HIPAA De-identification and Data Anonymization 4 — Questions and Answers
Question 1: A covered entity removes all 18 Safe Harbor identifiers but retains free-text clinical notes. Is the resulting data de-identified under HIPAA?
- Yes, because all 18 required identifiers have been removed
- No, because free-text notes may contain incidental identifiers and the entity must verify no such information remains (Correct answer)
- Yes, because free-text clinical notes are not PHI under HIPAA
- No, because de-identification always requires Expert Determination for datasets with clinical notes
Correct answer: No, because free-text notes may contain incidental identifiers and the entity must verify no such information remains
Safe Harbor also requires that the covered entity have no actual knowledge that the remaining information could identify an individual, which unredacted free-text notes often violate.
Question 2: What is 'differential privacy' and how does it relate to HIPAA de-identification?
- A HIPAA-mandated standard that replaces Safe Harbor for datasets over 1 million records
- A mathematical technique that adds calibrated noise to query results to protect individual privacy while enabling statistical analysis (Correct answer)
- A method of encrypting only the differential (changed) portions of a PHI dataset between updates
- A requirement that different workforce members access different subsets of de-identified data
Correct answer: A mathematical technique that adds calibrated noise to query results to protect individual privacy while enabling statistical analysis
Differential privacy adds mathematically calibrated noise to data outputs so that the presence or absence of any single individual cannot be detected, providing strong privacy guarantees beyond traditional de-identification.
Question 3: Under HIPAA, which of the following correctly describes when de-identified data is no longer subject to the Privacy Rule?
- When it is encrypted with a NIST-approved algorithm
- When either Safe Harbor or Expert Determination de-identification is properly applied and no actual knowledge of re-identification exists (Correct answer)
- When a business associate agreement is in place with all recipients
- When OCR issues a formal de-identification certification for the dataset
Correct answer: When either Safe Harbor or Expert Determination de-identification is properly applied and no actual knowledge of re-identification exists
HIPAA's Privacy Rule ceases to apply once information is de-identified using Safe Harbor or Expert Determination and the covered entity has no actual knowledge that the information could re-identify individuals.
Question 4: A hospital's de-identification policy strips birth years from all records. Under Safe Harbor, is this required for patients under age 90?
- Yes, all birth years must be removed regardless of patient age
- No, only the full date of birth must be removed; the year of birth may be retained for patients under 90 (Correct answer)
- Yes, but only if the patient lives in a county with fewer than 20,000 people
- No, birth years are not among the 18 Safe Harbor identifiers at all
Correct answer: No, only the full date of birth must be removed; the year of birth may be retained for patients under 90
Safe Harbor requires removal of the full date of birth (month, day, and year) but permits retention of the year of birth for patients aged 89 or younger.
Question 5: Which characteristic makes a data element a 'quasi-identifier' in health data de-identification?
- It is one of the 18 identifiers explicitly listed in HIPAA's Safe Harbor method
- It is an attribute that, alone or combined with others, can narrow down records to a specific individual (Correct answer)
- It is any demographic field that appears in the dataset more than 100 times
- It is a field that identifies the covered entity rather than the patient
Correct answer: It is an attribute that, alone or combined with others, can narrow down records to a specific individual
Quasi-identifiers are attributes such as age, gender, and ZIP code that are not direct identifiers but can be combined with external data to re-identify individuals.
Question 6: A public health agency requests a dataset with patient ZIP codes, admission dates, and diagnoses to track disease outbreaks. All 18 Safe Harbor identifiers have been removed. Is this permissible?
- Yes, this is fully de-identified data and can be shared without restriction
- Only if the agency signs a business associate agreement
- The covered entity must confirm no actual knowledge of re-identification; in small populations, residual risk may still exist (Correct answer)
- No, public health disclosures always require patient authorization
Correct answer: The covered entity must confirm no actual knowledge of re-identification; in small populations, residual risk may still exist
Even after Safe Harbor removal, the covered entity must ensure no actual knowledge of re-identification; small geographic areas or rare diagnoses can create residual risk requiring further action.
Question 7: What is 'data masking' in the context of HIPAA de-identification?
- A process that encrypts entire PHI files so they cannot be read without a key
- Replacing sensitive data values with realistic but fictitious substitutes to preserve data format and utility (Correct answer)
- Removing all data fields except those approved by the HIPAA Privacy Rule
- A technique that splits a database across multiple servers so no single server holds complete PHI
Correct answer: Replacing sensitive data values with realistic but fictitious substitutes to preserve data format and utility
Data masking substitutes real PHI values with realistic fictional values (e.g., replacing a real name with a fake name) to maintain data structure and utility while eliminating actual identifiers.
A covered entity removes all 18 Safe Harbor identifiers but retains free-text clinical notes.
Is the resulting data de-identified under HIPAA?