Examples
Worked examples
- Is an instance
A dataset stripped of all 18 Safe Harbor identifiers (45 CFR 164.514(b)(2)), with documented no-actual-knowledge of re-identification risk, is no longer PHI.
- Is an instance
Identifiable health information collected directly by a researcher who is not a HIPAA covered entity or business associate is generally not PHI under HIPAA, even though it is sensitive.
- Is an instance
A deceased individual's health information, more than 50 years after death, is no longer protected as PHI under 45 CFR 164.502(f).
Counter-examples
Looks similar, but isn't
- Not an instance
An extract with only direct identifiers (name, MRN) removed, but retaining indirect identifiers that could reasonably re-identify someone, has not met the Safe Harbor standard and remains PHI -- it is not exempt just because it looks de-identified.
- Not an instance
PHI disclosed under an IRB waiver of authorization, a review preparatory to research, or as a Limited Data Set remains PHI subject to the Privacy Rule -- these are permitted-disclosure exceptions, not exemptions.
Editorial commentary
Protected health information (PHI) is “exempt” from HIPAA’s Privacy Rule in only a narrow set of circumstances — and it is easy to conflate that with a much broader category: PHI that is still covered by the Privacy Rule but that a covered entity may lawfully disclose without the individual’s authorization under a research exception. These are not the same thing, and mixing them up leads research administrators to either over-restrict data that HIPAA never touched, or to under-document a disclosure that HIPAA still requires be tracked and, in some cases, accounted for.
Two different questions
“Is this information exempt from the Privacy Rule?” and “Can this PHI be disclosed for research without an authorization?” sound similar but have different legal consequences. If information is genuinely exempt, HIPAA’s rules on minimum necessary, accounting of disclosures, and breach notification simply do not apply to it — because it is not PHI. If information is still PHI but disclosure is permitted under a research exception (a waiver, a limited data set, a review preparatory to research), the Privacy Rule still governs it; the covered entity has just been given a lawful path to disclose it without asking the individual first, and other Privacy Rule obligations (documentation, data use agreements, accounting) typically still apply.
Route 1 — genuinely exempt (not PHI at all)
De-identified information
Information that meets the Safe Harbor method (removal of all 18 identifier categories at 45 CFR 164.514(b)(2), with no actual knowledge that the remainder could identify the individual) or the Expert Determination method (45 CFR 164.514(b)(1)) is, by regulatory definition, no longer PHI. See De-identification for the mechanics of both methods.
Information never held by a covered entity or business associate
PHI is defined by who holds it, not just what it says. Identifiable health information collected or held by a person or organization that is not a HIPAA “covered entity” (a health plan, health care clearinghouse, or health care provider that transmits standard electronic transactions) or a “business associate” acting on a covered entity’s behalf is generally not PHI under HIPAA at all — even though it may be highly sensitive. A researcher who collects health data directly from participants, outside any covered-entity function, is a common example: HIPAA’s Privacy Rule may never attach to that data, though other frameworks (the Common Rule, an institution’s own IRB-imposed conditions, state law, or GDPR for EU-linked data) can still apply. See HIPAA for the covered-entity/business-associate definitions.
Decedent information, 50+ years after death
Under 45 CFR 164.502(f), a covered entity’s Privacy Rule obligations toward a deceased individual’s PHI run for 50 years following death. After that period, the information ceases to be protected as PHI and the Privacy Rule no longer applies to it. This is a true exemption tied to elapsed time, separate from — and not to be confused with — the decedent-research disclosure pathway described below, which applies regardless of how long the person has been deceased.
Route 2 — still PHI, but disclosable for research without authorization
These pathways, all under 45 CFR 164.512(i), do not remove information from HIPAA’s scope. The covered entity remains bound by the Privacy Rule; it has simply been given a lawful basis to act without the individual’s signed authorization:
- IRB or Privacy Board waiver of authorization (164.512(i)(1)(i)) — granted when the board documents that the research poses minimal privacy risk, is not practicable without the waiver, and is not practicable without access to the PHI. See HIPAA Privacy Rule.
- Reviews preparatory to research (164.512(i)(1)(ii)) — used to design a study or assess feasibility; no PHI may be removed from the covered entity, and the researcher represents in writing that the review is solely to prepare a research protocol.
