HIPAA De-Identification, Explained: Safe Harbor vs. Expert Determination

A first-principles guide to HIPAA de-identification: PHI, the 18 Safe Harbor identifiers, Expert Determination under 164.514, BAAs, and why de-identified data unlocks broader use.

Prometheus BioJune 23, 20267 min read

If you work with clinical data, the single biggest gate between "locked down" and "usable at scale" is de-identification. Get it right and the same records that were tightly restricted can flow into model training, real-world evidence studies, and analytics with far fewer constraints. Get it wrong and you carry regulatory and reputational risk you can't see. This guide explains the mechanics from first principles: what counts as protected health information, the two legal paths to de-identification, and why the distinction matters for anyone licensing or consuming health data.

This article is educational and not legal advice. De-identification decisions carry regulatory consequences; consult qualified counsel and privacy experts for your specific use case.

What Counts as Protected Health Information (PHI)

The HIPAA Privacy Rule governs protected health information — individually identifiable health information held or transmitted by a covered entity (like a provider, health plan, or clearinghouse) or its business associates. PHI is broad on purpose. It includes the obvious things — diagnoses, lab values, prescriptions, claims — but it also includes any data that ties that health information to a specific person.

The key insight is that PHI is relational, not just a list of fields. A blood pressure reading by itself isn't PHI. A blood pressure reading attached to a name, a date of service, and a ZIP code is. Identifiability is what triggers the rule.

That framing matters because de-identification is, at its core, the act of severing the link between health information and the individual. Once that link is broken to the standard HIPAA defines, the data is no longer PHI — and the Privacy Rule's restrictions on use and disclosure no longer apply to it.

The Two Legal Paths: §164.514

HIPAA defines exactly two ways to de-identify PHI, both under 45 CFR §164.514(b). Health information is considered de-identified only if it meets one of these standards:

  1. Safe Harbor — §164.514(b)(2): a prescriptive checklist. Remove a defined set of identifiers and confirm no actual knowledge of residual re-identification risk.
  2. Expert Determination — §164.514(b)(1): a risk-based standard. A qualified expert determines that the risk of re-identifying an individual is very small, documents the methods, and retains that justification.

There is no third path. "We removed names and called it a day" is not a recognized method. Understanding the trade-offs between these two is the practical heart of any data strategy.

Safe Harbor: The 18 Identifiers

Safe Harbor is the more mechanical route. It requires removing all 18 categories of identifiers for the individual and for their relatives, employers, and household members. The 18, per §164.514(b)(2), are:

  1. Names
  2. Geographic subdivisions smaller than a state
  3. All elements of dates (except year) tied to an individual
  4. Telephone, cell phone, and fax numbers
  5. Email addresses
  6. Social Security numbers
  7. Medical record numbers
  8. Health plan beneficiary numbers
  9. Account numbers
  10. Certificate and license numbers
  11. Vehicle identifiers and serial numbers, including license plates
  12. Device identifiers and serial numbers
  13. Web URLs
  14. IP addresses
  15. Biometric identifiers (e.g., fingerprints, voiceprints)
  16. Full-face photographs and comparable images
  17. Any other unique identifying number, characteristic, or code
  18. (Combined with the above) any other unique identifying detail

Two specifics trip people up most often:

  • Geography. You may keep the first three digits of a ZIP code only if the area those digits cover contains more than 20,000 people. If it doesn't, those digits must be changed to `000`.
  • Age and dates. All ages over 89 must be aggregated into a single "90 or older" category, because extreme ages are rare enough to be identifying. Likewise, only the year of a date may generally be retained.

After removing all 18, the entity must also have no actual knowledge that the remaining information could re-identify someone. Safe Harbor is predictable and easy to audit, but it's blunt: stripping precise dates and geography can strip out exactly the signal that makes longitudinal or regional research valuable.

Expert Determination: A Risk-Based Standard

Expert Determination, under §164.514(b)(1), trades the checklist for statistical rigor. A person "with appropriate knowledge of and experience with generally accepted statistical and scientific principles and methods" applies those methods to conclude that the risk of re-identification is very small — both on its own and in combination with other data reasonably available to a recipient.

Crucially, the expert must document the methods and the justification and retain that documentation. The standard is about defensible analysis, not a fixed field list.

The practical advantage is utility preservation. Instead of mechanically deleting precise dates or three-digit ZIPs, an expert can model the actual re-identification risk and retain more analytic value — exact intervals between events, finer geography, rare clinical detail — as long as the residual risk stays very small. This is why data intended for serious longitudinal analysis, real-world evidence, or model training is frequently de-identified via Expert Determination rather than Safe Harbor.

The trade-off: it requires real expertise, is dataset- and context-specific, and must be revisited as data or release conditions change.

What a Business Associate Agreement (BAA) Does — and Doesn't

A Business Associate Agreement (BAA) is the contract a covered entity signs with a vendor or partner that handles PHI on its behalf. The BAA binds that business associate to HIPAA's safeguards and limits how PHI can be used and disclosed. If you process identifiable PHI for a covered entity, you almost certainly need one.

Here's the clarifying point: properly de-identified data is no longer PHI, so the Privacy Rule's use-and-disclosure restrictions — and the BAA machinery built around them — no longer attach to it. De-identification and BAAs solve different problems. A BAA governs how identifiable data moves between accountable parties; de-identification changes the data's legal status so it can be used more broadly in the first place.

In a mature pipeline, both matter: BAAs and safeguards protect data while it is still identifiable, and de-identification is the controlled transformation that produces a corpus you can responsibly license or analyze at scale.

Why De-Identified Data Unlocks Broader Use

De-identification isn't just a compliance checkbox — it's what makes large-scale, responsible secondary use possible. Once the link to the individual is severed to a recognized standard, the data can support:

  • Model training for AI/ML teams that need volume, variety, and longitudinal structure.
  • Real-world evidence and drug development for pharma and clinical-development teams studying outcomes and safety signals across populations.
  • Analytics and research that would be impractical if every use required individual authorization.

Note: using real-world evidence for regulatory submissions carries additional standards beyond de-identification; treat regulatory use as its own diligence track.

The throughline is that method choice shapes data value. Safe Harbor maximizes predictability; Expert Determination maximizes preserved utility under a documented risk ceiling. The right answer depends on what the data is for.

Key Takeaways

  • PHI is identifiability, not a field. De-identification severs the link between health information and a person; once severed to HIPAA's standard, the data is no longer PHI.
  • There are exactly two legal methods under §164.514: Safe Harbor (remove 18 identifier categories) and Expert Determination (documented "very small risk" by a qualified expert).
  • Safe Harbor is predictable but blunt; Expert Determination preserves more analytic utility — including dates and geography — under a defensible risk model.
  • BAAs and de-identification are different tools. BAAs govern identifiable PHI in motion; de-identification changes the data's legal status so it can be used more broadly.
  • Method choice is a value decision for AI training and real-world evidence alike, not just a compliance formality.

Where Prometheus Fits

At Prometheus Bio, we treat de-identification as the foundation of trustworthy "ground truth" — clinical data engineered so it stays both private and genuinely useful for the work AI labs and pharma teams need to do. Understanding these methods is the first step toward evaluating any health-data source on the dimension that matters most: rigor you can defend. If you're weighing how de-identified longitudinal data could support your model or evidence pipeline, this is the literacy that makes that conversation productive.


Sources for the public regulatory facts in this article: U.S. Department of Health & Human Services guidance on de-identification (45 CFR §164.514); [HIPAA Journal — De-Identification of PHI](https://www.hipaajournal.com/de-identification-protected-health-information/).