Skip to main content
Category: De-identification and PHI Types

Limited Data Set

Also known as: LDS, Limited Dataset
Simply put

A limited data set is health information from which certain direct identifiers, such as names, addresses, and Social Security numbers, have been removed, but which may still contain some indirect information like dates or geographic details. Because it is not fully de-identified, it remains protected health information (PHI) under the HIPAA Privacy Rule. It is generally used for research, public health, or health care operations, and its use or disclosure typically requires a data use agreement.

Formal definition

Under the HIPAA Privacy Rule, a limited data set is protected health information that excludes specified direct identifiers of the individual and of relatives, employers, or household members (for example, names, postal address information other than town/city, state, and ZIP code, telephone and fax numbers, email addresses, Social Security numbers, and full-face photographs). Because a limited data set retains identifiers that fall short of the standard for de-identification, it continues to constitute PHI and remains subject to the Privacy Rule; it is therefore distinct from de-identified information, which is not PHI. A covered entity may use or disclose a limited data set only for the permitted purposes of research, public health, or health care operations and, in most cases, must enter into a data use agreement with the recipient establishing permitted uses and safeguards. Practitioners should verify the current list of excluded identifiers and applicable data use agreement requirements against the current regulatory text at 45 CFR Part 164, and note that state law or other frameworks may impose additional requirements.

Why it matters

The limited data set occupies an important middle ground in the HIPAA Privacy Rule. Fully de-identified information falls outside the Privacy Rule entirely because it is no longer PHI, while a limited data set retains certain indirect identifiers, such as dates and some geographic detail, that make it more useful for research, public health, and health care operations. Because those retained elements fall short of the de-identification standard, a limited data set remains PHI and stays subject to the Privacy Rule. Misunderstanding this distinction is a common compliance pitfall: treating a limited data set as though it were de-identified can lead to improper uses or disclosures.

The mechanism that makes limited data set disclosures permissible in most cases is the data use agreement. This agreement establishes the permitted uses and required safeguards for the recipient and is a central control that compliance and privacy officers should verify is in place before any disclosure. Without a proper data use agreement, a disclosure that might otherwise be permitted can become an impermissible disclosure of PHI.

Because the retained identifiers still carry re-identification risk, organizations should treat limited data sets with appropriate care rather than assuming the removal of direct identifiers eliminates their obligations. Practitioners should verify the current list of excluded identifiers and applicable data use agreement requirements against the current text at 45 CFR Part 164, and remain aware that state law or other frameworks may impose additional requirements beyond HIPAA.

Who it's relevant to

Privacy Officers
Privacy officers are responsible for ensuring that any limited data set is constructed by correctly removing the specified direct identifiers and that it is not mistaken for de-identified information. They should confirm that a data use agreement is in place before disclosure and that the permitted purpose is limited to research, public health, or health care operations. Because the list of excluded identifiers is defined by regulation, they should verify it against the current text at 45 CFR Part 164.
Research Administrators and IRB Staff
Research programs frequently rely on limited data sets because retained elements such as dates and geographic detail support analysis while still narrowing exposure of direct identifiers. Research administrators and institutional review board staff should ensure that data use agreements govern each disclosure and that investigators understand that a limited data set remains PHI subject to the Privacy Rule, not de-identified data outside its scope.
Compliance and Legal Teams
Compliance and legal professionals should review and maintain data use agreements, confirm that recipients agree to the permitted uses and required safeguards, and assess whether state law or other frameworks impose requirements beyond HIPAA. They should treat improper use of a limited data set, or disclosure without a valid data use agreement, as a potential impermissible disclosure of PHI.
Recipients of Limited Data Sets
Organizations and individuals receiving a limited data set should understand that they are typically bound by a data use agreement that restricts how the data may be used and requires specific safeguards. Because the data set still constitutes PHI, recipients should not attempt to re-identify individuals or use the data beyond the agreed permitted purposes.

Inside LDS

Definition
A limited data set is protected health information (PHI) from which specified direct identifiers of the individual and of relatives, employers, and household members have been removed, as defined under the HIPAA Privacy Rule. It remains PHI and is still subject to the Privacy Rule, unlike de-identified information.
Direct Identifiers Removed
Creating a limited data set generally requires removing direct identifiers such as names, street addresses (though certain geographic detail like town, city, state, and ZIP code may typically be retained), telephone and fax numbers, email addresses, Social Security numbers, medical record numbers, account numbers, and similar direct identifiers. Practitioners should verify the complete list of required removals against the current regulatory text.
Elements That May Be Retained
Unlike a fully de-identified data set, a limited data set may generally retain certain indirect information such as dates (admission, discharge, service, birth, death) and some geographic detail below the level of a full street address. This is a key distinction from de-identification under the Safe Harbor or Expert Determination methods.
Permitted Uses and Disclosures
A limited data set may generally be used or disclosed only for the purposes of research, public health, or health care operations, as specified under the Privacy Rule. It is not a general-purpose exemption for any use.
Data Use Agreement (DUA) Requirement
Before disclosing a limited data set, a covered entity is generally required to enter into a data use agreement with the recipient. The DUA typically establishes permitted uses, safeguards, and restrictions, including that the recipient will not attempt to re-identify the individuals or contact them.
Relationship to De-Identification
A limited data set is not de-identified information. Because it retains PHI, it remains within the scope of the HIPAA Privacy Rule, whereas properly de-identified data is generally no longer subject to the Privacy Rule.

