1.3 Protected Health Information (PHI), 18 Identifiers & De-Identification Methods

Key Takeaways

  • Individually Identifiable Health Information (IIHI) is created or received by a covered entity/employer and relates to physical/mental health, healthcare provision, or payment, while Protected Health Information (PHI) encompasses IIHI transmitted or maintained in any medium (45 CFR § 160.103).
  • PHI specifically excludes employment records held by a covered entity in its role as employer, student education records subject to FERPA, and health data of deceased individuals who have been deceased for more than 50 years.
  • The Safe Harbor De-Identification Method (45 CFR § 164.514(b)(2)) requires removing 18 specified direct and indirect identifiers concerning the individual, relatives, employers, or household members, coupled with no actual knowledge of re-identification capability.
  • The Expert Determination Method (45 CFR § 164.514(b)(1)) relies on statistical and scientific principles applied by a qualified statistical expert to ensure the risk of re-identification is very small, requiring documented methodology retained for 6 years.
  • A Limited Data Set (LDS) under 45 CFR § 164.514(e) permits retaining dates and geographic elements (city, state, ZIP) exclusively for research, public health, or healthcare operations, conditioned upon a legally binding Data Use Agreement (DUA).
Last updated: August 2026

Protected Health Information (PHI), 18 Identifiers & De-Identification Methods

At the core of the HIPAA Privacy Rule lies the fundamental construct of Protected Health Information (PHI). Compliance Officers must possess an unyielding command of what constitutes PHI, what data categories are statutorily excluded, and the precise legal and statistical methodologies required to transform identifiable data into De-Identified Data or a Limited Data Set (LDS).

Under 45 CFR § 160.103 and 45 CFR § 164.514, the Privacy Rule establishes strict standards for data classification. Misclassifying identifiable patient data as de-identified exposes an organization to massive breach notification liabilities, civil monetary penalties, and regulatory sanctions.


1. Statutory Definitions: IIHI vs. PHI

The Privacy Rule distinguishes between Individually Identifiable Health Information (IIHI) and Protected Health Information (PHI).

+-----------------------------------------------------------------------------+
|                   INFORMATION CLASSIFICATION HIERARCHY                      |
|                                                                             |
|   [INDIVIDUALLY IDENTIFIABLE HEALTH INFORMATION (IIHI)] (42 U.S.C. 1320d)   |
|   - Information created or received by a healthcare provider, health plan,  |
|     employer, or healthcare clearinghouse; AND                              |
|   - Relates to past, present, or future physical/mental health condition,   |
|     the provision of healthcare, or payment for healthcare; AND             |
|   - Identifies the individual OR provides reasonable basis for identification|
|                                      |                                      |
|                                      v (Maintained or Transmitted)          |
|   [PROTECTED HEALTH INFORMATION (PHI)] (45 CFR § 160.103)                   |
|   - IIHI transmitted or maintained in ANY form or medium:                   |
|     * Electronic media (ePHI: servers, cloud, email, mobile devices, EHR)   |
|     * Paper records (charts, billing invoices, paper prescriptions)         |
|     * Spoken / Oral communications (verbal handoffs, telephone calls)       |
+-----------------------------------------------------------------------------+

Statutory Exclusions from PHI

Under 45 CFR § 160.103, PHI explicitly excludes:

  1. Education Records Covered by FERPA: Student medical records maintained by educational agencies or institutions (20 U.S.C. § 1232g).
  2. Student Treatment Records: Records of university students aged 18+ or attending post-secondary institutions, used solely for treatment and disclosed only to treating professionals.
  3. Employment Records Held in the Role as Employer: Records held by a covered entity strictly in its capacity as an employer (e.g., pre-employment drug screenings, OSHA medical surveillance records, FMLA medical certifications, fit-for-duty evaluations, workers' compensation claim files, and employee vaccination records).
  4. Deceased Individuals (The 50-Year Rule): Under 45 CFR § 164.502(f) (enacted under the 2013 Omnibus Rule), health information ceases to be PHI 50 years following the date of the individual's death.

[!NOTE] The Healthcare System Employee Patient: When an employee of a hospital receives clinical care as a patient within that hospital, their treatment record in the hospital's EHR is PHI, not an employment record. The employer-hospital cannot access that clinical record for human resources or managerial purposes without a valid HIPAA authorization.


