HEALTHCARE · PATIENT DE-IDENTIFICATION
HIPAA expert determination for PHI and SUD data, built and attested by one team
Expert determination does not require a certified attester. It requires a qualified statistician and a method that holds up under scrutiny. OutcomeCatalyst builds the de-identification pipeline and writes the determination, so there is one team, one contract and one accountable party.
Why de-identified data still fails somebody else's review
These are the four things that stop a data set from being usable, and they tend to surface late, in a counterparty's legal review rather than in your own.
Two vendors, or one
The usual way to buy this splits the work between a pipeline builder and an attester. That split is where the delay comes from, and it is why neither party ends up owning the result.
How the determination is actually reached
The standard is 45 CFR 164.514(b)(1): a qualified statistician applies generally accepted statistical and scientific principles and documents that the risk of re-identification is very small. Here is what that involves in practice.
What the engagement produces
Five deliverables, from one team, under one contract.
What operators use this for
One pipeline, but not one legal basis. The expert determination covers the de-identified releases. A limited data set is a different thing and travels under its own agreement, so each use below gets the release it actually needs.
Built for the stack a provider group actually runs
These are the systems referenced in the workflow above. Identifiers live in all of them, including the ones nobody thinks of as a source of PHI.
Try this on your own data before anyone else does
Age, three-digit ZIP and diagnosis are all permitted under Safe Harbor. The visit month is not: Safe Harbor removes every date element below the year. Expert determination is the only method that can keep finer timing at all, and only for the records where the numbers show it is safe to. Put these four together on an uncommon condition in a small population and you are often describing exactly one person.
If you can single out a patient in your own data this way, that data set is not de-identified, whatever the field list says about it. A checklist cannot tell you this, because it never looks at your data. Measuring it is the whole reason expert determination exists.
Questions operators and their counsel ask first
What is the difference between Safe Harbor and expert determination?
They are the two methods HIPAA permits. Safe Harbor, at 164.514(b)(2), removes eighteen categories of identifier and requires no actual knowledge that what remains could identify someone. Expert determination, at 164.514(b)(1), instead has a qualified statistician measure the actual risk and document that it is very small. Safe Harbor is simpler to apply. Expert determination usually leaves you with far more usable data.
Is there a certification for expert determination?
No. There is no certification, licence or official register of approved attesters, and anyone describing themselves as certified for this is describing something that does not exist. The rule asks for a person with appropriate knowledge of and experience with generally accepted statistical and scientific principles for rendering information not individually identifiable, and for the methods and results to be documented. That is the whole bar, and it is a substantive one.
Who signs the determination?
The statistician who performed the assessment signs it, and their name and qualifications appear in the report. When you are evaluating any provider, including us, ask who will sign yours and what their background is. You should get a direct answer, because that person's judgment is what the determination rests on.
Can we keep dates and geography?
Sometimes, and this is where expert determination earns its keep. Safe Harbor removes every date element below the year and all geography below the state, which is exactly what makes it so expensive for research. Expert determination can justify keeping finer detail, but only where the measurements show the risk stays very small, and only for the records where that holds. Everywhere else the detail is generalised or the record comes out. If you need dates and geography kept across the board no matter what, that is a limited data set under a data use agreement, not de-identified data.
What exactly gets measured?
Three things, each against a threshold. That no record in the release matches fewer than five people in the wider population, and no fewer than ten for records from Part 2 programs. That any group that size holds at least three different diagnoses. And that the mix of values inside a group stays close to the mix across the release as a whole. The measurements run across the full linked patient record rather than table by table, because a row that looks safe on its own often is not once it is joined back to everything else about that patient.
How long is a determination valid?
Ours runs for 24 months. HIPAA does not set a fixed expiry, but risk is measured against a data set and a population that both change, so an open-ended determination is not credible. We monitor monthly in between and re-attest when something moves enough to matter.
Can 42 CFR Part 2 SUD data be included?
Yes, and it is handled separately from the first step rather than folded in with everything else. Part 2 records are segmented before any transformation, and they are governed on their own track with their own consent and disclosure rules. In our default release design they are held out of external data products entirely and used only for consented or permitted research. This is the part most providers decline to take on.
Does de-identified data still count as PHI?
Once information meets the de-identification standard at 164.514, it is no longer PHI and the Privacy Rule no longer restricts its use or disclosure. That is precisely why the determination matters: it is the documented basis for saying the standard was met. A limited data set is a different thing. It keeps dates and geography, it remains PHI, the determination does not cover it, and it travels under a data use agreement instead.
How much does this cost?
It depends on how many systems are in scope, how much of the identifying information sits in free text rather than in structured fields, and whether Part 2 records are included. Because one team builds the pipeline and signs the determination, you are buying a single engagement rather than two, with no coordination overhead between vendors and no rework handed back and forth. We scope it against your actual data rather than quoting from a rate card, so the first step is a look at what you are holding.
Can the data still be linked after release?
Yes, through privacy-preserving linkage tokens rather than by retaining identifiers. Records can be joined across sources and over time without anyone holding the underlying identity, which is what makes longitudinal research possible on a data set that is genuinely de-identified.
This page describes how we approach de-identification and expert determination under HIPAA and 42 CFR Part 2. It is general information about our methodology, not legal advice, and it does not replace your own counsel's review of a specific data set or disclosure.
Patient de-identification and expert determination: common questions
What is HIPAA expert determination?
It is one of the two de-identification methods HIPAA allows, set out at 45 CFR 164.514(b)(1). A qualified statistician applies accepted statistical and scientific principles, measures the risk that a record could be re-identified, and determines in writing that the risk is very small. The other method is Safe Harbor, which removes eighteen categories of identifier.
Do you need to be certified to provide an expert determination?
No. There is no certification, licence or register of approved attesters for this. The rule asks for a person with appropriate knowledge of and experience with generally accepted statistical and scientific principles, and for the methods and results to be documented. Operators frequently pay more than they need to because they assume a certification is involved.
Can 42 CFR Part 2 SUD data be de-identified?
Yes, and it is handled on its own track from the start. Records from federally assisted substance use disorder programs carry obligations that HIPAA alone does not impose, so they are segmented before any transformation and governed separately. Many providers of de-identification will not take on Part 2 data at all.

