De-identify before sharing: more than removing a name
Removing a name is not enough. Use a recognized method and check the whole record, including notes and file details.
Bring: Use fictional records to rehearse; do not upload real records to an unapproved service.
Make: A record of the chosen method and review.
Choose the method deliberately
HIPAA provides Safe Harbor and Expert Determination methods. Safe Harbor requires removing the specified identifiers and no actual knowledge that the remaining information can identify someone. Expert Determination uses a qualified expert’s documented assessment of very small identification risk.
Under Safe Harbor, most dates directly related to an individual must be reduced to the year; special rules also apply to ages over 89. Consistently shifting dates or replacing a name with a code is not, by itself, Safe Harbor de-identification.
Review the entire file
Check free text, headers, screenshots, hidden spreadsheet tabs and file metadata as well as structured columns. Rare combinations and narrative details may remain identifying. Removing names, birth dates and record numbers alone is insufficient.
Do not upload PHI to an unapproved service to ask it to remove identifiers: the disclosure has already happened. An approved processing workflow can support de-identification, but its outputs still need verification. For teaching and prototyping, entirely fictional records often avoid the need to transform a real record at all.
Confirm permission to share
Even properly de-identified data can remain subject to contractual, research or organizational limits. Document the method and review rather than assuming a prompt or a pseudonym makes a dataset anonymous.
Check before you use the result
- Choose a recognized de-identification method.
- Review free text, screenshots, hidden fields and file metadata.
- Check contractual and organizational limits before sharing.
- Do not treat removed names or shifted dates as proof of de-identification.