US · guidance
CMS Pub. 100-11, ch. 2, § 50.5
De-identified Health Information and Limited Data Set
If it is necessary to disclose PHI, there are two methods to accomplish the release of
information. The organization may de-identify the information. The de-identified
information is not PHI because it does not identify an individual and there is no
reasonable basis to believe that the information can be used to identify an individual. De-identified information, therefore, is outside the purview of the Health Insurance
Portability and Accountability Act of 1996 (HIPAA) privacy standards.
Under the HIPAA privacy requirements there are two ways to de-identify PHI:
• The organization may de-identify in accordance with “generally accepted
statistical and scientific principles and methods”; or
• The organization may remove all identifiers of an individual or of relatives,
employers or household members of the individual listed in the safe harbor
method in the regulation:
ο Names;
ο All geographic subdivisions smaller than a State;
ο All elements of dates (except year) for dates directly related to an individual,
including birth date, admission date, discharge date, date of death, and all ages
over 89 and all elements of dates (including year) indicative of such age,
except that such ages and elements may be aggregated into a single category
of age 90 or older;
ο Telephone numbers;
ο Fax numbers;
ο Electronic mail addresses;
ο Social security numbers;
ο Medical record numbers;
ο Health plan beneficiary numbers;
ο Account numbers;
ο Certificate/license numbers;
ο Vehicle identifiers and serial numbers, including license plate numbers;
ο Device identifiers and serial numbers;
ο Web URLs;
ο IP address numbers;
ο Biometric identifiers, including finger and voice prints;
ο Full face photographic images and any comparable images; and
ο Any other unique identifying number, characteristic, or code.
Additionally, the PACE organization does not have actual knowledge that the
information could be used alone or in combination with other information to identify an
individual who is the subject of the information.
The organization may assign a code or other means of record identification to allow
information de-identified to be re-identified.
The PACE organization should have the following HIPAA Compliance for Safeguarding
PHI:
• The organization has a contingency plan and disaster recovery plan for all PHI;
• The organization has security policy and procedures for data.
[45 CFR § 164.514(a) and (b)]
History
(Rev. 2, Issued: 06-09-11; Effective: 06-03-11; Implementation: 06-03-11)
Provenance
- Source
- cms.gov
- Retrieved
- 2026-08-25
- Edition
- iom-2026-08-25
- Content hash
054aa65c945f608f592c70fa2ad6a54ae4da0003542a132a68ef22bc5ab4046c
The link goes to the issuing authority’s own document — the one we read to produce this record. Where a source publishes whole titles rather than sections, your browser may need a moment to jump to the provision.
Unofficial copy of government-published law, reproduced from official sources with full provenance. Not an official publication; verify against official sources before relying on it in a filing. Records in the 'guidance' corpus, and only that corpus, are sub-regulatory (interpretive guidelines, survey procedures) and are not binding law. Validity bounds follow each jurisdiction's declared temporalBasis.