2. The 18 HIPAA Identifiers (Safe Harbor De-Identification Method)

Under 45 CFR § 164.514(b)(2), health information is considered de-identified under the Safe Harbor Method only if all 18 specified identifiers of the individual, or of relatives, employers, or household members of the individual, are removed, and the covered entity has no actual knowledge that the remaining information could be used alone or in combination with other data to identify the person.

+-----------------------------------------------------------------------------+
|                        THE 18 HIPAA SAFE HARBOR IDENTIFIERS                 |
|                              (45 CFR § 164.514(b)(2))                       |
|                                                                             |
|   1. Names (Full or partial)                                                |
|   2. Geographic subdivisions smaller than a State:                          |
|      - Street address, city, county, precinct, ZIP code, & geocodes         |
|      - ZIP Rule: First 3 digits allowed ONLY IF matching 3-digit unit has   |
|        population > 20,000; otherwise must be masked to '000'               |
|   3. All elements of DATES (except year) directly related to an individual: |
|      - Birth date, admission date, discharge date, date of death/service    |
|      - Age Rule: All ages over 89 and elements indicative of age must be    |
|        aggregated into a single category of '90 or older'                   |
|   4. Telephone numbers                                                      |
|   5. Fax numbers                                                            |
|   6. Email addresses                                                        |
|   7. Social Security numbers (SSN)                                          |
|   8. Medical Record numbers (MRN)                                           |
|   9. Health Plan Beneficiary numbers                                        |
|  10. Account numbers                                                        |
|  11. Certificate / License numbers                                          |
|  12. Vehicle identifiers and serial numbers (including license plates)      |
|  13. Device identifiers and serial numbers (e.g., pacemaker UUIDs)          |
|  14. Web Universal Resource Locators (URLs)                                 |
|  15. Internet Protocol (IP) addresses                                       |
|  16. Biometric identifiers (including finger, palm, and voice prints)       |
|  17. Full-face photographic images and any comparable images                |
|  18. Any other unique identifying number, characteristic, or code           |
|      (excluding a secure re-identification key compliant with §164.514(c)) |
+-----------------------------------------------------------------------------+

The "Actual Knowledge" Standard

Even if all 18 identifiers are successfully scrubbed, the information is not de-identified if the covered entity has actual knowledge that a recipient could use the remaining data (for example, a rare clinical condition combined with a small town or public news story) to identify an individual.

Re-Identification Codes (§ 164.514(c))

A covered entity may assign a unique code or mechanism to allow de-identified records to be re-identified by the covered entity, provided that:

  1. The code is not derived from or related to information about the individual (e.g., cannot be a hash of the SSN or MRN).
  2. The code is not capable of being translated so as to identify the individual.
  3. The covered entity does not disclose the key or re-identification mechanism to any third party.

3. The Expert Determination Method

Under 45 CFR § 164.514(b)(1), an alternative method for de-identification allows organizations to retain valuable research variables (such as dates or geographic locations) through mathematical and statistical risk modeling.

+-----------------------------------------------------------------------------+
|                 EXPERT DETERMINATION METHOD (45 CFR § 164.514(b)(1))        |
|                                                                             |
|   [STEP 1: QUALIFIED EXPERT ENGAGEMENT]                                     |
|   - Professional with appropriate scientific / statistical knowledge        |
|     and experience applying mathematical principles                         |
|                             |                                               |
|                             v                                               |
|   [STEP 2: STATISTICAL RISK EVALUATION & MITIGATION]                        |
|   - Evaluates data context, recipient environment, and linking datasets     |
|   - Applies statistical perturbation, binning, noise injection, or k-anonymity|
|   - Determines the risk is "VERY SMALL" that an anticipated recipient      |
|     could identify an individual                                            |
|                             |                                               |
|                             v                                               |
|   [STEP 3: FORMAL DOCUMENTATION & RETENTION]                                |
|   - Documents expert credentials, mathematical methods, and risk analysis   |
|   - Must retain documentation for a minimum of SIX (6) YEARS (§ 164.530(j)) |
+-----------------------------------------------------------------------------+

Unlike the rigid checklist of Safe Harbor, Expert Determination evaluates the contextual risk environment, including recipient controls, data access restrictions, and available external voter/census datasets that could be linked to the data.


