Video 15 · Becoming a HIPAA Qualified Expert

15. Misconceptions, FAQ, and Your Next Steps

36 min

After this video you can

  • Rebut the ten common misconceptions
  • Answer the questions clients actually ask
  • Locate the post-HIPAA overlay
  • Execute your next steps deliberately
  • Decline the engagements you should decline

Module 8: Synthesis · Runtime 36:23 · YouTube title: Ten HIPAA De-identification Myths, FAQ, and Your Next Steps

Correct these ten misconceptions on the spot and you think like an expert. Ten myths demonstrated rather than asserted, thirteen questions clients actually ask, how to decline an engagement you should not take, the overlay in one slide, staying current, and what to do in the twelve months after this course.

In this video

  • Myths one to three, then a demonstration of what Safe Harbor leaves behind
  • Myths four to six, then a demonstration of "not zero" and how to say so in writing (Apex's final 0.002)
  • Myths seven to ten, and the one root error they share
  • The questions clients actually ask, in three parts
  • How to say no: undeterminable data, pressure to move the number, public release with no agreement, each declined with alternatives
  • The overlay in one slide, staying current in a volatile field, and your next steps

Reference: the ten misconceptions

Every one of these treats de-identification as a state you achieve once, by removing things, permanently, for everybody. Every correction says the same thing: it is a documented risk analysis, bounded by a dataset, a recipient, a release context, and a window of time. (Video 15)

# Misconception The correction
1 There is a government certification for HIPAA de-identification experts There is not. OCR's guidance says no specific professional degree or certification program exists. No registry, no license, no pre-approval.
2 You need a doctorate in statistics The guidance names experience twice and a degree zero times. Doctorates are common among visible experts because they came from research careers, not because the rule requires one.
3 Safe Harbor is always the safer choice Safe Harbor is the simpler choice. It carries an actual-knowledge condition, leaves residual risk in rare combinations and free text, and destroys utility. Expert determination is often both more protective and more useful.
4 A determination lasts forever The rule sets no expiry, but practice does: typically 12 to 36 months, voided earlier by new fields, new external datasets, a changed recipient, or a changed release model.
5 Very small risk means zero risk The guidance says "very small, but it is not zero." Zero risk equals zero analytic value. The job is to justify and document the residual, not eliminate it.
6 De-identified data is still PHI and needs a BAA Properly de-identified data exits the Privacy Rule entirely. The nuance: an outside expert who handles the raw identifiable input does need a BAA.
7 Expert determination means removing the 18 identifiers really carefully The 18 categories are Safe Harbor. Expert determination classifies fields, models an adversary, chooses and cites a threshold, measures, transforms, re-measures, and documents.
8 One determination covers all our data sharing The rule names an anticipated recipient. Scope is per dataset, per recipient, per release model. The same source data can legitimately support several releases at different strictness.
9 Aggregate data is automatically safe A count of two in a small demographic band identifies people without any statistics. Agencies suppress cells below 11 and extend the rule to derived values.
10 The expert de-identifies the data The expert determines and specifies. The data holder executes in its own environment. The expert then verifies the output before signing.

Reference: the questions clients actually ask

Thirteen questions from real engagements, with the short answers the course gives. (Video 15)

  1. Will OCR approve the determination? No. No pre-clearance mechanism exists. What exists is the record you create, examined afterward.
  2. Can you certify our organization as HIPAA compliant? No. A determination attaches to a dataset and a release, not to an organization.
  3. Can you sign off on a dataset we released last quarter? You can assess it and document what you find. You cannot write a determination that pretends to have existed before the release.
  4. Does this cover our other data sharing? No. Scope is per dataset, per recipient, per release model.
  5. Can marketing describe the data as anonymous? No. "Anonymous" implies zero risk, which the guidance denies, and a public claim the practice cannot support is itself the exposure. "De-identified in accordance with the HIPAA expert determination method" is accurate.
  6. What if the recipient re-identifies it anyway? If the recipient is an independent third party, that is not a HIPAA violation and OCR has no jurisdiction. That is why the contractual envelope is part of the deliverable.
  7. How often do we redo this? On triggers first, the calendar second. Typical validity is 12 to 36 months.
  8. Are you allowed to say no? Yes. Decline when the client wants a number rather than an analysis, will not show you the data or the recipient agreement, or intends to describe your work in words you would not sign.
  9. How much will this cost? Not priceable before scoping: data elements, unstructured text, release model, recipient count. Published fees are anecdotal and range enormously. Quote a scoping call.
  10. How long will it take? Weeks to a few months. The driver is the client's ability to produce the file, the agreement, and a decision maker.
  11. Can you sign off on the pipeline our vendor built? You can review it as its own engagement. You cannot adopt their conclusion; if you sign, the analysis becomes yours.
  12. What happens if we get audited? OCR asks for the documentation. Your client should be able to produce the technical report, the attestation, and the DUA without calling you.
  13. Can we re-identify later if we need to? A covered entity may retain a re-identification code under §164.514(c). The moment it is used the data is PHI again, and a downstream recipient doing the same may be unlawful under state law even where HIPAA permits it.

After the course: your next steps

The course ends with a checklist. (Video 15, drawing on Video 11)

  1. Work a ten-row table of your own. Build it, classify it, compute equivalence classes and k, apply the three risk models, generalize and suppress, and re-measure. Do it until the arithmetic is boring.
  2. Build your templates. A report skeleton with the ten sections and a threshold paragraph you can adapt, before you have a client.
  3. Start the 24-month pathway. Foundational calibration, supervised applied work, the synthetic-data frontier, then independence. Find an honest broker office, a disclosure review board, or a privacy engineering team where you compute before you sign.
  4. Set a quarterly law review. Re-read the 2012 guidance yearly, follow new attack publications, and track state law every quarter. The 2024 federal rule that was vacated in 2025 is the reason this is mandatory.
  5. Adopt the standing rule. Do not sign a determination you could not defend, line by line, to a hostile reviewer two years from now.

Key takeaways

  • The ten misconceptions all collapse into one truth: expert determination is documented risk analysis.
  • Leaving HIPAA is not leaving the law, and Video 14 maps what waits on the other side.
  • Your next step is deliberate practice, because experience is the only credential the rule names.

Saved in your browser only — no account, no server.