HIPAA de-identification: Safe Harbor and Expert Determination
By Sam Rivera, Founder, SentinelPanda · June 19, 2026 · 1 min read · HIPAA
Data that is properly de-identified is no longer PHI — and no longer your HIPAA problem. There are exactly two approved ways to get there.
Why it matters
HIPAA only governs protected health information. If data is de-identified to the standard, it is no longer PHI, and HIPAA simply does not apply to it. That makes de-identification one of the strongest scope-reduction tools available — analytics, testing, and product work on de-identified data fall outside the rules.
Safe Harbor
The Safe Harbor method removes 18 specified identifiers (names, geographic detail below a state, dates more specific than year, contact details, IDs, and so on) and requires no actual knowledge that the remaining data could re-identify someone. It is mechanical and predictable, which is why most teams use it.
Expert Determination
The alternative has a qualified expert apply statistical methods to determine the re-identification risk is very small, and document how. It allows retaining more granular data than Safe Harbor when the analysis supports it — useful for research datasets — but requires genuine expertise, not a self-assessment.
Do it properly
Informal "we removed the names" is not de-identification and does not take data out of scope — only the two approved methods do. Decide which method fits, apply it rigorously, and document it. SentinelPanda tracks where de-identification removes data from PHI scope so your controls focus on the data that still is PHI.