The U.S. Department of Health and Human Services (HHS) recently released guidance on methods for de-identification of protected health information (PHI) in accordance with the Health Insurance Portability and Accountability Act (HIPAA) Privacy Rule. The guidance, which was required under Section 13424(c) of the Health Information Technology for Economic and Clinical Health (HITECH) Act, answers questions about the two methods that can be used to satisfy the HIPAA de-identification standard in 45 C.F.R. § 164.514. It also incorporates input from stakeholders that HHS received at a workshop held in March 2010.
As summarized in the figure below, the two methods by which health information can be designated as de-identified under HIPAA are (1) the “expert determination” method and (2) the “safe harbor” method.
Source:HHS Guidance Regarding Methods for De-identification of PHI in Accordance with the HIPAA Privacy Rule