โ† All HIPAA Flashcard Decks

De-identification and Data Anonymization Flashcards

7 cards from real HIPAA practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 De-identification and Data Anonymization flashcards as text
  1. A covered entity removes all 18 Safe Harbor identifiers but retains free-text clinical notes. Is the resulting data de-identified under HIPAA?

    Answer: No, because free-text notes may contain incidental identifiers and the entity must verify no such information remains

    Safe Harbor also requires that the covered entity have no actual knowledge that the remaining information could identify an individual, which unredacted free-text notes often violate.

  2. What is 'differential privacy' and how does it relate to HIPAA de-identification?

    Answer: A mathematical technique that adds calibrated noise to query results to protect individual privacy while enabling statistical analysis

    Differential privacy adds mathematically calibrated noise to data outputs so that the presence or absence of any single individual cannot be detected, providing strong privacy guarantees beyond traditional de-identification.

  3. Under HIPAA, which of the following correctly describes when de-identified data is no longer subject to the Privacy Rule?

    Answer: When either Safe Harbor or Expert Determination de-identification is properly applied and no actual knowledge of re-identification exists

    HIPAA's Privacy Rule ceases to apply once information is de-identified using Safe Harbor or Expert Determination and the covered entity has no actual knowledge that the information could re-identify individuals.

  4. A hospital's de-identification policy strips birth years from all records. Under Safe Harbor, is this required for patients under age 90?

    Answer: No, only the full date of birth must be removed; the year of birth may be retained for patients under 90

    Safe Harbor requires removal of the full date of birth (month, day, and year) but permits retention of the year of birth for patients aged 89 or younger.

  5. Which characteristic makes a data element a 'quasi-identifier' in health data de-identification?

    Answer: It is an attribute that, alone or combined with others, can narrow down records to a specific individual

    Quasi-identifiers are attributes such as age, gender, and ZIP code that are not direct identifiers but can be combined with external data to re-identify individuals.

  6. A public health agency requests a dataset with patient ZIP codes, admission dates, and diagnoses to track disease outbreaks. All 18 Safe Harbor identifiers have been removed. Is this permissible?

    Answer: The covered entity must confirm no actual knowledge of re-identification; in small populations, residual risk may still exist

    Even after Safe Harbor removal, the covered entity must ensure no actual knowledge of re-identification; small geographic areas or rare diagnoses can create residual risk requiring further action.

  7. What is 'data masking' in the context of HIPAA de-identification?

    Answer: Replacing sensitive data values with realistic but fictitious substitutes to preserve data format and utility

    Data masking substitutes real PHI values with realistic fictional values (e.g., replacing a real name with a fake name) to maintain data structure and utility while eliminating actual identifiers.

De-identification and Data Anonymization Flashcards โ€” HIPAA Study Cards with Answers