Common questions

Answers to the questions practitioners most commonly ask about LDS.

Is a limited data set the same as de-identified data?
No. A limited data set is not de-identified data and remains protected health information (PHI) subject to the HIPAA Privacy Rule. While a limited data set has certain direct identifiers removed, it may still retain elements such as dates and some geographic information that are not permitted in de-identified data. Because it is still PHI, its use and disclosure remain regulated, whereas properly de-identified data generally falls outside the Privacy Rule's restrictions. Readers should confirm the specific identifier requirements against the current regulatory text.
Can I share a limited data set freely without any agreement in place?
No. Even though a limited data set has direct identifiers removed, it is still PHI, and disclosure generally requires a data use agreement between the covered entity (or business associate) and the recipient. The data use agreement establishes permitted uses and disclosures and the recipient's safeguarding obligations. Sharing a limited data set without this agreement in place is generally not permitted under the Privacy Rule.
For what purposes may a limited data set be used or disclosed?
Under the Privacy Rule, a limited data set may generally be used or disclosed only for the purposes of research, public health, or health care operations. Uses outside these specified purposes typically require another basis for disclosure, such as an authorization. Confirm the permitted purposes against the current regulatory text, and note that state law or other frameworks may impose additional conditions.
What elements should a data use agreement for a limited data set address?
A data use agreement generally establishes the permitted uses and disclosures of the limited data set, identifies who may use or receive the information, and requires the recipient to implement appropriate safeguards. It typically also obligates the recipient not to attempt to re-identify the individuals or contact them, and to ensure that any agents or subcontractors agree to the same restrictions. Organizations should confirm the required provisions against the current regulatory text.
Which identifiers must be removed to create a limited data set?
Creating a limited data set requires removing specified direct identifiers of the individual and of relatives, employers, and household members. Notably, a limited data set may retain certain elements, such as dates and some geographic detail, that are not allowed in de-identified data, which is one reason it remains PHI. Because the precise list of identifiers to remove is defined in the regulation, verify the current requirements against the applicable regulatory text before creating a limited data set.
Who is responsible if a recipient misuses a limited data set?
The data use agreement is the primary mechanism for assigning responsibility. If the disclosing party becomes aware of a pattern of activity or practice by the recipient that constitutes a material breach of the data use agreement, it generally must take reasonable steps to address the violation and, if unsuccessful, discontinue the disclosure and may need to report the matter. Specific obligations should be confirmed against the current regulatory text, and organizations should note that additional requirements may apply under the HITECH Act or state law.

Common misconceptions

A limited data set is the same as de-identified data and is therefore no longer regulated under HIPAA.
A limited data set remains PHI and is still subject to the HIPAA Privacy Rule. It is distinct from de-identified data, which is generally no longer PHI. The limited data set retains certain indirect identifiers (such as dates and some geographic detail) that would not remain in de-identified information.
A limited data set can be shared for any purpose once the direct identifiers are removed.
Use and disclosure of a limited data set is generally restricted to research, public health, and health care operations, and typically requires a data use agreement with the recipient. Removing direct identifiers does not create an unrestricted data set.
No agreement is needed to disclose a limited data set as long as identifiers are stripped.
A covered entity generally must obtain a data use agreement before disclosing a limited data set. The DUA typically specifies permitted uses, required safeguards, and a prohibition on re-identifying or contacting the individuals.

Best practices

Verify the complete list of direct identifiers that must be removed against the current HIPAA Privacy Rule text before creating a limited data set, rather than relying on memory or summaries.
Execute a data use agreement with the recipient before any disclosure, and ensure it addresses permitted uses, safeguards, and prohibitions on re-identification and contacting individuals.
Confirm that the intended use falls within the permitted categories (research, public health, or health care operations) before proceeding, since a limited data set is not authorized for general-purpose sharing.
Treat the limited data set as PHI throughout its lifecycle, applying appropriate Privacy Rule protections and, where ePHI is involved, applicable Security Rule safeguards.
Document the process used to remove direct identifiers and retain the executed data use agreement to support accountability and any subsequent review.
Check whether state law, the HITECH Act, or other frameworks impose additional requirements beyond HIPAA that may affect how the limited data set is created, shared, or protected.