Examples
Worked examples
- Is an instance
A dataset stripped of all 18 Safe Harbor identifiers (names, dates other than year, geographic detail smaller than state, contact and account numbers, biometric and image identifiers) and released with no restriction because it falls outside HIPAA's scope entirely.
Counter-examples
Looks similar, but isn't
- Not an instance
A Limited Data Set retaining dates and state-level geography, disclosed under a signed Data Use Agreement without individual authorisation — not fully de-identified, and not the same instrument as a Safe Harbor or Expert Determination dataset.
Editorial commentary
Under the Privacy Rule, a covered entity may use or disclose protected health information (PHI) for research only with the individual's written HIPAA authorisation, under an IRB-granted waiver of authorisation, as a limited data set with a Data Use Agreement, after de-identification, for reviews preparatory to research, or for research on decedents' information. The eighteen identifier categories defining de-identification under the safe-harbour method are enumerated in §164.514(b)(2). Research authorisations are study-specific, must contain core elements and required statements, and remain valid until revoked.
The two de-identification methods, precisely
45 CFR §164.514(a)-(b) sets out two, and only two, ways to remove data from HIPAA’s scope entirely. Safe Harbor requires removing all 18 identifier categories enumerated at §164.514(b)(2)(i) — name; geographic subdivisions smaller than a state; all elements of dates (except year) directly related to an individual; telephone and fax numbers; email addresses; Social Security numbers; medical record numbers; health plan beneficiary numbers; account numbers; certificate/licence numbers; vehicle identifiers; device identifiers/serial numbers; URLs; IP addresses; biometric identifiers; full-face photographs and comparable images; and any other unique identifying number, characteristic, or code — combined with no actual knowledge that the remaining information could identify an individual. Expert Determination, the alternative under §164.514(b)(1), instead has a qualified statistician or other expert apply generally accepted statistical/scientific methods to conclude the re-identification risk is very small, and document that analysis — useful when Safe Harbor would strip data of scientific value the study needs to retain.
Limited Data Set, distinct from de-identified data
A Limited Data Set under §164.514(e) keeps some indirect identifiers (dates, larger geographic subdivisions) that a fully de-identified dataset would strip, and is disclosable for research without authorisation or a waiver — provided the recipient signs a Data Use Agreement restricting use, access, and re-disclosure, and prohibiting re-identification attempts. It is a middle option between full authorisation/waiver and full de-identification, not a synonym for either.
Related pages
See also HIPAA (general), HIPAA in clinical research, HIPAA accounting of disclosures, de-identification (general), and the Five Safes framework as a comparable, non-US model for the same underlying problem.
Who Owns This in a Research Administration Office
HIPAA compliance for research is rarely one person’s job. The institution’s HIPAA Privacy Officer owns the covered entity’s overall Privacy Rule compliance program and typically maintains the standard authorization and waiver-documentation templates a study will use. The IRB is the body that actually grants or denies a waiver or alteration of authorization under §164.512(i), applying its own separate waiver criteria (not the Common Rule’s consent-waiver criteria, even though the same board often reviews both for the same study). The sponsored programs or research contracts office is generally the one that executes the Data Use Agreement before a Limited Data Set leaves the institution, and confirms the DUA’s restrictions match what the IRB-approved protocol actually authorizes. Individual investigators are responsible for completing institutional HIPAA/human-subjects training and for not going beyond what the authorization, waiver, or DUA actually permits — a common gap is a researcher assuming a waiver for one specific use covers a later, related secondary use it was never written to include.
What a Reviewer or Auditor Checks
An institutional auditor or an HHS Office for Civil Rights reviewer working through a research file is not just checking that an authorization or waiver exists; they check specific, documented elements. For a signed authorization, that means the core elements and required statements at §164.508(c) are all present — a specific, not blanket, description of the PHI to be used; the purpose; an expiration date or event; and the individual’s right to revoke. For a waiver, the reviewer checks that the IRB’s own documentation addresses each of the §164.512(i)(2)(ii) waiver criteria (minimal privacy risk, adequate plan to protect and destroy identifiers, and that the research could not practicably be conducted without the waiver) rather than a one-line approval. For de-identification under Safe Harbor, the check is a documented list confirming all 18 identifier categories were actually removed, not just an assertion that the data is de-identified; for Expert Determination, the reviewer looks for the expert’s retained written analysis and methodology, not just their conclusion. For a Limited Data Set, the executed DUA itself — naming the permitted uses, prohibiting re-identification attempts, and specifying data destruction or return — is the artifact checked, not the underlying research protocol.
