Bindinglaw

US · guidance

CMS Pub. 100-11, ch. 2, § 50.5

De-identified Health Information and Limited Data Set

activein force · 2026-08-25 – presentas-observed

If it is necessary to disclose PHI, there are two methods to accomplish the release of

information. The organization may de-identify the information. The de-identified

information is not PHI because it does not identify an individual and there is no

reasonable basis to believe that the information can be used to identify an individual. De-identified information, therefore, is outside the purview of the Health Insurance

Portability and Accountability Act of 1996 (HIPAA) privacy standards.

Under the HIPAA privacy requirements there are two ways to de-identify PHI:

• The organization may de-identify in accordance with “generally accepted

statistical and scientific principles and methods”; or

• The organization may remove all identifiers of an individual or of relatives,

employers or household members of the individual listed in the safe harbor

method in the regulation:

ο Names;

ο All geographic subdivisions smaller than a State;

ο All elements of dates (except year) for dates directly related to an individual,

including birth date, admission date, discharge date, date of death, and all ages

over 89 and all elements of dates (including year) indicative of such age,

except that such ages and elements may be aggregated into a single category

of age 90 or older;

ο Telephone numbers;

ο Fax numbers;

ο Electronic mail addresses;

ο Social security numbers;

ο Medical record numbers;

ο Health plan beneficiary numbers;

ο Account numbers;

ο Certificate/license numbers;

ο Vehicle identifiers and serial numbers, including license plate numbers;

ο Device identifiers and serial numbers;

ο Web URLs;

ο IP address numbers;

ο Biometric identifiers, including finger and voice prints;

ο Full face photographic images and any comparable images; and

ο Any other unique identifying number, characteristic, or code.

Additionally, the PACE organization does not have actual knowledge that the

information could be used alone or in combination with other information to identify an

individual who is the subject of the information.

The organization may assign a code or other means of record identification to allow

information de-identified to be re-identified.

The PACE organization should have the following HIPAA Compliance for Safeguarding

PHI:

• The organization has a contingency plan and disaster recovery plan for all PHI;

• The organization has security policy and procedures for data.

[45 CFR § 164.514(a) and (b)]

History

(Rev. 2, Issued: 06-09-11; Effective: 06-03-11; Implementation: 06-03-11)

Provenance

Source
cms.gov
Retrieved
2026-08-25
Edition
iom-2026-08-25
Content hash
054aa65c945f608f592c70fa2ad6a54ae4da0003542a132a68ef22bc5ab4046c
View the official source →

The link goes to the issuing authority’s own document — the one we read to produce this record. Where a source publishes whole titles rather than sections, your browser may need a moment to jump to the provision.

Unofficial copy of government-published law, reproduced from official sources with full provenance. Not an official publication; verify against official sources before relying on it in a filing. Records in the 'guidance' corpus, and only that corpus, are sub-regulatory (interpretive guidelines, survey procedures) and are not binding law. Validity bounds follow each jurisdiction's declared temporalBasis.

Coverage · API docs

Bindinglaw

Point-in-time US law with the receipt attached. Source URL, retrieval time, content hash, and validity dates on every answer.

curl api.binding.law/v1/law/coverage

© 2026 binding.law · a Jubal, Inc. productAttorneys and firms never pay. Ever.