13. The Determination Report and Liability
After this video you can
- Source every report section to authority
- Draft all ten sections in prose
- Write a seven-part attestation letter
- Manage validity, governance, and liability
Module 7: Practice · Runtime 48:52 · YouTube title: The HIPAA Determination Report and Expert Liability Explained
The report is the product, not the data transformation. All ten sections of the technical report are drafted in prose, each traced to an authority, followed by the seven-part attestation letter with sample language, validity periods and refresh triggers, the contractual envelope, liability and insurance, independence, disclosure review boards, and how a determination gets tested.
The ten sections of the technical report
- Expert qualifications, with a full CV attached
- Dataset description and scope, structured fields distinguished from free text
- Context and recipient assessment: release model, architecture, DUA clauses, recipient motives and capabilities
- Identifier classification dictionary, every field tagged
- Threat modeling: adversary models and background-knowledge assumptions
- Risk threshold and its justification, with citation
- Baseline risk measurement, estimator and population source named
- Mitigation methods and parameters: generalization hierarchies, suppression rules, date-shift ranges, text redaction approach
- Post-mitigation quantitative results
- Conditions, limitations, validity period, and signature, with residual risk stated and never called zero
The seven-part attestation letter
A. Statutory invocation · B. Expert identity, competence, and independence · C. Scope and dataset definition · D. Methodology overview without the math · E. The "very small risk" conclusion in the rule's own words · F. Conditions of validity and expiration · G. Signature and date
In this video
- Where the ten sections come from: OCR guidance, NIST 800-188, El Emam, CalHHS, CSIRO Data61
- Public templates: CalHHS Appendix B, NIST 800-188 structure, the CSIRO and UK decision-making frameworks; why full reports are essentially never public
- Inside the Apex report: about 60 pages archived and not circulated, a 2-page attestation, 24 months validity
- Drafting sections one to three in prose, then four to six, seven to nine, and ten
- Validity periods (typically 12 to 36 months) and the triggers that void a determination early
- What the contractual envelope adds: the FTC three-part test, California Civil Code §1798.148, 42 CFR Part 2
- Liability: the determination is professional opinion, failed de-identification is the covered entity's breach; DUA, indemnity, liability cap, and errors-and-omissions cover as four separate instruments
- Independence, the internal expert, disclosure review boards, and the three ways a determination gets tested
Authorities quoted on screen
HHS OCR De-identification Guidance (2012); NIST SP 800-188; CalHHS Data De-Identification Guidelines (Appendix B template); CSIRO Data61 De-Identification Decision-Making Framework; FTC Act §5 and the 2012 privacy report; California Civil Code §1798.148; 42 CFR Part 2.
Key takeaways
- The report is the product, and every section traces to an authority.
- Draft for reproducibility; the attestation circulates, the report is archived.
- Liability is allocated by contract and insurance; defensibility is earned by documentation.
Coming next: Video 14, Beyond HIPAA: The Regulatory Overlay
De-identified data exits HIPAA, but that is a boundary, not a shield. The FTC three-part test prong by prong, the GoodRx, BetterHelp, Premom, Kochava, and Outlogic actions, eight state statutes that codify the test, California AB 713, Washington My Health My Data, 42 CFR Part 2, the Common Rule, genomics, clinical trial transparency, the tracking-pixel litigation, and the 2024 rule that was vacated in 2025.
Saved in your browser only — no account, no server.