- Research on decedents’ information (164.512(i)(1)(iii)) — available regardless of how long the individual has been deceased, on written representation that the use is solely for research on the decedent and, if requested, that PHI is necessary for the research.
- Limited Data Set with a Data Use Agreement (45 CFR 164.514(e)) — direct identifiers are removed but some indirect identifiers (dates, geographic subdivisions larger than street address) are retained; the data remains PHI and requires a signed DUA. See Limited Data Set (HIPAA).
Because this information stays “in scope,” disclosures made under the waiver and preparatory-to-research pathways are generally subject to the Privacy Rule’s accounting-of-disclosures requirement — see HIPAA Accounting of Disclosures — whereas information that is genuinely exempt (de-identified, never held by a covered entity, or a decedent past the 50-year mark) generates no accounting obligation at all, because there is no PHI disclosure to account for.
Why the distinction matters in practice
Getting this wrong runs in both directions. Treating a limited data set or a waiver-based disclosure as “exempt” can mean skipping a required Data Use Agreement or accounting entry. Conversely, treating genuinely de-identified or non-covered-entity data as if it still required IRB waiver documentation or a DUA adds unnecessary administrative burden with no privacy benefit. Research administrators handling multi-site or retrospective studies — see HIPAA and Retrospective Research and HIPAA in Clinical Research — should confirm which route applies before deciding what documentation a given dataset needs.
Worked examples
Example — genuinely exempt: A university researcher receives a dataset stripped of all 18 Safe Harbor identifiers from a hospital’s research office, with a written statement of no actual knowledge that any individual could be re-identified. Once that determination is documented, the dataset is not PHI, and the researcher’s subsequent use is not governed by the Privacy Rule (though the institution’s own data-handling and IRB requirements may still apply).
Example — covered but disclosable: A hospital’s IRB grants a waiver of authorization so an epidemiologist can review identifiable records to identify a cohort of eligible patients for a retrospective study. The records remain PHI; the disclosure is permitted without individual authorization because the IRB documented the three waiver criteria, and the disclosure must still be tracked for accounting purposes.
Counter-example — a common mistake: A researcher receives an extract with names and medical record numbers removed and assumes it is automatically “de-identified” and therefore exempt. If the extract still contains a combination of indirect identifiers (unusual diagnosis, rare procedure date, small-population ZIP code) that a person could reasonably use to re-identify someone, it has not met the Safe Harbor or Expert Determination standard — it remains PHI, and treating it as exempt without a documented determination is a compliance gap, not a technicality.
Machine-readable encodings
Use in your systems
<role vocab="credit"
vocab-identifier="https://casrai.org/dictionary/"
vocab-term="PHI Exemptions From the HIPAA Privacy Rule"
vocab-term-identifier="https://casrai.org/dictionary/term/phi-exemptions-from-the-hipaa-privacy-rule" />{
"@context": "https://schema.org",
"@type": "DefinedTerm",
"@id": "https://casrai.org/dictionary/term/phi-exemptions-from-the-hipaa-privacy-rule",
"name": "PHI Exemptions From the HIPAA Privacy Rule",
"identifier": "https://casrai.org/dictionary/term/phi-exemptions-from-the-hipaa-privacy-rule",
"description": "PHI is exempt from the HIPAA Privacy Rule only when it meets one of three conditions: (1) it has been de-identified under the Safe Harbor or Expert Determination method (45 CFR 164.514), (2) it is held by a person or organization that is not a HIPAA covered entity or business associate, or (3) it is a deceased individual's information more than 50 years after death (45 CFR 164.502(f)). PHI that is disclosed for research without individual authorization under a waiver, a review preparatory to research, the decedent-research pathway, or as a Limited Data Set (all under 45 CFR 164.512(i) or 164.514(e)) remains PHI and remains subject to the Privacy Rule -- it is not exempt, merely disclosable through a permitted exception.",
"inDefinedTermSet": "https://casrai.org/dictionary/domain/compliance-regulatory#set",
"url": "https://casrai.org/dictionary/term/phi-exemptions-from-the-hipaa-privacy-rule",
"sameAs": [],
"license": "https://creativecommons.org/licenses/by/4.0/",
"publisher": {
"@id": "https://casrai.org/#organization"
},
"dateModified": "2026-07-23T08:03:36",
"inLanguage": "en"
}






