without care, and the applicable requirements should be confirmed against the current regulatory text.
Who qualifies as an 'expert' for the purposes of an Expert Determination?
The HIPAA Privacy Rule generally describes the expert in terms of qualifications rather than a specific credential or certification. In most cases this means a person with appropriate knowledge of and experience with generally accepted statistical and scientific principles and methods for rendering information not individually identifiable. There is typically no single mandated license or title. Because the standard is about demonstrated expertise, organizations should document the basis for the expert's qualifications and confirm the applicable requirements against the current regulation.
What documentation should be retained after an Expert Determination is completed?
As a practical matter, organizations generally retain records that support and evidence the determination. This typically includes documentation of the methods and results of the analysis that justify the conclusion that the re-identification risk is very small, along with information about the expert's qualifications. Maintaining this documentation helps demonstrate the basis for the determination if questioned. You should verify current recordkeeping expectations and any applicable retention periods against the current regulatory text and your organization's own policies.
Does an Expert Determination expire or need to be revisited over time?
The regulation does not, in itself, establish a fixed expiration date, but a determination reflects the re-identification risk under the conditions and data landscape assessed at the time it was made. Because available external data sources and re-identification techniques change, many organizations choose to revisit determinations periodically or when relevant circumstances change, such as new data being added or a change in how the data will be shared. Any specific reassessment triggers or intervals should be defined by organizational policy and confirmed against current guidance rather than assumed.
Does using the Expert Determination Method by itself make an organization HIPAA compliant?
No. Expert Determination is one recognized method for de-identifying protected health information under the HIPAA Privacy Rule, and properly de-identified information is generally no longer subject to the Privacy Rule's restrictions. However, completing a determination does not by itself establish overall HIPAA compliance, which involves broader Privacy Rule, Security Rule, Breach Notification Rule, and Enforcement Rule obligations depending on the organization's role. Additionally, state law or other frameworks may impose requirements beyond HIPAA. Organizations should treat Expert Determination as addressing a specific de-identification objective, not as a substitute for a complete compliance program.

Common misconceptions

The Expert Determination Method requires the expert to guarantee that data can never be re-identified.
The standard is that the risk of identification is very small, not zero. HIPAA does not require an absolute guarantee against re-identification, and no de-identification method can be said to eliminate all risk.
Any qualified data scientist or statistician automatically satisfies the expert requirement, or a specific credential is mandated.
The Privacy Rule does not mandate a particular degree or certification; it requires a person with appropriate knowledge of and experience with generally accepted statistical and scientific principles and methods. Qualifications are established through demonstrated education and experience, and the determination and its documentation are what matter.
Expert Determination and Safe Harbor are interchangeable and produce identical results.
They are two separate pathways. Safe Harbor requires removal of a specified list of identifiers and absence of actual knowledge of residual identifiability, while Expert Determination relies on statistical or scientific analysis of re-identification risk. A dataset that fails one approach may still qualify under the other.

Best practices

Engage an expert whose knowledge of and experience with generally accepted statistical and scientific principles can be clearly demonstrated and documented, since the rule ties qualification to education and experience rather than a fixed credential.
Require the expert to document the methods and results of the analysis supporting the very small risk determination, and retain that documentation to support reliance on the de-identification.
Have the expert assess re-identification risk in light of other reasonably available information that could be combined with the dataset, rather than evaluating the dataset in isolation.
Treat the determination as time- and context-sensitive; re-evaluate when data uses, recipients, or the availability of external information change, since a prior very small risk finding may not remain valid.
Where a business associate performs or relies on the determination, confirm that the relationship and responsibilities are addressed in the business associate agreement.
Confirm current regulatory expectations for documentation, retention, and the de-identification standard against the applicable Privacy Rule text, and check whether state law or other frameworks impose additional requirements beyond HIPAA.