Compliance with HIPAA security regulations
Identifying and de-identifying health information (PHI) in any source


De-identification refers to processes that remove personally identifiable information (PII) from protected health information (PHI) and other "sensitive data.".
PHI de-identification is a specific requirement in Healthcare, where they for example are included in both the „Safe Harbor“ and the „Expert Determination Methodology“used in medical research (to remove patient identities from study data). De-identification is also a general term for the anonymization or masking of PII in many other industries.”.
The latest Safety Rules in the HIPAA-Regulations (45 CFR Parts 160 and 164) establish the compliance requirements for organizations that handle PHI. The HIPAA rules apply to 18 specific identifiers:
|
Name |
Address |
Date of birth |
|
Phone number |
Fax number |
Email Address |
|
Social security number |
Medical Record |
Health insurance policyholder |
|
Account number |
Certificates |
Auto-ID |
|
Device ID |
Personal URL |
IP Address |
|
Biometric ID |
Face |
Another unique ID code |
Each of the data masking software products in the IRI Data Protection Suite helps you with PII, PAN, PHI, etc. in multiple data sources to find, to classify and then to protect, to ensure compliance with Safe Harbor rules. They also work hand-in-hand with a free, advanced re-ID Risk Assessment Technology to comply with the rule of the expert determination method. For more information on what PHI is, see in this article I am the HIPAA Journal.
HIPAA compliance requires both:
Editorial – Safe Haven
Manipulation, masking, or removal of these key identifiers, making it difficult or impossible to identify a person or recover the original data.
De-identification – Expert Determination Method
The removal of identifiers and the generalization of quasi-identifiers until an expert determines the statistical risk of re-identification is very low.
Here Learn about our three-hour online HIPAA compliance course that covers de-identification of PHI and masking of structured, semi-structured, and unstructured data sources on-premises and in the cloud, as well as re-ID risk assessment processes for structured data. The course also includes information on regulatory compliance certification, data breach insurance, and defending against data breach claims.
Blog Article
Other resources