Skip to main content
v2026.11,610 entries · CC-BY 4.0
LAC HealthLaboratory & ResearchLab & research supplies.Reagents, consumables, PPE & instruments — documented, fast, chain-of-custody shipping.Shop lac.us lac.us
Dictionary termTrack DProposedv2026.1

Limited Data Set (HIPAA)

A dataset qualifies as a HIPAA limited data set under 45 CFR 164.514(e) when a covered entity removes the 16 direct identifiers enumerated at 164.514(e)(2) (names, contact details, medical record/account/certificate numbers, device and biometric identifiers, full-face photos, and similar) while retaining permitted indirect identifiers -- full dates and geographic subdivisions down to town, city, state, and zip code -- and discloses the resulting dataset only for research, public health, or health care operations to a recipient who has signed a Data Use Agreement restricting its use, access, safeguarding, and redisclosure, and prohibiting re-identification attempts. It remains protected health information (PHI) and stays subject to the Privacy Rule, unlike data that has been fully de-identified under 164.514(a)-(b).

ByCASRAI Editorial Board
· Last updated 30 Jul 2026

Examples

Worked examples

  • Is an instance

    A hospital cancer registry removes all 16 required direct identifiers but keeps admission/discharge dates and county of residence, then discloses the dataset to a university research team under a signed Data Use Agreement limiting use to an approved research protocol -- a valid limited-data-set disclosure requiring no individual authorization or IRB waiver of authorization under HIPAA.

  • Is an instance

    A state health department receives a limited data set with full dates and zip codes from a regional health system, under a DUA, to track disease incidence over time and by geographic area -- permitted because public health is one of the three purposes 164.514(e)(3) allows for this pathway.

Counter-examples

Looks similar, but isn't

  • Not an instance

    A researcher receives a dataset with all dates generalized to year only, no geographic detail below the state level, and all 18 Safe Harbor identifier categories removed. This is Safe Harbor de-identified data under 164.514(b), not a limited data set -- it is no longer PHI, falls outside the Privacy Rule entirely, and requires no Data Use Agreement.

Editorial commentary

A limited data set is a HIPAA-regulated category of protected health information, defined at 45 CFR §164.514(e), that has had all 16 direct identifiers removed but retains dates and geographic detail such as city, state, and zip code. A covered entity may disclose it without the individual’s authorization or an IRB/Privacy Board waiver, but only for research, public health, or health care operations, and only to a recipient who has signed a Data Use Agreement (DUA) restricting its use, access, and redisclosure. It is still PHI — not de-identified data — and remains subject to the Privacy Rule.

What makes a dataset a “limited data set”

Section 164.514(e)(2) requires that a limited data set exclude the following direct identifiers of the individual, and of the individual’s relatives, employers, or household members:

  • Names
  • Postal address information, other than town or city, state, and zip code
  • Telephone numbers
  • Fax numbers
  • Electronic mail addresses
  • Social Security numbers
  • Medical record numbers
  • Health plan beneficiary numbers
  • Account numbers
  • Certificate/license numbers
  • Vehicle identifiers and serial numbers, including license plate numbers
  • Device identifiers and serial numbers
  • Web URLs
  • Internet Protocol (IP) address numbers
  • Biometric identifiers, including finger and voice prints
  • Full-face photographic images and any comparable images

Everything not on that list may be retained. In practice, that means a limited data set can still include all elements of dates directly related to an individual (birth date, admission date, discharge date, date of death, date of service) and geographic subdivisions larger than a street address — town or city, county, state, and zip code. That is the entire point of the category: dates and coarse geography are frequently essential to the research or public-health question being asked (calculating length of stay, tracking disease clusters by county, following a cohort over calendar time), and Safe Harbor de-identification would strip all of it.

