By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Health Works CollectiveHealth Works Collective
  • Health
    • Mental Health
    Health
    Healthcare organizations are operating on slimmer profit margins than ever. One report in August showed that they are even lower than the beginning of the…
    Show More
    Top News
    improving patient experience
    6 Ways to Improve Patient Satisfaction Within Hospitals
    December 1, 2021
    degree for healthcare job
    What Are The Health Benefits Of Having A Degree?
    March 9, 2022
    custom software development is changing healthcare
    Digital Customer Journey Mapping and its Importance for Healthcare
    July 21, 2022
    Latest News
    How to Combat Home Sickness After Moving Abroad
    March 19, 2023
    4 Ways to Recover from a Broken Hip
    March 14, 2023
    What Are Dietary Supplements: Purpose, Benefits, & Facts
    March 15, 2023
    5 Benefits of Receiving Acupuncture Regularly
    March 9, 2023
  • Policy and Law
    • Global Healthcare
    • Medical Ethics
    Policy and Law
    Get the latest updates about Insurance policies and Laws in the Healthcare industry for different geographical locations.
    Show More
    Top News
    Cash for mammograms is ‘ethically troubling,’ JAMA article says
    September 12, 2015
    Six Tips To Help You Provide Better Patient Care
    September 26, 2017
    The Elephant in the Room: Discussing Obesity with the Doctor
    August 23, 2017
    Latest News
    3 Ways to Improve the U.S. Healthcare System By 2030
    March 14, 2023
    6 Steps To Ensure Speed And Efficiency Of Clinical Studies
    March 14, 2023
    5 Most Valuable Healthcare Programs in 2023
    March 8, 2023
    The Everest Foundation’s Mission to Support Inclusive Healthcare
    February 24, 2023
  • Medical Innovations
  • News
  • Wellness
  • Tech
Search
© 2023 HealthWorks Collective. All Rights Reserved.
Reading: OCR Releases HIPAA Privacy Rule Guidance on De-Identifying PHI
Share
Sign In
Notification Show More
Latest News
mental health tips
Caring for Your Mental Health Should Be a Top Priority
Mental Health
combat home sickness
How to Combat Home Sickness After Moving Abroad
Health News
depression signs
Early Signs of Depression that You Shouldn’t Ignore
Mental Health
positive mental health
How to Build a Positive Mental Health Environment
Mental Health
broken hip recovery
4 Ways to Recover from a Broken Hip
Health
Aa
Health Works CollectiveHealth Works Collective
Aa
Search
Have an existing account? Sign In
Follow US
  • About
  • Contact
  • Privacy
© 2023 HealthWorks Collective. All Rights Reserved.
Health Works Collective > Policy & Law > OCR Releases HIPAA Privacy Rule Guidance on De-Identifying PHI
Policy & Law

OCR Releases HIPAA Privacy Rule Guidance on De-Identifying PHI

David Harlow
Last updated: 2012/11/28 at 6:07 AM
David Harlow
Share
7 Min Read
SHARE

HHS OCRJust two and a half years after hosting a workshop on the HIPAA Privacy Rule’s de-identification standard, OCR has issued its “HHS OCRJust two and a half years after hosting a workshop on the HIPAA Privacy Rule’s de-identification standard, OCR has issued its “Guidance Regarding Methods for De-identification of Protected Health Information in Accordance with the Health Insurance Portability and Accountability Act (HIPAA) Privacy Rule.” Like they say, it’s not rocket surgery — and there are few surprises here. One area worth reviewing is the expert determination section — for those of you using, or considering the use of, expert opinions to guide your de-identification programs. Reproduced below is a table describing some of the principles used by experts in determining whether information has been de-identified:

 

Table 1. Principles used by experts in the determination of the identifiability of health information.

PrincipleDescriptionExamples
ReplicabilityPrioritize health information features into levels of risk according to the chance it will consistently occur in relation to the individual.Low: Results of a patient’s blood glucose level test will vary
High: Demographics of a patient (e.g., birth date) are relatively stable
Data source AvailabilityDetermine which external data sources contain the patients’ identifiers and the replicable features in the health information, as well as who is permitted access to the data source.Low: The results of laboratory reports are not often disclosed with identity beyond healthcare environments.
High: Patient name and demographics are often in public data sources, such as vital records — birth, death, and marriage registries.
DistinguishabilityDetermine the extent to which the subject’s data can be distinguished in the health information.Low: It has been estimated that the combination of Year of Birth, Gender,and 3-Digit ZIP Code is unique for approximately 0.04% of residents in the United States.  This means that very few residents could be identified through this combination of data alone.
High: It has been estimated that the combination of a patient’s Date of Birth, Gender, and 5-Digit ZIP Code is unique for over 50% of residents in the United States.  This means that over half of U.S. residents could be uniquely described just with these three data elements.
Assess RiskThe greater the replicability, availability, and distinguishability of the health information, the greater the risk for identification.Low: Laboratory values may be very distinguishing, but they are rarely independently replicable and are rarely disclosed in multiple data sources to which many people have access.
High: Demographics are highly distinguishing, highly replicable, and are available in public data sources.

