HIPAA De-identification and Data Anonymization 2 — Questions and Answers
Question 1: Under HIPAA's Expert Determination method, what standard must a statistician meet to certify de-identification?
- The risk of identifying an individual must be less than 0.1%
- The risk of identifying an individual is very small and the methods used are documented (Correct answer)
- At least 18 identifiers must be removed from the dataset
- The data must be encrypted using AES-256 or stronger
Correct answer: The risk of identifying an individual is very small and the methods used are documented
Under Expert Determination, a qualified statistician must certify that the risk of identification is 'very small' and document the methods and results of analysis.
Question 2: Which of the following geographic data elements is permitted to remain in a Safe Harbor de-identified dataset?
- Five-digit ZIP codes
- City names
- Three-digit ZIP code prefixes for all regions (Correct answer)
- County names
Correct answer: Three-digit ZIP code prefixes for all regions
Three-digit ZIP code prefixes may be retained under Safe Harbor unless the geographic area they cover contains 20,000 or fewer people, in which case '000' must replace the three-digit code.
Question 3: A hospital wants to share patient data with a research partner. After removing all 18 Safe Harbor identifiers, they discover the dataset still contains information that could re-identify patients. What should the covered entity do?
- Share the data anyway since all 18 identifiers were removed
- Apply additional de-identification measures or use Expert Determination to certify safety (Correct answer)
- Obtain patient consent before sharing the already de-identified data
- File a breach notification since re-identification is possible
Correct answer: Apply additional de-identification measures or use Expert Determination to certify safety
If a covered entity has 'actual knowledge' that remaining information could re-identify individuals, the data is not considered de-identified and further steps must be taken.
Question 4: Which of the following is NOT one of the 18 categories of identifiers that must be removed under HIPAA's Safe Harbor method?
- Medical record numbers
- Health plan beneficiary numbers
- ICD diagnosis codes (Correct answer)
- Biometric identifiers including finger and voice prints
Correct answer: ICD diagnosis codes
ICD diagnosis codes (clinical codes describing a patient's condition) are not among the 18 Safe Harbor identifiers and may remain in de-identified data.
Question 5: What is a 'limited data set' under HIPAA, and how does it differ from fully de-identified data?
- A limited data set is fully de-identified and can be shared without restrictions
- A limited data set removes only direct identifiers but may retain dates and geographic data, requiring a data use agreement (Correct answer)
- A limited data set is protected health information that requires patient authorization to share
- A limited data set is any dataset under 500 records that is automatically exempt from HIPAA
Correct answer: A limited data set removes only direct identifiers but may retain dates and geographic data, requiring a data use agreement
A limited data set removes direct identifiers (names, addresses, phone numbers, etc.) but may retain dates and geographic subdivisions smaller than a state, and sharing requires a data use agreement.
Question 6: Under the Safe Harbor method, what must a covered entity do with dates of birth for patients aged 90 or older?
- Replace the exact date with the year of birth only
- Remove the age entirely and replace with 'elderly'
- Aggregate all ages 90 and above into a single category such as '90 or older' (Correct answer)
- Encrypt the date of birth while leaving it in the dataset
Correct answer: Aggregate all ages 90 and above into a single category such as '90 or older'
Safe Harbor requires that ages and dates for individuals over 89 must be aggregated into a category of age 90 or older to prevent identification of very elderly individuals.
Question 7: Which scenario describes re-identification risk in a de-identified dataset?
- A dataset contains only aggregated statistics with no individual records
- A dataset with rare disease diagnoses in a small geographic area could allow linking back to specific patients (Correct answer)
- A dataset encrypted with a HIPAA-approved algorithm shared with a business associate
- A dataset containing only ICD codes and admission months for a large urban hospital
Correct answer: A dataset with rare disease diagnoses in a small geographic area could allow linking back to specific patients
When rare diagnoses are combined with small geographic areas, the combination can be unique enough to identify specific individuals even without explicit identifiers.
Under HIPAA's Expert Determination method, what standard must a statistician meet to certify de-identification?