Limited data set vs. full de-identification

A limited data set is frequently confused with fully de-identified data, but the two sit on opposite sides of a hard regulatory line. Full de-identification under 45 CFR §164.514(a)–(b) — via either the Safe Harbor method (removing all 18 enumerated identifier categories) or Expert Determination (a qualified statistician certifying a very small re-identification risk) — removes data from HIPAA’s scope entirely. Once data is de-identified under those provisions, it is no longer PHI, the Privacy Rule no longer applies to it, and no Data Use Agreement is required to use or share it. See CASRAI’s De-identification entry for the mechanics of both methods.

A limited data set does none of that. It is an intermediate category created specifically at 164.514(e) as a middle ground: fewer identifiers than a fully identified record, but still PHI, still governed by the Privacy Rule, and disclosable only under the conditions in 164.514(e) — permitted purpose, signed DUA, and the removal of the 16 direct identifiers listed above. An institution cannot treat a limited data set as equivalent to de-identified data for any other purpose (public release, unrestricted secondary use, posting to an open repository); the DUA’s restrictions travel with the data for as long as the recipient holds it.

Permitted purposes and the Data Use Agreement

Under 164.514(e)(3), a covered entity may use or disclose a limited data set only for research, public health, or health care operations — no other purpose is permitted under this pathway. Before disclosing, the covered entity must obtain a Data Use Agreement from the intended recipient. Under 164.514(e)(4), that agreement must:

  • Establish the permitted uses and disclosures of the limited data set by the recipient, consistent with the research/public health/health care operations purposes above (and never for a purpose that would have required authorization for identifiable PHI);
  • Identify who is permitted to use or receive the limited data set; and
  • Require the recipient to: not use or further disclose the information other than as permitted by the agreement or by law; use appropriate safeguards to prevent unauthorized use or disclosure; report to the covered entity any unauthorized use or disclosure it becomes aware of; bind any agents or subcontractors to the same restrictions; and not attempt to re-identify the information or contact the individuals it describes.

Because a limited data set disclosure is made under a DUA rather than an authorization, it also falls outside the HIPAA accounting-of-disclosures requirement — 164.528(a)(1) exempts limited-data-set disclosures made under 164.514(e) from the six-year disclosure log a covered entity otherwise has to maintain for many other non-routine disclosures. See CASRAI’s HIPAA Accounting of Disclosures entry.

Where this fits alongside the Common Rule and IRB review

The limited-data-set pathway is a HIPAA Privacy Rule mechanism; it does not, by itself, resolve whether a study also needs IRB review under the Common Rule (45 CFR 46) or whether the recipient’s use of the data counts as human subjects research. HIPAA and the Common Rule are separate, independently-triggered legal regimes that commonly apply to the same study, with separate waiver criteria (164.512(i) for a HIPAA authorization waiver, 46.116(f) for Common Rule informed-consent waiver). A researcher receiving a limited data set under a DUA should confirm separately with their institution’s IRB or research-compliance office whether the study itself qualifies as human subjects research and, if so, what level of IRB review applies — retaining dates and county-level geography, while permitted under 164.514(e), can still leave a dataset identifiable enough in context to raise that question. See CASRAI’s Common Rule (45 CFR 46) and HIPAA in Clinical Research entries.

Worked examples

Multi-site outcomes research. A hospital’s cancer registry wants to share patient records with a university research team for a multi-site outcomes study. The registry removes all 16 direct identifiers required under 164.514(e)(2) — names, contact details, medical record numbers, and so on — but retains full admission and discharge dates and county of residence, both needed for the analysis. Before disclosure, the university signs a Data Use Agreement limiting use of the data to the approved research protocol, prohibiting re-identification attempts, and requiring appropriate safeguards. Because the disclosure is for research, under a signed DUA, with the required identifiers removed, it is a valid limited-data-set disclosure and needs no individual authorization or IRB waiver of authorization under HIPAA.

Public health surveillance. A state health department requests a limited data set from a regional health system to track disease incidence by zip code and month over several years. Because zip code and full dates are both permitted retained fields under 164.514(e)(2), and public health is an enumerated permitted purpose under 164.514(e)(3), the health system may disclose the data once the department signs the required DUA.

