Skip to content

HIPAA de-identification: Safe Harbor and Expert Determination

By Sam Rivera, Founder, SentinelPanda · June 19, 2026 · 1 min read · HIPAA

Data that is properly de-identified is no longer PHI — and no longer your HIPAA problem. There are exactly two approved ways to get there.

Why it matters

HIPAA only governs protected health information. If data is de-identified to the standard, it is no longer PHI, and HIPAA simply does not apply to it. That makes de-identification one of the strongest scope-reduction tools available — analytics, testing, and product work on de-identified data fall outside the rules.

Safe Harbor

The Safe Harbor method removes 18 specified identifiers (names, geographic detail below a state, dates more specific than year, contact details, IDs, and so on) and requires no actual knowledge that the remaining data could re-identify someone. It is mechanical and predictable, which is why most teams use it.

Expert Determination

The alternative has a qualified expert apply statistical methods to determine the re-identification risk is very small, and document how. It allows retaining more granular data than Safe Harbor when the analysis supports it — useful for research datasets — but requires genuine expertise, not a self-assessment.

Do it properly

Informal "we removed the names" is not de-identification and does not take data out of scope — only the two approved methods do. Decide which method fits, apply it rigorously, and document it. SentinelPanda tracks where de-identification removes data from PHI scope so your controls focus on the data that still is PHI.

HIPAA for SaaS and tech companies A practical data classification scheme HIPAA privacy vs security rule

Run your compliance program in one workspace.