Skip to main content
v2026.11,610 entries · CC-BY 4.0
LAC HealthLaboratory & ResearchLab & research supplies.Reagents, consumables, PPE & instruments — documented, fast, chain-of-custody shipping.Shop lac.us lac.us
Dictionary termTrack DProposedv2026.1

PHI Exemptions From the HIPAA Privacy Rule

PHI is exempt from the HIPAA Privacy Rule only when it meets one of three conditions: (1) it has been de-identified under the Safe Harbor or Expert Determination method (45 CFR 164.514), (2) it is held by a person or organization that is not a HIPAA covered entity or business associate, or (3) it is a deceased individual's information more than 50 years after death (45 CFR 164.502(f)). PHI that is disclosed for research without individual authorization under a waiver, a review preparatory to research, the decedent-research pathway, or as a Limited Data Set (all under 45 CFR 164.512(i) or 164.514(e)) remains PHI and remains subject to the Privacy Rule -- it is not exempt, merely disclosable through a permitted exception.

ByCASRAI Editorial Board
· Last updated 23 Jul 2026

Examples

Worked examples

  • Is an instance

    A dataset stripped of all 18 Safe Harbor identifiers (45 CFR 164.514(b)(2)), with documented no-actual-knowledge of re-identification risk, is no longer PHI.

  • Is an instance

    Identifiable health information collected directly by a researcher who is not a HIPAA covered entity or business associate is generally not PHI under HIPAA, even though it is sensitive.

  • Is an instance

    A deceased individual's health information, more than 50 years after death, is no longer protected as PHI under 45 CFR 164.502(f).

Counter-examples

Looks similar, but isn't

  • Not an instance

    An extract with only direct identifiers (name, MRN) removed, but retaining indirect identifiers that could reasonably re-identify someone, has not met the Safe Harbor standard and remains PHI -- it is not exempt just because it looks de-identified.

  • Not an instance

    PHI disclosed under an IRB waiver of authorization, a review preparatory to research, or as a Limited Data Set remains PHI subject to the Privacy Rule -- these are permitted-disclosure exceptions, not exemptions.

Editorial commentary

Protected health information (PHI) is “exempt” from HIPAA’s Privacy Rule in only a narrow set of circumstances — and it is easy to conflate that with a much broader category: PHI that is still covered by the Privacy Rule but that a covered entity may lawfully disclose without the individual’s authorization under a research exception. These are not the same thing, and mixing them up leads research administrators to either over-restrict data that HIPAA never touched, or to under-document a disclosure that HIPAA still requires be tracked and, in some cases, accounted for.

Two different questions

“Is this information exempt from the Privacy Rule?” and “Can this PHI be disclosed for research without an authorization?” sound similar but have different legal consequences. If information is genuinely exempt, HIPAA’s rules on minimum necessary, accounting of disclosures, and breach notification simply do not apply to it — because it is not PHI. If information is still PHI but disclosure is permitted under a research exception (a waiver, a limited data set, a review preparatory to research), the Privacy Rule still governs it; the covered entity has just been given a lawful path to disclose it without asking the individual first, and other Privacy Rule obligations (documentation, data use agreements, accounting) typically still apply.

Route 1 — genuinely exempt (not PHI at all)

De-identified information

Information that meets the Safe Harbor method (removal of all 18 identifier categories at 45 CFR 164.514(b)(2), with no actual knowledge that the remainder could identify the individual) or the Expert Determination method (45 CFR 164.514(b)(1)) is, by regulatory definition, no longer PHI. See De-identification for the mechanics of both methods.

Information never held by a covered entity or business associate

PHI is defined by who holds it, not just what it says. Identifiable health information collected or held by a person or organization that is not a HIPAA “covered entity” (a health plan, health care clearinghouse, or health care provider that transmits standard electronic transactions) or a “business associate” acting on a covered entity’s behalf is generally not PHI under HIPAA at all — even though it may be highly sensitive. A researcher who collects health data directly from participants, outside any covered-entity function, is a common example: HIPAA’s Privacy Rule may never attach to that data, though other frameworks (the Common Rule, an institution’s own IRB-imposed conditions, state law, or GDPR for EU-linked data) can still apply. See HIPAA for the covered-entity/business-associate definitions.

Decedent information, 50+ years after death

Under 45 CFR 164.502(f), a covered entity’s Privacy Rule obligations toward a deceased individual’s PHI run for 50 years following death. After that period, the information ceases to be protected as PHI and the Privacy Rule no longer applies to it. This is a true exemption tied to elapsed time, separate from — and not to be confused with — the decedent-research disclosure pathway described below, which applies regardless of how long the person has been deceased.

