Direct comparison
Limited Data Set vs. De-Identified Data
How a HIPAA Limited Data Set differs from fully de-identified data: which identifiers each retains, whether a DUA is required, and when to request which.
Written and maintained by CASRAI Editorial Board
Last updated
Ask CASRAI · free to try
Ask about Limited Data Set vs. De-Identified Data
Ask your first 2 questions free below. Subscribers get 150 a day for $29 a month.
An AI assistant specialized in research administration. It cites the sources behind every answer, labels web answers and says when it can't answer.
Answers draw on CASRAI's guides and dictionary plus the federal and funder documents we index: Federal Register, Grants.gov, Regulations.gov and UKRI.
Works on this site and inside Claude, Cursor and the AI tools you already use.
Everything CASRAI publishes — this page, the dictionary, the guides and the news — stays free to read, with no account and no card.
How do Limited Data Set, De-Identified Data compare side by side?
The table below compares Limited Data Set, De-Identified Data across 10 procurement-relevant dimensions, from governing regulation through typical research use case.
Side-by-side comparison
| Dimension | Limited Data Set | De-Identified Data |
|---|---|---|
| Governing regulation | 45 CFR 164.514(e) | 45 CFR 164.514(a)-(b) -- Safe Harbor at 164.514(b)(2), or Expert Determination at 164.514(b)(1) |
| Legal status under HIPAA | Still protected health information (PHI) -- a reduced-identifiability subset of PHI, not exempt from the Privacy Rule | No longer PHI -- falls entirely outside the Privacy Rule's scope once properly de-identified |
| Identifiers removed | 16 direct identifiers per 164.514(e)(2): names, postal address other than town/city/state/ZIP, phone, fax, email, SSN, medical record numbers, health plan beneficiary numbers, account numbers, certificate/license numbers, vehicle and device identifiers/serial numbers, URLs, IP addresses, biometric identifiers, full-face photographs | All 18 Safe Harbor categories at 164.514(b)(2) -- the 16 above, plus all elements of dates and any other unique identifying number, characteristic, or code -- or a documented expert determination that re-identification risk is very small |
| Identifiers retained | All elements of dates (birth date, admission, discharge, death, etc.) and geographic subdivisions down to town, city, state, and five-digit ZIP code | Under Safe Harbor: only year (no month or day), and geography no smaller than state, with a narrow three-digit ZIP exception for large population areas. Expert Determination may retain more detail if the expert's documented analysis supports a very low re-identification risk |
| How it's produced | Direct-identifier stripping limited to the (e)(2) list -- a defined, fixed checklist | Either the fixed Safe Harbor checklist (all 18 categories removed, no actual knowledge the remainder could identify someone), or a qualified expert applying generally accepted statistical and scientific methods, with the analysis documented |
| Contract required to share it | Yes -- a Data Use Agreement (DUA) under 164.514(e)(4) must be in place with the recipient before disclosure | No -- because it is no longer PHI, HIPAA does not require authorization, a DUA, or an IRB/Privacy Board waiver to share it |
| Permitted uses under HIPAA | Research, public health, or health care operations only, per 164.514(e)(3) | No HIPAA-specific use restriction -- once de-identified, the data can be used or shared for any purpose as far as the Privacy Rule is concerned |
| Accounting of disclosures | Exempt from the 164.528(a)(1) accounting-of-disclosures requirement, but the DUA remains a required governance record | Not applicable -- accounting of disclosures only governs PHI |
| Relative re-identification risk | Higher than de-identified data -- retained dates and small-area geography make re-identification more feasible, which is why the DUA's access restrictions, safeguards, and no-re-identification clause do the remaining protective work | Designed to be very low, either by the fixed Safe Harbor checklist or a documented statistical determination |
| Typical research use case | Multi-site registries, longitudinal or time-series studies that need exact dates or fine-grained geography, shared with a known, accountable recipient under a controlled DUA | Public or broadly shared secondary-analysis datasets where the recipient and downstream use can't be tracked or restricted |
Common questions
Common questions about Limited Data Set vs De-Identified Data
Is a Limited Data Set the same as de-identified data?
+
No. A Limited Data Set is still PHI under HIPAA -- it retains dates and detailed geographic information that Safe Harbor de-identification (45 CFR 164.514(b)(2)) requires removing. It carries a narrower set of protections instead: a signed Data Use Agreement and restricted permitted purposes, rather than falling outside the Privacy Rule entirely.
Do I need a Data Use Agreement for de-identified data?
+
No. A DUA is a 164.514(e)(4) requirement specific to Limited Data Sets. Data that has been properly de-identified under Safe Harbor or Expert Determination is no longer PHI, so HIPAA does not require a DUA, authorization, or an IRB/Privacy Board waiver to disclose it.
Which one should I request for my study?
+
It depends on what your analysis needs. If you need exact dates or fine geographic detail -- common in longitudinal or geospatial research -- you will likely need a Limited Data Set under a DUA. If your analysis doesn't depend on those fields, request de-identified data instead, since it comes without a DUA, authorization, or HIPAA use restriction.
Can de-identified data be re-identified later?
+
Attempting to re-identify data de-identified under Safe Harbor or Expert Determination, or using a code or key that could link it back to identifiers, takes it back into PHI status under HIPAA. A Limited Data Set is a different concept -- it is deliberately never fully de-identified in the first place, which is exactly why it still requires a DUA.
Going deeper








