Research

When health data stops counting as yours

The federal medical privacy rules define a point at which information about a person stops being protected health information. There are exactly two ways to reach it, and one of them is a list of eighteen things to remove.

By Nora Castellan, Standards Editor

The short answer

The federal medical privacy rules contain a standard for de-identification. Health information that does not identify an individual, and with respect to which there is no reasonable basis to believe that the information can be used to identify an individual, is not individually identifiable health information.

That sentence is doing something specific. Information outside the definition of individually identifiable health information is outside the protections built on that definition.

The rules then say a covered entity may determine that health information is not individually identifiable only in one of two ways. There is no third route.

One is a determination by a qualified person applying statistical and scientific methods. The other is removing a specified list of identifiers and having no actual knowledge that what remains could still identify someone.

Route one: an expert says the risk is very small

The first route requires a person with appropriate knowledge of and experience with generally accepted statistical and scientific principles and methods for rendering information not individually identifiable.

Applying those principles and methods, that person must determine that the risk is very small that the information could be used, alone or in combination with other reasonably available information, by an anticipated recipient to identify an individual who is a subject of the information.

Three phrases in that sentence carry the weight. The standard is very small rather than zero. The comparison set is other reasonably available information, not only the data at hand. And the test is framed around an anticipated recipient, which means the answer depends on who is receiving it.

The rules add a documentation requirement. The person must document the methods and results of the analysis that justify the determination.

Route two: the eighteen categories

The second route is mechanical. Eighteen categories of identifier, of the individual or of relatives, employers, or household members of the individual, have to be removed.

Names. All geographic subdivisions smaller than a state, including street address, city, county, precinct, zip code and their equivalent geocodes, with a narrow allowance for the initial three digits of a zip code subject to a population condition drawn from Census data. All elements of dates except year for dates directly related to an individual, including birth date, admission date, discharge date and date of death, and all ages over eighty-nine together with all date elements indicative of such age, which may instead be aggregated into a single category.

Telephone numbers. Fax numbers. Electronic mail addresses. Social security numbers. Medical record numbers. Health plan beneficiary numbers. Account numbers. Certificate or license numbers. Vehicle identifiers and serial numbers including license plate numbers. Device identifiers and serial numbers.

Web addresses. Internet protocol address numbers. Biometric identifiers including finger and voice prints. Full face photographic images and any comparable images.

And then a catch-all: any other unique identifying number, characteristic, or code, except as permitted by the re-identification provision.

Removing all eighteen is not sufficient on its own. The covered entity must also not have actual knowledge that the information could be used alone or in combination with other information to identify an individual who is a subject of it.

It is worth noticing what is on that list and what is not. Web addresses, IP addresses and device identifiers are enumerated. What remains after removal can still be very detailed.

The key that can put the names back

De-identified information is not necessarily permanently severed from the people it describes, and the rules say so.

A covered entity may assign a code or other means of record identification to allow de-identified information to be re-identified by the covered entity, on two conditions.

The code must not be derived from or related to information about the individual, and must not otherwise be capable of being translated so as to identify the individual. And the covered entity must not use or disclose the code for any other purpose, and must not disclose the mechanism for re-identification.

So a de-identified data set can sit alongside a key held by the entity that made it. What the rules prohibit is deriving the key from the person, using it for anything else, or handing over the method.

The limited data set is a different thing with a different list

A separate provision creates a middle category that is frequently confused with de-identified data, and the two lists are not the same length.

A limited data set is protected health information that excludes sixteen direct identifiers: names, postal address information other than town or city, state and zip code, telephone numbers, fax numbers, email addresses, social security numbers, medical record numbers, health plan beneficiary numbers, account numbers, certificate or license numbers, vehicle identifiers and serial numbers, device identifiers and serial numbers, web addresses, IP address numbers, biometric identifiers, and full face photographic images and comparable images.

Dates and town-level geography survive that list, which is precisely why it is a smaller exclusion than the de-identification safe harbour. A limited data set remains protected health information.

It may be used or disclosed only for research, public health, or health care operations, and only if the covered entity enters into a data use agreement with the recipient.

The rules specify what that agreement must do: establish the permitted uses and disclosures consistent with those three purposes, establish who may use or receive the set, and provide that the recipient will not use or further disclose the information other than as the agreement permits or as required by law, will use appropriate safeguards, will report any use or disclosure not provided for, will bind any agents to the same restrictions, and will not identify the information or contact the individuals.

There is a compliance provision with teeth in it. A covered entity is not in compliance if it knew of a pattern of activity or practice of the recipient constituting a material breach or violation of the agreement, unless it took reasonable steps to cure the breach or end the violation and, if unsuccessful, discontinued disclosure to that recipient and reported the problem to the Secretary.

