Limited Data Set
A limited data set is health information from which certain direct identifiers, such as names, addresses, and Social Security numbers, have been removed, but which may still contain some indirect information like dates or geographic details. Because it is not fully de-identified, it remains protected health information (PHI) under the HIPAA Privacy Rule. It is generally used for research, public health, or health care operations, and its use or disclosure typically requires a data use agreement.
Under the HIPAA Privacy Rule, a limited data set is protected health information that excludes specified direct identifiers of the individual and of relatives, employers, or household members (for example, names, postal address information other than town/city, state, and ZIP code, telephone and fax numbers, email addresses, Social Security numbers, and full-face photographs). Because a limited data set retains identifiers that fall short of the standard for de-identification, it continues to constitute PHI and remains subject to the Privacy Rule; it is therefore distinct from de-identified information, which is not PHI. A covered entity may use or disclose a limited data set only for the permitted purposes of research, public health, or health care operations and, in most cases, must enter into a data use agreement with the recipient establishing permitted uses and safeguards. Practitioners should verify the current list of excluded identifiers and applicable data use agreement requirements against the current regulatory text at 45 CFR Part 164, and note that state law or other frameworks may impose additional requirements.
Why it matters
The limited data set occupies an important middle ground in the HIPAA Privacy Rule. Fully de-identified information falls outside the Privacy Rule entirely because it is no longer PHI, while a limited data set retains certain indirect identifiers, such as dates and some geographic detail, that make it more useful for research, public health, and health care operations. Because those retained elements fall short of the de-identification standard, a limited data set remains PHI and stays subject to the Privacy Rule. Misunderstanding this distinction is a common compliance pitfall: treating a limited data set as though it were de-identified can lead to improper uses or disclosures.
The mechanism that makes limited data set disclosures permissible in most cases is the data use agreement. This agreement establishes the permitted uses and required safeguards for the recipient and is a central control that compliance and privacy officers should verify is in place before any disclosure. Without a proper data use agreement, a disclosure that might otherwise be permitted can become an impermissible disclosure of PHI.
Because the retained identifiers still carry re-identification risk, organizations should treat limited data sets with appropriate care rather than assuming the removal of direct identifiers eliminates their obligations. Practitioners should verify the current list of excluded identifiers and applicable data use agreement requirements against the current text at 45 CFR Part 164, and remain aware that state law or other frameworks may impose additional requirements beyond HIPAA.
Who it's relevant to
Inside LDS
Common questions
Answers to the questions practitioners most commonly ask about LDS.