HIPAA safe harbor vs expert determination: which fits business records?
HIPAA safe harbor removes 18 listed identifiers from structured data, while expert determination relies on a qualified expert documenting that re-identification risk is very small. Safe harbor suits clean tables; expert determination suits free text and dense data. SourceX treats PHI-adjacent records with neither one nor a valid authorization as a red flag.
Which HIPAA de-identification method fits business records?
Safe harbor fits records where identifiers sit in predictable fields and can be stripped cleanly; expert determination fits messy or free-text records where a qualified statistician must judge the remaining re-identification risk. Both are defined in 45 CFR 164.514(b), and HHS Office for Civil Rights guidance on de-identification explains that health information de-identified by either method is no longer protected health information under the Privacy Rule.
For a referral partner the practical point is narrow. Most companies SourceX works with are not healthcare providers, so HIPAA is not their main constraint. It becomes relevant when a company's records touch patient or member information: a billing outsourcer, a healthcare administration firm, a benefits broker or a practice-management software vendor. In those cases, the records cannot be licensed until one of these two methods, or another valid authorization, has been applied.
This is general information, not legal, tax or financial advice. Confirm with your own counsel before acting.
How do the two methods compare side by side?
Safe harbor is a checklist; expert determination is an opinion. The table below sets them next to each other using the points HHS describes.
| Question | Safe harbor | Expert determination |
|---|---|---|
| What is the test? | Remove the 18 listed identifiers and have no actual knowledge that what remains could identify a person | A qualified expert concludes and documents that the risk of re-identification is very small |
| Who decides? | The covered entity or business associate applying the list | A person with appropriate knowledge of and experience with statistical and scientific de-identification methods |
| Evidence produced | A record of what was removed and from which fields | A written analysis stating methods and results |
| Works best on | Structured tables with known columns | Free text, dense geographic or date data, or datasets where some identifiers are worth keeping |
| Main risk | Identifiers hiding in notes, attachments or file names | Cost, time and a conclusion that holds only for the dataset and recipient analyzed |
| Effect if met | Data is no longer PHI | Data is no longer PHI |
The "actual knowledge" clause deserves attention. If a billing manager knows that a rare diagnosis plus a small town points to one patient, stripping the listed fields does not satisfy the method.
What do the 18 identifiers look like in operational records?
The 18 HIPAA identifiers checklist for operational records walks through each one. In business systems they rarely appear only in a clean "patient name" column. Typical hiding places are:
- Support tickets and call notes where an agent types a member's name or phone number into a free-text field.
- Attachment file names such as scanned claim forms named after the person.
- Email signatures, subject lines and calendar invites that include appointment dates.
- Billing exports with account numbers, device serials or URLs embedded in comments.
- Screenshots and PDFs pasted into Slack or Teams threads.
This is why a column-level scrub is rarely enough for operational archives.
Which method fits which kind of record?
Match the method to the shape of the data rather than to a preference.
| Record type | Likely fit | Why |
|---|---|---|
| Claims-processing SOPs and training manuals with no patient content | Often outside HIPAA entirely | Procedures describe the work, not individuals |
| Billing workflow exports with coded fields | Safe harbor, if fields are clean | Structure makes field-level removal checkable |
| Call notes and support transcripts | Expert determination, or heavy redaction plus review | Free text carries identifiers in unpredictable places |
| Email archives of a healthcare administrator | Expert determination or exclusion from scope | Volume and variety make list-based removal unreliable |
| Dense date and location data | Expert determination | Safe harbor restricts dates and small geographies; an expert can assess risk with partial detail |
Many companies resolve this by scoping the dataset: leave out the patient-facing systems and license the procedural, financial-operations and internal-coordination records instead.
How does SourceX treat PHI-adjacent records?
Records that touch protected health information need either de-identification under one of the two methods or a valid HIPAA authorization before they belong in a licensed scope. Mainly-PHI datasets without that basis are a red flag for qualification, as are records belonging to a client of the company rather than the company itself.
Partners never handle the records. You do not export, upload or describe confidential content; you introduce the company and give basic fit information. Redaction and de-identification requirements are agreed with the company before any work begins, and data is delivered only after an executed agreement and the company's authorization. Nothing is binding until the company agrees price and terms and signs.
