De-identification and Data Anonymization Flashcards
36 cards from real HIPAA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 20 De-identification and Data Anonymization flashcards as text
Under HIPAA, what is the primary significance of de-identifying health information?
Answer: De-identified information is no longer PHI and is not subject to HIPAA's privacy protections
Once properly de-identified under HIPAA standards, health information is no longer considered PHI and falls outside the scope of HIPAA's privacy and security requirements.
HIPAA's Safe Harbor de-identification method requires removal of how many specific identifiers?
Answer: 18 identifiers
HIPAA's Safe Harbor method requires removal of 18 specific categories of identifiers to de-identify health information.
Under HIPAA's Expert Determination method of de-identification, who must make the determination?
Answer: A person with appropriate knowledge and experience applying statistical and scientific principles to health data
Expert Determination requires a qualified statistician or data scientist with appropriate experience in applying scientific principles to determine that re-identification risk is very small.
Which of the following items must be removed under HIPAA's Safe Harbor de-identification method?
Answer: ZIP codes with populations less than 20,000
Geographic data below the state level must be removed, including ZIP codes that could identify small populations. The first three digits of ZIP codes may be retained if the geographic area contains more than 20,000 people.
Under HIPAA Safe Harbor de-identification, how must ages over 89 be handled?
Answer: They may be aggregated into a single category of '90 or older'
HIPAA allows ages over 89 to be aggregated into a category of '90 or older' rather than being completely removed, preserving some demographic information.
What does the term 're-identification' mean in the context of HIPAA de-identification?
Answer: The process of linking de-identified information back to the specific individual it pertains to
Re-identification is the process of combining de-identified data with other available information to link the data back to specific individuals, defeating the purpose of de-identification.
Under HIPAA, can a covered entity re-identify de-identified information that it originally de-identified?
Answer: Yes, covered entities may re-identify data they originally de-identified if they have a code key, subject to privacy rule restrictions
HIPAA allows covered entities to maintain a code system to re-identify de-identified data, provided the code cannot be used to identify individuals independently and access is restricted.
A research team wants to use patient data that retains some identifiers but has most removed. Under HIPAA, what is this arrangement called?
Answer: A limited data set
A HIPAA Limited Data Set is a partial de-identification approach retaining certain identifiers (geographic data, dates) for research/public health purposes, governed by a Data Use Agreement.
Under HIPAA, what document must be executed before a covered entity can share a Limited Data Set?
Answer: A Data Use Agreement (DUA)
Limited Data Sets can only be shared under a Data Use Agreement that restricts the recipient's use of the data and prohibits re-identification.
Which of the following is NOT one of the 18 Safe Harbor identifiers that must be removed under HIPAA de-identification?
Answer: ICD-10 diagnosis codes
ICD-10 diagnosis codes are clinical codes that do not themselves identify individuals and are not among the 18 Safe Harbor identifiers that must be removed.
A data analytics company receives de-identified health data from a hospital. Under HIPAA, what restrictions apply to this recipient?
Answer: If the data was provided as a limited data set, the recipient is bound by a DUA; if fully de-identified via Safe Harbor or Expert Determination, no HIPAA restrictions apply
Properly de-identified data (Safe Harbor or Expert Determination) is not PHI and HIPAA does not restrict its use; Limited Data Sets require a DUA but do not make recipients business associates.
Under HIPAA's Safe Harbor method, what must happen with web URLs associated with patients?
Answer: All web URLs that could be used to identify an individual must be removed
Web Uniform Resource Locators (URLs) are included in the 18 Safe Harbor identifiers and must be removed because they can link back to identifying information about individuals.
Why are biometric identifiers listed as Safe Harbor identifiers requiring removal under HIPAA de-identification?
Answer: Because biometric identifiers like fingerprints and retinal scans are unique to individuals and can definitively identify them
Biometric identifiers are the ultimate unique identifiers — fingerprints, retinal scans, and voice prints are biologically unique to each individual and can definitively link data to a specific person.
Under HIPAA, what is the primary risk of using 'quasi-identifiers' in a dataset claimed to be de-identified?
Answer: Multiple quasi-identifiers combined can uniquely identify individuals even when no direct identifiers are present
Quasi-identifiers (age, ZIP code, gender, dates) can be combined to uniquely identify individuals through linkage attacks, making data that appears de-identified actually re-identifiable.
A covered entity's dataset contains dates of service but not patient names or identifiers. Under HIPAA Safe Harbor, what must be done with these dates?
Answer: All dates related to an individual must be removed except year, including service dates, admission dates, and discharge dates
Safe Harbor requires removal of all dates (except year) directly related to an individual, including dates of service, admission, discharge, and procedures.
Under HIPAA, which method of de-identification is generally considered more flexible but requires more expertise to implement properly?
Answer: Expert Determination method, because it allows retention of more data elements through statistical risk assessment
Expert Determination is more flexible as it uses statistical risk analysis to justify retaining data elements that Safe Harbor would require removing, but requires qualified expert analysis.
What is the 'Cell Size Suppression' technique used in healthcare data de-identification?
Answer: Suppressing data cells where the count is so small that individuals could be identified (typically fewer than 5)
Cell size suppression removes or masks data cells where counts are too small to prevent identification of individuals in small groups, commonly suppressing cells with fewer than 5 individuals.
Under HIPAA, may a covered entity share properly de-identified health data with a competitor for research purposes without a BAA?
Answer: Yes, properly de-identified data is not PHI and HIPAA does not restrict its sharing or use, including with competitors
Properly de-identified data is not PHI and HIPAA imposes no restrictions on its sharing — though other legal considerations (trade secrets, state law, contract terms) may apply.
What is 'k-anonymity' in the context of healthcare data de-identification?
Answer: A technique ensuring each individual's record cannot be distinguished from at least k-1 other individuals in a dataset
k-anonymity is a privacy model ensuring that each record in a dataset is indistinguishable from at least k-1 other records based on quasi-identifiers, reducing re-identification risk.
Under HIPAA, what does 'actual knowledge' mean in the context of the Safe Harbor de-identification method?
Answer: The covered entity must have no actual knowledge that the information, in combination with other information, could be used to identify an individual
Safe Harbor requires not only removal of 18 identifiers but also that the organization has no 'actual knowledge' that remaining information could re-identify individuals.