Counter-example

A researcher receives a dataset in which every date has been generalized to year only, all geographic detail below the state level has been removed, and all 18 Safe Harbor identifier categories — not just the 16 required for a limited data set — have been stripped. This is Safe Harbor de-identified data under 164.514(b), not a limited data set: it is no longer PHI at all, so it falls outside the Privacy Rule entirely and requires no Data Use Agreement.

Frequently asked questions

Does a limited data set need IRB approval?

Not under HIPAA itself — a limited-data-set disclosure under a signed DUA is a HIPAA-permitted pathway that doesn’t require an authorization or an IRB/Privacy Board waiver. Whether the recipient’s use of the data separately requires Common Rule IRB review is a distinct question the institution must evaluate on its own, since dates and coarse geography can still make a dataset identifiable in context.

Is a limited data set the same as de-identified data?

No. A limited data set is still PHI and remains subject to the Privacy Rule; fully de-identified data under Safe Harbor or Expert Determination (164.514(a)–(b)) is no longer PHI at all. See CASRAI’s De-identification entry.

What can a limited data set be used for?

Only research, public health, or health care operations — 164.514(e)(3) does not permit any other purpose under this pathway.

Does disclosing a limited data set require logging it in an accounting of disclosures?

No. 164.528(a)(1) exempts limited-data-set disclosures made under a DUA from the accounting-of-disclosures requirement.

Related CASRAI resources

References

  • 45 CFR §164.514(e) — Other requirements relating to uses and disclosures of protected health information: Limited data set
  • 45 CFR §164.514(a)–(b) — De-identification of protected health information
  • 45 CFR §164.528(a)(1) — Accounting of disclosures: exempt categories
  • 45 CFR §164.512(i) — Uses and disclosures for research purposes
  • HHS Office for Civil Rights, “Limited Data Set” guidance (hhs.gov/hipaa)

Machine-readable encodings

Use in your systems

JATS XML <role> element
xml
<role vocab="credit"
      vocab-identifier="https://casrai.org/dictionary/"
      vocab-term="Limited Data Set (HIPAA)"
      vocab-term-identifier="https://casrai.org/dictionary/term/limited-data-set" />
Schema.org DefinedTerm (JSON-LD)
json
{
  "@context": "https://schema.org",
  "@type": "DefinedTerm",
  "@id": "https://casrai.org/dictionary/term/limited-data-set",
  "name": "Limited Data Set (HIPAA)",
  "identifier": "https://casrai.org/dictionary/term/limited-data-set",
  "description": "A dataset qualifies as a HIPAA limited data set under 45 CFR 164.514(e) when a covered entity removes the 16 direct identifiers enumerated at 164.514(e)(2) (names, contact details, medical record/account/certificate numbers, device and biometric identifiers, full-face photos, and similar) while retaining permitted indirect identifiers -- full dates and geographic subdivisions down to town, city, state, and zip code -- and discloses the resulting dataset only for research, public health, or health care operations to a recipient who has signed a Data Use Agreement restricting its use, access, safeguarding, and redisclosure, and prohibiting re-identification attempts. It remains protected health information (PHI) and stays subject to the Privacy Rule, unlike data that has been fully de-identified under 164.514(a)-(b).",
  "inDefinedTermSet": "https://casrai.org/dictionary/domain/compliance-regulatory#set",
  "url": "https://casrai.org/dictionary/term/limited-data-set",
  "sameAs": [],
  "license": "https://creativecommons.org/licenses/by/4.0/",
  "publisher": {
    "@id": "https://casrai.org/#organization"
  },
  "dateModified": "2026-07-30T05:50:33",
  "inLanguage": "en"
}

Referenced across the research world

University of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logoUniversity of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logo
  • University of Cambridge logo
  • Columbia University logo
  • Crossref logo
  • University of Edinburgh logo
  • Harvard University logo
  • University of Oxford logo
  • Princeton University logo
  • Stanford School of Medicine logo
  • University College London logo
  • ORCID logo

View CASRAI adoption →