Route 2 — still PHI, but disclosable for research without authorization

These pathways, all under 45 CFR 164.512(i), do not remove information from HIPAA’s scope. The covered entity remains bound by the Privacy Rule; it has simply been given a lawful basis to act without the individual’s signed authorization:

  • IRB or Privacy Board waiver of authorization (164.512(i)(1)(i)) — granted when the board documents that the research poses minimal privacy risk, is not practicable without the waiver, and is not practicable without access to the PHI. See HIPAA Privacy Rule.
  • Reviews preparatory to research (164.512(i)(1)(ii)) — used to design a study or assess feasibility; no PHI may be removed from the covered entity, and the researcher represents in writing that the review is solely to prepare a research protocol.
  • Research on decedents’ information (164.512(i)(1)(iii)) — available regardless of how long the individual has been deceased, on written representation that the use is solely for research on the decedent and, if requested, that PHI is necessary for the research.
  • Limited Data Set with a Data Use Agreement (45 CFR 164.514(e)) — direct identifiers are removed but some indirect identifiers (dates, geographic subdivisions larger than street address) are retained; the data remains PHI and requires a signed DUA. See Limited Data Set (HIPAA).

Because this information stays “in scope,” disclosures made under the waiver and preparatory-to-research pathways are generally subject to the Privacy Rule’s accounting-of-disclosures requirement — see HIPAA Accounting of Disclosures — whereas information that is genuinely exempt (de-identified, never held by a covered entity, or a decedent past the 50-year mark) generates no accounting obligation at all, because there is no PHI disclosure to account for.

Why the distinction matters in practice

Getting this wrong runs in both directions. Treating a limited data set or a waiver-based disclosure as “exempt” can mean skipping a required Data Use Agreement or accounting entry. Conversely, treating genuinely de-identified or non-covered-entity data as if it still required IRB waiver documentation or a DUA adds unnecessary administrative burden with no privacy benefit. Research administrators handling multi-site or retrospective studies — see HIPAA and Retrospective Research and HIPAA in Clinical Research — should confirm which route applies before deciding what documentation a given dataset needs.

Worked examples

Example — genuinely exempt: A university researcher receives a dataset stripped of all 18 Safe Harbor identifiers from a hospital’s research office, with a written statement of no actual knowledge that any individual could be re-identified. Once that determination is documented, the dataset is not PHI, and the researcher’s subsequent use is not governed by the Privacy Rule (though the institution’s own data-handling and IRB requirements may still apply).

Example — covered but disclosable: A hospital’s IRB grants a waiver of authorization so an epidemiologist can review identifiable records to identify a cohort of eligible patients for a retrospective study. The records remain PHI; the disclosure is permitted without individual authorization because the IRB documented the three waiver criteria, and the disclosure must still be tracked for accounting purposes.

Counter-example — a common mistake: A researcher receives an extract with names and medical record numbers removed and assumes it is automatically “de-identified” and therefore exempt. If the extract still contains a combination of indirect identifiers (unusual diagnosis, rare procedure date, small-population ZIP code) that a person could reasonably use to re-identify someone, it has not met the Safe Harbor or Expert Determination standard — it remains PHI, and treating it as exempt without a documented determination is a compliance gap, not a technicality.

Machine-readable encodings

Use in your systems

JATS XML <role> element
xml
<role vocab="credit"
      vocab-identifier="https://casrai.org/dictionary/"
      vocab-term="PHI Exemptions From the HIPAA Privacy Rule"
      vocab-term-identifier="https://casrai.org/dictionary/term/phi-exemptions-from-the-hipaa-privacy-rule" />
Schema.org DefinedTerm (JSON-LD)
json
{
  "@context": "https://schema.org",
  "@type": "DefinedTerm",
  "@id": "https://casrai.org/dictionary/term/phi-exemptions-from-the-hipaa-privacy-rule",
  "name": "PHI Exemptions From the HIPAA Privacy Rule",
  "identifier": "https://casrai.org/dictionary/term/phi-exemptions-from-the-hipaa-privacy-rule",
  "description": "PHI is exempt from the HIPAA Privacy Rule only when it meets one of three conditions: (1) it has been de-identified under the Safe Harbor or Expert Determination method (45 CFR 164.514), (2) it is held by a person or organization that is not a HIPAA covered entity or business associate, or (3) it is a deceased individual's information more than 50 years after death (45 CFR 164.502(f)). PHI that is disclosed for research without individual authorization under a waiver, a review preparatory to research, the decedent-research pathway, or as a Limited Data Set (all under 45 CFR 164.512(i) or 164.514(e)) remains PHI and remains subject to the Privacy Rule -- it is not exempt, merely disclosable through a permitted exception.",
  "inDefinedTermSet": "https://casrai.org/dictionary/domain/compliance-regulatory#set",
  "url": "https://casrai.org/dictionary/term/phi-exemptions-from-the-hipaa-privacy-rule",
  "sameAs": [],
  "license": "https://creativecommons.org/licenses/by/4.0/",
  "publisher": {
    "@id": "https://casrai.org/#organization"
  },
  "dateModified": "2026-07-23T08:03:36",
  "inLanguage": "en"
}

Referenced across the research world

University of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logoUniversity of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logo
  • University of Cambridge logo
  • Columbia University logo
  • Crossref logo
  • University of Edinburgh logo
  • Harvard University logo
  • University of Oxford logo
  • Princeton University logo
  • Stanford School of Medicine logo
  • University College London logo
  • ORCID logo

View CASRAI adoption →