Checking this against the current guidance
Which of the two de-identification methods your institution should use, and who has to sign off, depends on whether the dataset needs to retain any indirect identifiers for the analysis. The answer depends on the specific facts of your award, agency, or institution, and the page above states the general rule.
It searches CASRAI’s indexed corpus of research-administration guidance and cites the passage behind each claim, so you can open the source and check it rather than take its word on it — and it says so when the corpus does not cover something instead of guessing. Two questions a day are free while you are signed out, no account and no card. Everything CASRAI publishes stays free to read.
Frequently asked questions
Do we need IRB approval before requesting a waiver of HIPAA authorization?
Yes. A waiver or alteration of authorization under §164.512(i) has to be granted by an IRB or a Privacy Board applying the specific waiver criteria in the Privacy Rule — it is a separate determination from, though often reviewed alongside, the IRB’s Common Rule approval of the study itself.
Is de-identified data under Safe Harbor still considered human subjects research?
Data that has been properly de-identified under Safe Harbor is no longer PHI, but that does not automatically mean using it falls outside the Common Rule’s definition of human subjects research — that is a separate determination the IRB makes based on whether the activity otherwise meets the regulatory definition. De-identification removes the HIPAA question; it does not by itself resolve the Common Rule question.
How long is a HIPAA research authorization valid?
For however long the authorization itself specifies — a fixed expiration date, or an expiration event (such as “end of the research study”) — since §164.508(c) requires the authorization to state one or the other. An authorization with no expiration date or event does not meet the Privacy Rule’s core-element requirements.
Who is responsible for accounting of disclosures when research is conducted under a waiver?
The covered entity making the disclosure is generally responsible for tracking it for accounting-of-disclosures purposes, since a waiver of authorization does not also waive the accounting requirement — see CASRAI’s HIPAA accounting of disclosures entry for what has to be tracked and for how long.
Can a Limited Data Set be shared with a foreign collaborator?
The Privacy Rule itself does not bar sharing a Limited Data Set internationally, but the Data Use Agreement still has to be executed and its restrictions (no re-identification, no further disclosure beyond what’s authorized) still have to be enforceable against the recipient — institutions frequently add extra review here because enforcing a US-style DUA against a foreign recipient raises practical questions a domestic DUA does not.
References
- HIPAA Privacy Rule, 45 CFR §164.500 et seq., and §164.514(a)-(b), (e) (eCFR).
- HHS Office for Civil Rights, Guidance on Research and HIPAA; HIPAA De-identification Guidance (Safe Harbor and Expert Determination).
Also known as
HIPAA · Privacy Rule · 45 CFR 164 Subpart E
Machine-readable encodings
Use in your systems
<role vocab="credit"
vocab-identifier="https://casrai.org/dictionary/"
vocab-term="HIPAA Privacy Rule"
vocab-term-identifier="https://casrai.org/dictionary/term/hipaa-privacy-rule" />{
"@context": "https://schema.org",
"@type": "DefinedTerm",
"@id": "https://casrai.org/dictionary/term/hipaa-privacy-rule",
"name": "HIPAA Privacy Rule",
"identifier": "https://casrai.org/dictionary/term/hipaa-privacy-rule",
"description": "The US federal regulation at 45 CFR Parts 160 and 164 Subparts A and E that establishes national standards for the protection of individually identifiable health information held or transmitted by covered entities and their business associates, requiring authorisation, a waiver, or another permitted basis for any use or disclosure for research.",
"inDefinedTermSet": "https://casrai.org/dictionary/domain/compliance-regulatory#set",
"url": "https://casrai.org/dictionary/term/hipaa-privacy-rule",
"alternateName": [
"HIPAA",
"Privacy Rule",
"45 CFR 164 Subpart E"
],
"license": "https://creativecommons.org/licenses/by/4.0/",
"publisher": {
"@id": "https://casrai.org/#organization"
},
"author": {
"@id": "https://casrai.org/#editorial-team"
},
"datePublished": "2026-05-21T02:22:53",
"dateModified": "2026-09-06T19:58:52",
"inLanguage": "en-GB",
"isAccessibleForFree": true
}