4. Limited Data Sets (LDS) & Data Use Agreements (DUA)

When healthcare operations, public health initiatives, or medical research require more data than Safe Harbor allows (specifically, dates and geographic elements), but full PHI is unnecessary, organizations utilize a Limited Data Set (LDS) under 45 CFR § 164.514(e).

+-----------------------------------------------------------------------------+
|                      LIMITED DATA SET (LDS) ARCHITECTURE                    |
|                                                                             |
|   [WHAT MUST BE REMOVED (16 DIRECT IDENTIFIERS)]                            |
|   - Names, street addresses, phone/fax, email, SSN, MRN, account numbers,   |
|     certificate/license numbers, vehicle IDs, device IDs, URLs, IP addresses,|
|     biometrics, and full-face photos.                                       |
|                                                                             |
|   [WHAT MAY BE RETAINED IN AN LDS]                                          |
|   - Dates: Admission, discharge, service, birth, and death dates.           |
|   - Geographic Data: Town, City, State, and 5-digit ZIP code.               |
|   - Age: Exact age in years, months, days (including ages > 89).            |
|                                                                             |
|   [MANDATORY GOVERNANCE: DATA USE AGREEMENT (DUA)]                          |
|   - No patient authorization required, BUT recipient MUST sign a DUA        |
|   - Permitted Purposes: RESEARCH, PUBLIC HEALTH, or HEALTHCARE OPERATIONS   |
+-----------------------------------------------------------------------------+

Mandatory Elements of a Data Use Agreement (DUA)

Under 45 CFR § 164.514(e)(4), a legally binding DUA between the covered entity and the LDS recipient must:

  1. Establish Permitted Uses: Specify that the data will be used solely for research, public health, or healthcare operations.
  2. Identify Authorized Users: Establish who is permitted to use or receive the limited data set.
  3. Prohibit Re-Identification & Contact: Explicitly prohibit the recipient from attempting to re-identify the information or contacting any individual.
  4. Safeguard the Data: Require the recipient to implement appropriate administrative, physical, and technical safeguards to prevent unauthorized use or disclosure.
  5. Report Breaches: Mandate immediate reporting to the covered entity of any use or disclosure not provided for by the DUA.
  6. Flowdown Restrictions: Ensure any subcontractors or agents agree to the same restrictions and conditions.

5. Comprehensive Comparison Matrix: PHI vs. LDS vs. De-Identified Data

Compliance DimensionFully Identifiable PHILimited Data Set (LDS)De-Identified Data (Safe Harbor / Expert)
Legal StatusPHI (Full HIPAA protection)PHI (Hybrid subset)Not PHI (Exempt from HIPAA)
Governing Regulation45 CFR Part 164 Subparts A & E45 CFR § 164.514(e)45 CFR § 164.514(a)-(c)
Patient AuthorizationRequired (unless TPO or §164.512 exception)Not RequiredNot Required
Permitted UsesTreatment, Payment, Operations, LawResearch, Public Health, Healthcare OpsAny lawful purpose (No restrictions)
Required AgreementBusiness Associate Agreement (if BA)Data Use Agreement (DUA)None required
Accounting of DisclosuresMandatory tracking (§ 164.528)Exempt from individual accountingExempt from individual accounting
Breach Notification RuleFully applies if breachedFully applies if breachedInapplicable (Data is not PHI)
Geographic ElementsFull street address, city, state, ZIPCity, State, 5-digit ZIP codeState only (or 3-digit ZIP >20k pop.)
Date ElementsFull dates (service, birth, death)Full dates (service, birth, death)Year only (Ages >89 aggregated to 90+)
Loading diagram...
HIPAA De-Identification and Data Classification Pathway
Test Your Knowledge

A hospital's human resources department maintains employee medical files containing mandatory annual tuberculosis (TB) skin test results, pre-employment drug screening reports, and Family and Medical Leave Act (FMLA) medical certifications. Under 45 CFR § 160.103, how are these records classified?

A
B
C
D
Test Your Knowledge

Under the HIPAA Safe Harbor De-Identification Method (45 CFR § 164.514(b)(2)), which of the following rules applies to geographic subdivisions and age variables?

A
B
C
D
Test Your Knowledge

A clinical research team seeks to analyze patient outcome data including exact admission dates, discharge dates, dates of surgical procedures, and 5-digit ZIP codes without obtaining individual patient authorizations. What mechanism permits this disclosure under HIPAA?

A
B
C
D