De-identification and Data Anonymization Flashcards
7 cards from real HIPAA practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 De-identification and Data Anonymization flashcards as text
A researcher publishes a study using de-identified HIPAA data. Later, a third party uses publicly available voter registration records to re-identify individuals in the dataset. Who bears HIPAA liability?
Answer: The covered entity that originally de-identified the data bears liability if de-identification was improper
If the covered entity's de-identification did not meet HIPAA standards (e.g., Expert Determination or Safe Harbor), they may bear liability; proper de-identification shifts risk but not automatically.
What does 'pseudonymization' mean in the context of HIPAA compliance?
Answer: Replacing direct identifiers with artificial codes while retaining the ability to re-identify through a separate key
Pseudonymization replaces identifiers with codes, but because re-identification is possible with the code key, pseudonymized data is still considered PHI under HIPAA.
Which entity is authorized to receive data under a HIPAA data use agreement for a limited data set?
Answer: Researchers, public health authorities, or health care operations entities who agree to specific use restrictions
Limited data sets may be disclosed for research, public health, or health care operations purposes to recipients who sign a data use agreement specifying permitted uses and safeguards.
Under the Safe Harbor method, which type of account number must be removed to achieve de-identification?
Answer: Health plan beneficiary numbers and account numbers
Health plan beneficiary numbers and account numbers are among the 18 Safe Harbor identifiers that must be removed because they can directly link records to specific individuals.
A data analytics firm receives de-identified patient data and later acquires a consumer database that allows them to re-identify the patients. What is this called?
Answer: A data linkage attack or re-identification attack
Combining de-identified health data with external datasets to re-identify individuals is called a re-identification or data linkage attack, and is a primary concern in modern de-identification.
When applying Safe Harbor de-identification, what must happen to telephone and fax numbers?
Answer: They must be removed entirely
All telephone numbers and fax numbers are among the 18 Safe Harbor identifiers and must be completely removed from de-identified datasets.
Which approach best describes k-anonymity as used in health data de-identification?
Answer: Ensuring each record in a dataset is indistinguishable from at least k-1 other records based on quasi-identifiers
K-anonymity ensures that any individual's record matches at least k-1 other records on quasi-identifiers (like age and ZIP code), making it harder to single out a specific person.