HHS Guidance: De-identification of PHI in accordance with HIPAA

Select the "Visit Website" button to view U.S. Department of Health & Human Services guidance about methods and approaches to achieve de-identification of Protected Health Information (PHI) in accordance with the Health Insurance Portability and Accountability Act of 1996 (HIPAA) Privacy Rule. The guidance explains and answers questions regarding the two methods that can be used to satisfy the Privacy Rule's de-identification standard: Expert Determination and Safe Harbor (permanently removing all 18 identifiers). This guidance is intended to assist covered entities to understand what is de-identification, the general process by which de-identified information is created, and the options available for performing de-identification. A few notes related to common misconceptions: * Dates related to personal health (date of diagnosis, test, visit, surgery, discharge, etc.) are considered a HIPAA identifier. Consider using year only, or relative dates (such as setting surgery date as day 0 and making all dates just day counts relative to day 0, not actual month/day/year). * Linked and coded data is not the same as de-identified data. It may also be helpful to review this portal page: Does my study need health sciences IRB approval?

Attachments

There are no files to display.