Redacting PHI for HIPAA: the 18 Safe Harbor identifiers
Updated
Short answer
Under HIPAA’s Safe Harbor method (45 CFR 164.514(b)(2)), health information counts as de-identified only when 18 kinds of identifiers are removed — including names, sub-state geography, dates other than year, contact and record numbers, and full-face photos — and you have no actual knowledge the remainder could identify the person.
What PHI is
Protected health information (PHI) is individually identifiable health information created, received, maintained, or transmitted by a HIPAA covered entity (a health plan, a health care clearinghouse, or a provider that conducts certain electronic transactions) or by a business associate working on its behalf. It covers information in any form — paper, electronic, or spoken — that relates to a person’s health, care, or payment for care and identifies the person or could reasonably be used to identify them.
De-identification versus redaction
De-identification is a standard: information that meets it is no longer PHI, and the HIPAA Privacy Rule stops applying to it. HIPAA recognizes two methods — Safe Harbor, which removes a fixed list of identifiers, and Expert Determination, in which a qualified expert applies statistical or scientific methods and documents that the risk of re-identification is very small.
Redaction is a technique: removing specific information from a specific document. Redaction is how you remove identifiers, but a redacted document is not automatically de-identified. A record released to one patient, one insurer, or one court with a few fields blacked out is often still PHI and still subject to the Privacy Rule’s other requirements, such as the minimum necessary standard.
The 18 Safe Harbor identifiers
Under 45 CFR 164.514(b)(2)(i), these identifiers of the individual, and of the individual’s relatives, employers, and household members, must be removed:
- Names.
- All geographic subdivisions smaller than a state — street address, city, county, precinct, ZIP code, and their equivalent geocodes. The first three digits of a ZIP code may be kept if the area formed by all ZIP codes sharing those three digits contains more than 20,000 people; otherwise they must be changed to 000.
- All elements of dates (except year) directly related to the individual, including birth date, admission date, discharge date, and date of death, and all ages over 89 and date elements (including year) indicating such an age — those must be aggregated into a single category of age 90 or older.
- Telephone numbers.
- Fax numbers.
- Email addresses.
- Social Security numbers.
- Medical record numbers.
- Health plan beneficiary numbers.
- Account numbers.
- Certificate and license numbers.
- Vehicle identifiers and serial numbers, including license plate numbers.
- Device identifiers and serial numbers.
- Web URLs.
- IP addresses.
- Biometric identifiers, including finger and voice prints.
- Full-face photographs and any comparable images.
- Any other unique identifying number, characteristic, or code, except a re-identification code permitted by the rule.
Removing the list is only half of Safe Harbor. Under 164.514(b)(2)(ii), the covered entity must also have no actual knowledge that the remaining information could be used, alone or in combination, to identify the individual. A rare diagnosis in a small town can identify someone even with every listed field removed.
A practical checklist for documents
- Headers, footers, and fax cover sheets, which repeat names, record numbers, and phone numbers on every page.
- Barcodes and QR codes on labels and wristbands, which often encode a medical record number.
- Free-text notes, where names of relatives, employers, and places appear in sentences rather than labelled fields.
- Dates in every form: visit dates, lab dates, and signature dates, not only the birth date.
- Images: faces, tattoos, and photos of documents or wristbands.
- Handwriting and stamps, which text detection and OCR often miss.
- Metadata: document author, title, comments, and the file name itself.
- Audio and video: spoken names and numbers, and faces in frame. Voice prints are on the list too.
After redacting, verify the file the same way you would any redaction: try to copy, search, and extract the removed text, and look at every page.
Why client-side processing matters
When a covered entity uses an online service that creates, receives, maintains, or transmits PHI on its behalf, that service is generally a business associate and needs a business associate agreement. Uploading patient records to an arbitrary website to redact them can therefore be a compliance problem in its own right.
Tools that process files entirely in your browser avoid sending the file to the vendor. GhostX’s PDF redaction and X-ray run locally: the page downloads the tool’s code and detection models, but the document itself is not uploaded, which you can confirm with your browser’s Network tab. Whether a given tool is acceptable under your organization’s policies is a decision for your privacy or compliance officer.
What automatic detection can and can’t do
GhostX’s detectors find email addresses, phone numbers, US Social Security number patterns, card numbers, IBANs, IP addresses, and dates, and — with the on-device name model loaded — names, organizations, and locations. Custom rules let you add your own patterns, such as your medical record number format. That covers several Safe Harbor categories but not all of them: fax numbers are found as phone numbers, and license plates, device serials, biometric identifiers, faces, and most free-form identifiers need human review. Treat detection as a first pass, not as a compliance determination.
Not legal advice
This article summarizes the Safe Harbor text for general information. It is not legal advice, and using GhostX or any other tool does not by itself make a disclosure HIPAA-compliant. Your obligations depend on who you are, what you’re disclosing, and to whom; consult your privacy officer or counsel, and read the HHS de-identification guidance for detail on each identifier.
Frequently asked questions
-
Is a redacted medical record still PHI?
Often, yes. Only information that meets HIPAA’s de-identification standard — Safe Harbor or Expert Determination — stops being PHI. A record with a few fields removed and released to a specific recipient is usually still PHI.
-
Can I keep the year in dates under Safe Harbor?
Yes, the year may be kept, except for people over 89: ages over 89, and any date elements including year that would indicate such an age, must be grouped into a single ‘90 or older’ category.
-
Can I keep part of a ZIP code?
The first three digits may be kept only if all ZIP codes sharing those digits together contain more than 20,000 people, based on current Census data. Otherwise the three digits must be replaced with 000.
-
Does using a client-side redaction tool make me HIPAA compliant?
No. Client-side processing avoids sending PHI to the tool’s vendor, but compliance depends on your policies, what you disclose, and to whom. It is not a substitute for your organization’s review.