Video 6 · Becoming a HIPAA Qualified Expert

6. Identifiers, Quasi-identifiers, and Uniqueness

48 min

After this video you can

  • Classify fields with the NIST taxonomy
  • Compute equivalence classes and k
  • Contrast sample and population uniqueness
  • Hunt hidden identifiers in real data

Module 3: Statistical Foundations · Runtime 48:05 · YouTube title: Quasi-identifiers and Uniqueness in HIPAA De-identification

Nobody's name needs to be in a dataset for the dataset to name them. This is where the statistics start: the NIST identifier taxonomy, equivalence classes and k computed by hand on the Springfield table, sample versus population uniqueness, the Zayatz and Pitman estimators, and the places identifiers hide.

In this video

  • The four buckets: direct identifiers, quasi-identifiers, sensitive attributes, non-identifying attributes, and why classification is contextual
  • NIST IR 8053 versus SP 800-188
  • Why three fields are enough: 9 ages × 2 sexes × 4 ZIPs = 72 cells for only 10 records
  • The Springfield extract: 9 classes, 8 singletons, minimum k = 1; adding admit date makes all 10 unique
  • Special uniques and the SUDA algorithm
  • Sample uniqueness versus population uniqueness, and the estimation problem
  • The Zayatz estimator and the Pitman estimator
  • A field-classification decision procedure, free text, DICOM metadata, hashed MRNs, geocodes, and an applied schema exercise

Authorities quoted on screen

NIST Interagency Report 8053; NIST Special Publication 800-188.

Worked example

Springfield. Raw table k = 1; per-class probability of a correct pick ≤ 1/k.

Key takeaways

  • Every field must be classified as direct, quasi, sensitive, or non-identifying.
  • Equivalence-class size k is the atom of every risk metric, and Springfield's k is 1.
  • Sample uniqueness is observable; population uniqueness is what identifies people.

Coming next: Video 7, The De-identification Toolbox

Risk you can measure, you can lower. Nine statistical disclosure limitation techniques worked on Springfield, then the formal models built from attacks: k-anonymity, l-diversity, t-closeness, and differential privacy with the Laplace mechanism computed by hand. Every transformation charges a utility cost, and this video measures it.

Saved in your browser only — no account, no server.