HIPAA Safe Harbor: the 18 identifiers to remove from a medical document
The HIPAA Safe Harbor method names 18 identifiers to strip from a health record. See the full list, the ZIP and date rules, and where GDPR diverges.
The HIPAA Safe Harbor method spells out exactly what to strip from a health record: 18 named identifiers, listed at 45 CFR 164.514(b)(2). Remove all 18, and the record counts as de-identified under one of the two paths federal law allows. The other path is called Expert Determination.
Take Jane Example, a records clerk at a teaching hospital. A university asks for de-identified discharge summaries to teach a class on sepsis care. She cannot send the originals. She needs to know which fields she must strip, and which ones the rule still lets her keep, such as the year of a procedure.
What are the two ways to de-identify PHI under HIPAA?
Section 164.514(b) of the HIPAA Privacy Rule sets two paths. Expert Determination asks a person with recognized statistical and scientific training to conclude the re-identification risk is very small, and to document that analysis in writing. It suits research datasets that need exact dates or a fine-grained location.
Safe Harbor works differently. Remove the 18 listed identifier types, confirm the covered entity has no actual knowledge that what remains could still identify someone, and the job is done. No statistician, no risk score, no paperwork. That is why it is the faster path to a de-identified record.
Which 18 identifiers does the Safe Harbor method list?
Here is the condensed list. Two entries, ZIP codes and dates, carry their own numeric thresholds, explained in the rows below.
| Identifier | What the rule asks for |
|---|---|
| Names | Removed in full, including nicknames and initials that could point to one person |
| Geographic detail smaller than a state | Street, county, precinct and city removed; only the state may stay |
| ZIP code | First three digits only, and only where that area holds more than 20,000 people; otherwise it becomes 000 |
| Dates tied to a person, except the year | Birth, admission and discharge dates keep the year and drop the day and month |
| Age over 89 | Grouped as 90 or older, along with any date detail that would reveal the exact age |
| Phone, fax and email | All three removed, including a personal mobile number written into a referral letter |
| Social Security number | Removed in full, wherever it appears |
| Medical record and health plan numbers | Any internal patient ID, insurance member number or claim number |
| Account, certificate and license numbers | Bank accounts, professional licenses, certificate numbers |
| Vehicle and device identifiers | License plates and serial numbers, such as an insulin pump's serial number |
| Web and IP addresses | Any URL or IP number that could trace back to the person |
| Biometric identifiers and full-face photos | Fingerprints, voiceprints, and any photo that shows the face |
| Any other unique code | A catch-all: a study ID, a badge number, anything else that singles someone out |
The ZIP and age thresholds exist because a rare combination can point to one person even without a name. A three-digit ZIP shared by more than 20,000 people keeps a patient inside a crowd large enough to stay unnamed.
What does the actual knowledge condition mean?
Safe Harbor carries a second requirement, easy to miss. The covered entity must not have actual knowledge that the leftover information, alone or combined with other data, could still identify the patient. Stripping the 18 fields is not enough once you know better.
Where do these identifiers hide in a scanned lab report or discharge summary?
A scan carries more identifiers than the body text suggests. The letterhead usually shows a clinic phone and fax number. A running footer often repeats the patient's name on every page. A barcode near the top usually encodes the medical record number.
- A date stamp reading 'received' or 'faxed on', often paired with a phone number
- A referring physician's signature block, with a direct line and an email address
- A patient label pasted onto a lab report, sometimes covering part of the printed text
- Handwritten notes in a margin, which optical character recognition may not even read
A tool can carry some of this work. ONYRI Sanitize runs in the browser and detects several Safe Harbor identifiers in a PDF or a scan: names, phone numbers, emails, postal addresses, dates and US Social Security numbers. It misses some of the 18: faces (mask them by hand with the “Draw an area” tool), device identifiers, medical record numbers without a custom rule. Detection helps. It does not make a document Safe Harbor compliant.
Why doesn't HIPAA de-identification equal GDPR anonymisation?
HIPAA gives a fixed list. Remove these 18 fields, and the record counts as de-identified, unless you have actual knowledge otherwise. The GDPR gives no list at all. It asks whether a person stays identifiable by any means reasonably likely to be used, a standard that shifts as re-identification techniques improve.
The principles of data protection should therefore not apply to anonymous information, namely information which does not relate to an identified or identifiable natural person or to personal data rendered anonymous in such a manner that the data subject is not or no longer identifiable. (Recital 26, GDPR)
| Test | HIPAA Safe Harbor | GDPR anonymisation |
|---|---|---|
| Method | Remove 18 named fields | Case-by-case risk assessment |
| Who sets the standard | U.S. Department of Health and Human Services | The European Data Protection Board and national authorities |
| Result if done correctly | De-identified health information, outside the Privacy Rule | Anonymous information, outside the GDPR entirely |
A file that clears Safe Harbor in the United States can still count as personal data under the GDPR the moment it reaches the EU. Treat the two as separate tests. Run the one that matches where the document is actually going.
Frequently asked questions
- Does the Safe Harbor method guarantee a record cannot be re-identified?
- No. It guarantees the 18 listed fields are gone. The actual knowledge condition still applies: if the covered entity knows the leftover information could point to one person, removal alone does not satisfy the rule. Context, not just fields, can still identify someone.
- Can I keep any part of a patient's ZIP code?
- Only the first three digits, and only if the area sharing those three digits holds more than 20,000 people. A large metro area usually clears that bar. A rural clinic's three-digit prefix often does not, so it becomes 000.
- Is Expert Determination required, or can every hospital use Safe Harbor?
- Safe Harbor is open to any covered entity. Expert Determination becomes useful when the mechanical removal would ruin the data, for instance a study that needs exact admission dates. A qualified statistician then documents why the residual risk stays very small.
- If a record meets HIPAA Safe Harbor, is it automatically anonymous under the GDPR?
- No. The GDPR does not recognize Safe Harbor. It asks a separate question: could any means reasonably likely to be used still identify the person? A record can pass Safe Harbor in the US and still count as personal data once it reaches the EU.
Sources & references
- 45 CFR 164.514 — Other requirements relating to uses and disclosures of protected health information — Cornell Law School, Legal Information Institute
- Appendix B: The HIPAA De-Identification Standard — California Health and Human Services Open Data
- Recital 26 — Regulation (EU) 2016/679 (GDPR) — GDPR-info.eu (consolidated regulation text)
- L'anonymisation de données personnelles — CNIL
Mask a document without uploading it
ONYRI Sanitize finds names, identifiers, bank details and secrets in a PDF, a Word file or a scan, and masks them in your browser. You check the preview, then download a flattened copy.