Does the Safe Harbor scan mean my data is HIPAA de-identified? #8
Unanswered
cognis-digital
asked this question in
Q&A
Replies: 0 comments
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
A recurring question: is
deidproof's "HIPAA Safe Harbor" check sufficient to declare data de-identified under 45 CFR 164.514(b)?Short answer: no tool can make that determination for you.
deidproofdetects the 18 Safe Harbor identifier categories (S1-S18) by column name and by cell content, and it computes k-anonymity and l-diversity. That is a strong, reproducible, machine-checkable first pass -- but Safe Harbor also has a subjective clause (the covered entity must have no actual knowledge that the residual information could identify an individual), and the alternative Expert Determination method is a statistical judgmentdeidproofdoes not attempt.Also worth understanding about the detectors:
Use
deidproofto catch the obvious leaks and to produce audit evidence -- not as a substitute for a qualified privacy review. Questions about a specific column or format? Post them here with a synthetic example.All reactions