CHPC De-identification of Protected Health Information 1 — Questions and Answers
Question 1: Under HIPAA, which two methods are officially recognized for de-identifying protected health information?
- Safe Harbor and Expert Determination (Correct answer)
- Anonymization and Pseudonymization
- Encryption and Tokenization
- Data Masking and Aggregation
Correct answer: Safe Harbor and Expert Determination
HIPAA's Privacy Rule recognizes two de-identification methods: Safe Harbor (removing 18 specified identifiers) and Expert Determination (a qualified statistician certifies re-identification risk is very small).
Question 2: Under the HIPAA Safe Harbor method, how many specific categories of identifiers must be removed to achieve de-identification?
- 12
- 15
- 18 (Correct answer)
- 21
Correct answer: 18
The Safe Harbor method requires removal of exactly 18 categories of identifiers, including names, geographic data smaller than a state, dates, phone numbers, Social Security numbers, and biometric identifiers.
Question 3: Under the HIPAA Safe Harbor method, which geographic data element may be retained in de-identified data?
- Street address
- County name
- The state (Correct answer)
- Full 5-digit ZIP code
Correct answer: The state
Safe Harbor requires removal of all geographic subdivisions smaller than a state, but the state itself may be retained in de-identified information.
Question 4: What is a 'limited data set' under HIPAA's Privacy Rule?
- PHI with all 18 Safe Harbor identifiers removed
- PHI with direct identifiers removed but some indirect identifiers such as dates retained (Correct answer)
- Fully anonymized health information with no remaining identifiers
- Encrypted PHI accessible only to authorized workforce members
Correct answer: PHI with direct identifiers removed but some indirect identifiers such as dates retained
A limited data set has direct identifiers (names, addresses, phone numbers, SSNs) removed, but may retain indirect identifiers such as dates, ages, and geographic information at the city, state, or ZIP code level.
Question 5: When a covered entity shares a limited data set, what agreement must be executed with the recipient?
- Business Associate Agreement
- Data Use Agreement (Correct answer)
- Memorandum of Understanding
- Confidentiality and Non-Disclosure Agreement
Correct answer: Data Use Agreement
HIPAA requires a Data Use Agreement (DUA) between the covered entity and any recipient of a limited data set, specifying permitted uses and prohibiting re-identification attempts.
Question 6: Under the Expert Determination method of de-identification, what must the qualified expert certify?
- That all 18 Safe Harbor identifiers have been removed
- That the data has been encrypted using FIPS 140-2 compliant algorithms
- That the risk of identifying any individual is very small using generally accepted statistical principles (Correct answer)
- That the dataset contains fewer than 100 records
Correct answer: That the risk of identifying any individual is very small using generally accepted statistical principles
Under Expert Determination, a person with statistical or scientific knowledge must apply generally accepted principles and document that the probability of identifying an individual is very small.
Question 7: Once information has been properly de-identified according to HIPAA standards, how does this affect the data's legal status?
- It remains PHI but with reduced privacy protections
- It is no longer considered PHI and HIPAA's Privacy Rule does not apply to it (Correct answer)
- It can only be used for treatment purposes without further restrictions
- It requires patient authorization before it may be used or disclosed
Correct answer: It is no longer considered PHI and HIPAA's Privacy Rule does not apply to it
Properly de-identified information is no longer considered PHI, so the HIPAA Privacy Rule's protections, restrictions, and authorization requirements no longer apply to it.
Under HIPAA, which two methods are officially recognized for de-identifying protected health information?