Minimum necessary, and the fundraising carve-out

The same section carries two other rules that shape what leaves an organisation, and both are worth knowing because neither is about de-identification at all.

The minimum necessary standard requires a covered entity to identify the persons or classes in its workforce who need access to protected health information to carry out their duties, and the categories of information each needs, and to make reasonable efforts to limit access accordingly. For routine and recurring disclosures it must implement policies limiting what is disclosed to the amount reasonably necessary; for other disclosures it must develop criteria and review requests individually. It may not use, disclose or request an entire medical record except where that is specifically justified as the amount reasonably necessary.

The fundraising provision permits a covered entity to use, or disclose to a business associate or an institutionally related foundation, a named set of information for the purpose of raising funds for its own benefit without an authorization. That set is demographic information including name, address, other contact information, age, gender and date of birth; dates of health care provided; department of service information; treating physician; outcome information; and health insurance status.

Conditions attach. The notice of privacy practices must contain the required statement. Each fundraising communication must give the individual a clear and conspicuous opportunity to elect not to receive further ones, by a method that does not cause an undue burden or more than a nominal cost. Treatment or payment may not be conditioned on that choice. And once someone has opted out, further fundraising communications under this provision may not be made to them.

The final paragraph of the section is about verification. Before a disclosure permitted by the subpart, a covered entity must verify the identity of a person requesting protected health information, and that person's authority to have access to it, where either is not known to the entity.

What this does and does not settle

These rules apply to covered entities as the regulations define that term. A company holding health information that falls outside those definitions is not brought inside them by this section, and this article makes no claim about which sellers in this market are or are not covered entities.

Within their scope, the section answers a narrow question precisely: when information stops being individually identifiable, and therefore stops being protected health information. Two routes, one expert and one mechanical, and a documented standard for each.

It also makes clear that de-identified is not the same as untraceable. A key may exist. A limited data set retains dates and town-level geography and remains protected. And the safe harbour route depends partly on what the entity actually knows.

Nothing here says anything about what any company has done with anyone's information. It sets out the definitions, which is what a reader needs before asking a specific question of a specific privacy notice.

Key takeaways

Frequently asked questions

When is health information no longer protected under the federal privacy rules?

The rules state that health information which does not identify an individual, and with respect to which there is no reasonable basis to believe the information can be used to identify an individual, is not individually identifiable health information. A covered entity may determine that only by one of two routes: a qualified expert determination, or removal of a specified list of identifiers combined with a lack of actual knowledge that the remainder could identify someone.

What has to be removed under the safe harbour route?

Eighteen categories of identifier of the individual or of relatives, employers or household members: names; geographic subdivisions smaller than a state with a narrow three-digit zip code allowance; all date elements except year for dates directly related to an individual, plus ages over eighty-nine; telephone, fax, email, social security, medical record, health plan beneficiary, account, certificate or license, vehicle, and device numbers; web addresses; IP addresses; biometric identifiers; full face images; and any other unique identifying number, characteristic or code.

What standard does the expert route apply?

A person with appropriate knowledge of and experience with generally accepted statistical and scientific principles and methods must determine that the risk is very small that the information could be used, alone or in combination with other reasonably available information, by an anticipated recipient to identify an individual who is a subject of it. That person must document the methods and results of the analysis justifying the determination.

Can de-identified data be linked back to a person?

The rules permit a covered entity to assign a code or other means of record identification allowing it to re-identify the information, subject to two conditions. The code must not be derived from or related to information about the individual, and must not otherwise be capable of being translated to identify them. And the entity must not use or disclose the code for any other purpose, or disclose the mechanism for re-identification.

How is a limited data set different from de-identified data?

It excludes sixteen direct identifiers rather than the eighteen categories of the safe harbour, and it notably retains dates and town, city, state and zip code level geography. A limited data set remains protected health information. It may be used or disclosed only for research, public health or health care operations, and only under a data use agreement whose required contents the rules specify.

Do these rules apply to every company that holds health information?

No. They apply to covered entities as the regulations define that term. Whether a particular company is one is answered by definitions elsewhere in the same regulations, and this article makes no claim about which sellers in this market are or are not covered entities.

Sources

Each document below is named as it names itself, with the date printed on that document rather than the day it was read.

  1. Title 45 Code of Federal Regulations Section 164.514, Other requirements relating to uses and disclosures of protected health information, read in full — the de-identification standard at (a), the expert determination and the eighteen identifier categories at (b), the re-identification code conditions at (c), the minimum necessary standard at (d), the limited data set with its sixteen excluded direct identifiers and data use agreement contents at (e), the fundraising provision at (f), and the verification requirements at (h); amendment note 65 FR 82802, Dec. 28, 2000, as amended through 78 FR 34266, June 7, 2013Electronic Code of Federal Regulations, Office of the Federal Register, September 2026