Use an authority-first checklist to assess whether administrative data can support an approved evaluation or secondary purpose.

Start here

Does any of this sound familiar?

  • Your organization has records that seem less sensitive after direct identifiers are removed.
  • Dates, locations, rare services, free text, or linked records may still make individuals recognizable.
  • A vendor or internal team proposes AI evaluation, research, or reuse and needs a documented permissions review.

Prior authorization attachments, appointment histories, claim notes, billing correspondence, and referrals can reveal care even without names. A rare service date and small location may still identify someone.

First ask whether the organization has authority for the proposed use. HIPAA methods do not erase contractual duties, other privacy laws, ethical commitments, or security obligations. De-identification is not permission to send files to an unreviewed service.

Not ready to share a single file? You don't have to.

Take the 3-question fit check

The problem

Identifier removal does not resolve rights or every re-identification risk.

Removing names and medical record numbers may leave detailed dates, rare services, free text, or linkable codes. Small cohorts make events recognizable. Recipient data access, intended use, and environment affect risk even after a HIPAA method is applied.

Records may come from patients, providers, payers, or vendors under different agreements. Establish who created the fields, who can disclose them, and whether the activity is allowed. Synthetic evaluation tasks differ from licensing historical records; removing names does not settle rights.

A safer file is not necessarily an authorized file, and an authorized use still needs controls.

The solution

Use a staged de-identification and release review.

Before transfer, document purpose and involve privacy, security, legal, and the operational owner. Record when the answer is no or needs analysis.

DataSupply partners only with labs that meet its top 0.01% credibility standard. We help assess whether a qualified buyer may be a fit and negotiate terms that reflect the data's potential value, including exclusivity where relevant. We also help you work through diligence questions about rights, privacy, security, and compliance, then present a high-level inventory of permitted records, not the dataset. Fit is specific to each situation; no buyer or value is guaranteed.

What to inventory before any buyer conversation

  • Establish source and authority Inventory origin, record categories, owners, collection context, notices, authorizations, agreements, business associate roles, and proposed use. Distinguish quality review, research, service delivery, vendor evaluation, and external licensing. Do not infer authority from possession.
  • Select and document the method Assess HIPAA Safe Harbor or Expert Determination. Safe Harbor requires removal of specified identifiers and no actual knowledge that remaining data could identify someone. Expert Determination requires a qualified expert to document very small risk in the recipient context. Check dates, geography, rare events, narratives, linkages, and small cells.
  • Constrain the release and monitor For an approved disclosure, specify fields, recipients, purpose, environment, roles, retention, deletion verification, incident reporting, and bans on re-identification and onward disclosure. Test for residual identifiers and reassess changed uses. Keep a release register and owner.

Set the boundaries before discussing access.

Have privacy and legal reviewers document method and risk. Minimize, encrypt, limit and log access; bind recipients to purpose, deletion, incident, subcontracting, derivative-output, and no-reidentification terms. Consider state law, research rules, contracts, and patient expectations. Removing identifiers does not mean PHI can simply be sold.

What could make a permitted example useful?

Preparation, expert review, linkage risk, and controls have costs. No automatic value or payment follows. A bounded task evaluation is distinct from licensing a historical corpus and needs separate rights analysis.

A practical first step.

Inventory sources, fields, owners, and purpose without export. Ask privacy and counsel to identify the HIPAA pathway and added contract or state-law limits.

datasupply.ai can discuss possible fit and buyer questions without receiving your dataset. You decide whether to pursue any introduction. No buyer, license, or payment is guaranteed.

Documented example / what it proves

HHS explains two HIPAA de-identification methods and their standard.

HHS OCR describes two HIPAA methods: Safe Harbor removes specified identifiers and requires no actual knowledge that remaining data could identify someone; Expert Determination uses a qualified expert to find risk very small under accepted principles. The guidance addresses recipient and data context. Read U.S. Department of Health and Human Services Office for Civil Rights.

This supports a documented method and risk assessment rather than name removal alone. HIPAA de-identification does not settle every contractual or legal permission and does not remove security duties.

The important limit: HHS describes HIPAA methods, not a closed data license, blanket commercial permission, or guaranteed non-identifiability.

Where might your own organization stand?

Take the private fit check

Quiz / Your next step

What do you know about authority and de-identification?

Select the closest description without uploading or sharing any records.

01 What kind of records do you have?
02 What do you know about the rights?
03 Where are you in the process?

This check stays in your browser. If you choose to apply, your answers are included when you submit the application.

No fee for the initial conversation or introduction. We may be compensated by a buyer if an introduction becomes a partnership. No buyer, license, or payment is guaranteed. Review any proposed deal with your own legal and security advisers.