One element of the expert determination worth noting is the notion that a determination should perhaps be time-limited.  Since that which is de-identified today may not be de-identified tomorrow (thanks in part to the rapid growth in the volume of data that is made available to the public on the internet).  Here is the relevant FAQ:

More Read

benefits of EHR systems in healthcare

Using EHR systems in healthcare for Cost-Effective Services

Benefits of Emerging Technology in Healthcare in 2023
Why Is a Referenced Based Pricing Tool Necessary?
Simplifying the Genetic Testing Process: How At-Home Kits are Changing the Game
9 Hospitals That Have Introduced Green Initiatives

How long is an expert determination valid for a given data set?

The Privacy Rule does not explicitly require that an expiration date be attached to the determination that a data set, or the method that generated such a data set, is de-identified information.  However, experts have recognized that technology, social conditions, and the availability of information changes over time.  Consequently, certain de-identification practitioners use the approach of time-limited certifications.  In this sense, the expert will assess the expected change of computational capability, as well as access to various data sources, and then determine an appropriate timeframe within which the health information will be considered reasonably protected from identification of an individual.

Information that had previously been de-identified may still be adequately de-identified when the certification limit has been reached.  When the certification timeframe reaches its conclusion, it does not imply that the data which has already been disseminated is no longer sufficiently protected in accordance with the de-identification standard.  Covered entities will need to have an expert examine whether future releases of the data to the same recipient (e.g., monthly reporting) should be subject to additional or different de-identification processes consistent with current conditions to reach the very low risk requirement.

It is also worth noting that the guidelines suggest that a data use agreement is not required to be put in place in connection with the sharing of data de-identified in accordance with an expert determination. However, use of such agreements is common, whether or not data has been de-identified, and may contain other provisions of value to the parties.

(I was also tickled to learn the identity of the seventeen ZIP code tabulation areas — identified by the first three digits of their ZIP codes– that include fewer than 20,000 residents each per the 2000 Census, and therefore must be listed as 000 in order for a record containing one of them to be condidered de-identified.) 

When it comes to HIPAA compliance, these guidelines provide a greater measure of certainty regarding the privacy rule for folks in the secondary use of health data market. It remains to be seen whether the market has anticipated the content of these guidelines or whether there will be an uptick in the secondary use market, and further growth of “big data” in health care and/or an increase in the proliferation of health management tools (including mHealth apps using this population health data), as a result of the guidelines’ release.


TAGGED: HIPAA

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
David Harlow November 28, 2012
Share this Article
Facebook Twitter Copy Link Print
Share
By David Harlow
Follow:
DAVID HARLOW is Principal of The Harlow Group LLC, a health care law and consulting firm based in the Hub of the Universe, Boston, MA. His thirty years’ experience in the public and private sectors affords him a unique perspective on legal, policy and business issues facing the health care community. David is adept at assisting clients in developing new paradigms for their business organizations, relationships and processes so as to maximize the realization of organizational goals in a highly regulated environment, in realms ranging from health data privacy and security to digital health strategy to physician-hospital relationships to the avoidance of fraud and abuse. He's been called "an expert on HIPAA and other health-related law issues [who] knows more than virtually anyone on those topics.” (Forbes.com.) His award-winning blog, HealthBlawg, is highly regarded in both the legal and health policy blogging worlds. David is a charter member of the external Advisory Board of the Mayo Clinic Social Media Network and has served as the Public Policy Chair of the Society for Participatory Medicine, on the Health Law Section Council of the Massachusetts Bar Association and on the Advisory Board of FierceHealthIT. He speaks regularly before health care and legal industry groups on business, policy and legal matters. You should follow him on Twitter.
Previous Article Medications and Your Dental Health
Next Article Meet the Bone Ninja, an iPad App That Analyzes Bone Deformities!

Stay Connected

1.5k Followers Like
4.5k Followers Follow
2.8k Followers Pin
136k Subscribers Subscribe

Latest News

mental health tips
Caring for Your Mental Health Should Be a Top Priority
Mental Health March 19, 2023
combat home sickness
How to Combat Home Sickness After Moving Abroad
Health News March 19, 2023
depression signs
Early Signs of Depression that You Shouldn’t Ignore
Mental Health March 19, 2023
positive mental health
How to Build a Positive Mental Health Environment
Mental Health March 15, 2023

You Might also Like

US healthcare system
Global Healthcare

3 Ways to Improve the U.S. Healthcare System By 2030

March 14, 2023
Clinical Studies
Global Healthcare

6 Steps To Ensure Speed And Efficiency Of Clinical Studies

March 14, 2023
valueable healthcare programs
News

5 Most Valuable Healthcare Programs in 2023

March 8, 2023
everest healthcare
Global Healthcare

The Everest Foundation’s Mission to Support Inclusive Healthcare

February 24, 2023
//

We influence million of users and is the most authentic source of information on healthcare business and technology news.

Quick Links

  • About
  • Contact
  • Privacy
Subscribe

Subscribe to our newsletter to get our newest articles instantly!

Follow US

© 2008-2023 HealthWorks Collective. All Rights Reserved.

Removed from reading list

Undo
Welcome Back!

Sign in to your account

Lost your password?