The company also needs its own counsel or compliance lead to confirm its position, especially if it is a business associate. The question of whether such a company may de-identify at all is covered in can a HIPAA business associate license de-identified data.
What should you ask the owner in the first conversation?
Use these as a short screen. They tell you whether HIPAA is a footnote or the main issue.
- Does the company serve healthcare providers, payers or patients directly?
- Do its systems hold names, dates of service or member numbers in free text?
- Does it act as a business associate under agreements with covered entities?
- Could the useful records be separated from the patient-facing ones?
- Has anyone at the company ever run a formal de-identification review?
Two or more "yes" answers on the first three lines means expect counsel and possibly an expert to be involved. Zero or one means the topic is probably manageable through scoping. The company fit checker gives a preliminary, non-binding screen without asking for contact details.
When is neither method the right answer?
Skip both methods and reconsider the introduction when the company's main asset is medical records or claims with no authorization route, or when a covered-entity client owns the data and has not consented. The broader legal picture is in is it legal for a company to license its business records for AI training, and the state-law angle in is licensing company records a sale under the CCPA.
Next step
If you know a US company with 50+ full-time employees at peak (contractors excluded), years of documented operations and an authorized sponsor, register as a partner and introduce it. Partners earn 25% of the eligible platform fees SourceX actually collects, capped at $100,000 cumulative per referred company, and only after the buyer pays and SourceX receives its fee. Rewards are not guaranteed. See how SourceX referrals work for the full process.
Common questions
Can a company mix both methods in one dataset?
Yes, in practice. A company can apply safe harbor to its structured billing tables and commission an expert determination for free-text notes or date-heavy files. Each portion needs its own documented basis. What matters is that every record touching health information in the licensed scope has a valid de-identification or authorization trail before delivery.
Does an expert determination last forever?
Not necessarily. The expert's conclusion applies to the dataset, the methods and the intended recipient as analyzed. If the data changes materially, new fields are added or it is shared with a different party, the analysis may need refreshing. Ask the expert what assumptions the opinion depends on and keep the written report with the contract file.
Is removing names enough to call a dataset de-identified?
No. Names are only one of 18 listed identifiers, and safe harbor also requires no actual knowledge that the remaining data could identify someone. Dates, small geographic areas, account numbers, device identifiers and free-text mentions all count. A name-only scrub is the most common reason a dataset fails review.
Do non-healthcare companies need either method?
Usually not, unless their records contain information received from covered entities or about patients or plan members. A logistics or software company with no health data sits outside the scope. A billing outsourcer, benefits administrator or health-software vendor should assume the question applies and ask counsel early.
What is a limited data set and how does it differ?
A limited data set removes direct identifiers but may keep some dates and geographic detail. HIPAA generally allows sharing it only for research, public health or health care operations under a data use agreement, so confirm the details with counsel. It is not the same as de-identified data and does not by itself support a commercial license.
Who should a partner talk to about this?
Partners should not advise on HIPAA at all. Raise the question, then point the owner to their own healthcare counsel or compliance officer. Your role is to flag that health-adjacent records exist and make the introduction; SourceX and the company's advisers handle scoping, redaction and review.
Related pages
- How SourceX US company data referrals work
- Can a HIPAA business associate de-identify PHI and license the result?
- Is it legal for a company to license its business records for AI training?
- Is licensing company records a 'sale' under the CCPA?
- The 18 HIPAA identifiers: where each one hides in business records
- Check Company Fit for Data Licensing
Free resources
- Earnout scenario calculator — Probability-weighted earnout value and its present value.
- Profit margin calculator — Profit and margin across three scenarios.
- Client opportunity brief generator — An editable intro email, summary and checklist.
- All free tools · MCP resource center
By SourceX Partnerships Team · Published 2026-10-09 · Updated 2026-10-09
Know a US company with valuable proprietary data?
Become a referral partner from anywhere we support, get your link and introduce an owner or authorized decision-maker.
Refer a company →I own a business
Explore licensing your company's data to AI developers worldwide. Start a short assessment; no uploads needed.
Start an assessment