How to Render PHI “Deidentified”

Q. I need to provide an insurance company a deidentified sampling of medical records from my practice for initial credentialing. What, precisely, defines a “deidentified” record?

A. Physicians may need to use deidentified records for various purposes, such as research, demographic and public health studies, or operational purposes like credentialing. Deidentified health information as defined by HIPAA is not protected health information (PHI) and thus is not covered by the HIPAA Privacy Rule.

To create a deidentified record according to HIPAA, you must remove all of the following information about a patient, as well as similar information about the patient’s relatives, employer, and household members:

  1. Name;
  2. Street address, city, county, precinct, and ZIP Code;
  3. Dates directly related to any individual, including birth date, admission date, discharge date, date of death;
  4. Telephone numbers;
  5. Fax numbers;
  6. Email addresses;
  7. Social Security number;
  8. Medical record number;
  9. Health plan beneficiary number;
  10. Account number;
  11. Certificate/license numbers;
  12. Vehicle identifiers and serial numbers including license plate numbers;
  13. Device identifiers and serial numbers;
  14. Web Universal Resource Locators (URLs);
  15. Internet protocol (IP) address numbers;
  16. Biometric identifiers, including finger and voice prints;
  17. Full-face photographic images and any comparable images; and
  18. Any other unique identifying number, characteristic, or code.

 Physicians involved in research can learn more on the National Institutes for Health’s Information for Researchers webpage.


Published Jan. 22, 2013

   TMA Practice E-Tips main page  


Last Updated On

April 05, 2016

Related Content

HIPAA | Medical Records