The 18 HIPAA identifiers: where each one hides in business records

The 18 HIPAA identifiers are the categories of data, from names and dates to IP addresses and photographs, that Safe Harbor requires removing before health information counts as de-identified. This checklist adds where each one hides in business systems, so owners and partners can spot protected health information before records are considered for licensing.

What are the 18 HIPAA identifiers?

The 18 HIPAA identifiers are the categories of information that the Safe Harbor method in the HIPAA Privacy Rule requires removal of before health information counts as de-identified. They cover names, small geographic units, dates, contact details, account and record numbers, device and vehicle IDs, web and network identifiers, biometric identifiers, photographs and any other unique code. HHS publishes the list in its guidance on de-identification of protected health information.

Most checklists stop at the list. This one adds the part business owners actually need: where each identifier hides inside ordinary operational systems such as email signatures, ticket metadata, scanned forms, call audio and file names. A company that never touches a hospital can still hold several of these identifiers in its records.

This matters to a referral partner because mainly-PHI datasets are a red flag for data licensing. Knowing the identifiers helps you recognize a dead-end early, and helps an owner understand why SourceX agrees redaction rules with the company before any work begins.

The 18 identifiers and where they hide in business systems

The identifiers below follow the categories HHS describes. The right-hand column is a practical reading for operational records, not part of the regulation.

#IdentifierWhere it hides in business systems
1NamesEmail headers and signatures, ticket requester fields, CRM contacts, file names such as "Smith_intake.pdf"
2Geographic units smaller than a stateStreet addresses in invoices, shipping labels, scanned forms, and ZIP codes in CRM exports
3Dates tied to an individual (except year)Appointment, admission, service and birth dates in tickets, calendars and log timestamps
4Telephone numbersCall logs, signature blocks, SMS exports, voicemail transcripts
5Fax numbersFax-to-email archives, scanned cover sheets
6Email addressesSender and recipient fields, support portal accounts, mailing lists
7Social Security numbersScanned onboarding forms, spreadsheets attached to email, payroll exports
8Medical record numbersBilling notes, referral documents, free text in support tickets
9Health plan beneficiary numbersEligibility checks, claim attachments, insurance card photos
10Account numbersInvoices, collections notes, customer IDs reused as health account numbers
11Certificate and license numbersCredentialing files, vendor onboarding packets
12Vehicle identifiers and platesFleet logs, transport and delivery records, incident reports
13Device identifiers and serial numbersAsset registers, service tickets, equipment maintenance logs
14Web URLsBrowser history exports, links pasted into chat, portal deep links with record IDs
15IP addressesWeb server logs, login audit trails, helpdesk metadata
16Biometric identifiers, including finger and voice printsVoice biometrics in call platforms, badge systems, exported templates
17Full-face photographs and comparable imagesBadge photos, scanned IDs, attachments in tickets and chat
18Any other unique identifying number, characteristic or codeInternal patient or client codes, free-text nicknames, case numbers

The identifiers must be removed for the individual and also for the individual's relatives, employers and household members. The Safe Harbor method also requires that the company has no actual knowledge that the remaining information could identify a person. Removing the 18 fields from a database column is therefore not enough if the same person is described in free text.

The hiding-place checklist for owners

Use these groups with whoever administers each system. The point is to find out whether any identifiers exist at all, not to remove them yourself.

Email and chat

  • Signature blocks and quoted reply chains include names, phone and fax numbers
  • Attachments include scanned forms, insurance cards or photographed IDs
  • Chat threads paste links, record numbers or account IDs

Tickets, CRM and billing

  • Free-text notes mention dates of service, plan numbers or medical record numbers
  • Custom fields store birth dates, member IDs or device serial numbers
  • Automatic metadata stores IP addresses and requester email addresses

Files, forms and media

  • File and folder names contain a person's name or a record number
  • Scanned PDFs hold image-only text that keyword search will not find
  • Call recordings contain spoken names, dates of birth or account numbers, and the platform may store voiceprints

What the results mean and what to do next

ResultWhat it meansNext action
No identifiers found in any systemRecords are likely general business operations, not health-relatedProceed to a normal fit screen
Identifiers found only in a few free-text fieldsRedaction may be practical and can be scopedAsk the company to describe those fields during its data inventory
Identifiers in most records, health contextThe dataset may be mainly PHIPause; the company needs HIPAA authorization or a recognized de-identification route
Company is a vendor handling PHI for othersIts rights depend on its contractsRead can a business associate de-identify PHI first

Safe Harbor is one of two HIPAA routes; the other is expert determination. The comparison of safe harbor and expert determination explains how they differ for business records. Call audio raises its own consent questions, covered in does "this call may be recorded" cover AI. Privacy laws beyond HIPAA also apply; see whether licensing is a sale under the CCPA.

Red flags for a referral

  • The company's records are mainly clinical notes, claims or patient communications
  • The company cannot say who created the records or under what contract
  • Identifiers are embedded in scans and audio that nobody can search
  • The owner assumes that deleting a name column makes a record anonymous

A company with these signs can often still qualify later, for example after an expert determination, so treat it as "not yet" rather than "never". A partner's part ends at asking whether any of this might exist. The company's own staff search the systems during the data inventory, and redaction rules are settled with SourceX before any work begins. This is general information, not legal, tax or financial advice. Confirm with your own counsel or compliance adviser before acting.

Next step

Run one company through the company fit checker, which is a preliminary, non-binding screen with no contact details required, and read how it works to see where redaction fits. If the company looks suitable, register as a partner and make the introduction.

  1. Step 1Share your linkSend your personal link to a company you know.
  2. Step 2Company appliesThe company applies itself at /apply.
  3. Step 3Buyer selects and paysThe buyer selects and pays for the data and SourceX receives its fee.
  4. Step 4You get your rewardYour share of SourceX fees becomes payable.

Common questions

Is a company covered by HIPAA just because its records contain a name and a date?

Not necessarily. HIPAA applies to covered entities and their business associates, and identifiers only matter as protected health information when they relate to health care, payment or health status. A company with names and dates in ordinary sales tickets is usually outside HIPAA, though other privacy laws may apply. Ask counsel to confirm the company's status.

Does removing the 18 identifiers make a dataset safe to license?

No. Safe Harbor also requires that the company has no actual knowledge that the remaining information could identify someone, and other laws or contracts may still restrict use. Free text, scans and audio often retain identifying detail. De-identification is one step in a rights review, not a substitute for it.

Are ZIP codes always an identifier?

Geographic units smaller than a state are covered, and HHS describes limited conditions for keeping part of a ZIP code. Because the exception depends on population thresholds, owners should not apply it from memory. Ask the company's privacy adviser to apply the HHS guidance to the actual data.

Can a partner help check which identifiers a company holds?

A partner can share this checklist and ask basic fit questions, but never exports, uploads or describes confidential records. The company's own staff, working with SourceX during the data inventory, determine what exists and agree redaction requirements before any work begins.

Why would call recordings count here?

Spoken names, dates of birth and account numbers appear in audio, and some call platforms create voiceprints, which are a biometric identifier. Audio is also hard to search, so identifiers can go unnoticed. Recordings usually need transcription-based detection and a separate consent review.

Free resources

By SourceX Partnerships Team · Published 2026-10-09 · Updated 2026-10-09

Know a US company with valuable proprietary data?

Become a referral partner from anywhere we support, get your link and introduce an owner or authorized decision-maker.

Refer a company →

I own a business

Explore licensing your company's data to AI developers worldwide. Start a short assessment; no uploads needed.

Start an assessment