5. Very Small Risk: The Three Principles
After this video you can
- Explain why no numeric threshold exists
- Apply the three risk principles
- Name the guidance's transformation techniques
- Explain expiry, retention, and agreements
- State the guidance's known blind spots
Module 2: The OCR 2012 Guidance · Runtime 46:25 · YouTube title: Very Small Risk in HIPAA: The Three Principles OCR Requires
The regulator never gives you a number, only three principles. This video teaches replicability, data source availability, and distinguishability as the analytic engine of every determination, then covers the guidance's transformation classes, expiry, data use agreements, and the six-year retention duty.
In this video
- Why "very small" has no number, and why it is never zero
- Principle one, replicability: will the feature recur? Principle two, availability: which outside data holds it? Principle three, distinguishability: how many people share these values?
- The anticipated-recipient triad: resources, motives, existing knowledge
- Three mitigation classes from the guidance: suppression, generalization, perturbation, and the remnant risk when they overlap
- Multiple solutions from one dataset, and data use agreements as a weighable control
- Why determinations expire, cyclical governance for ongoing feeds, and the §164.530(j) six-year retention duty
Authorities quoted on screen
HHS OCR De-identification Guidance (2012), including the sentence "The greater the replicability, availability, and distinguishability of the health information, the greater the risk for identification"; 45 CFR §164.530(j).
Key takeaways
- Very small risk has no universal number; the expert sets and defends a contextual threshold.
- Replicability, availability, and distinguishability are the analytic engine of every determination.
- Transformations, expiry dates, agreements, and a six-year retention clock surround every opinion you sign.
Coming next: Video 6, Identifiers, Quasi-identifiers, and Uniqueness
Nobody's name needs to be in a dataset for the dataset to name them. This is where the statistics start: the NIST identifier taxonomy, equivalence classes and k computed by hand on the Springfield table, sample versus population uniqueness, the Zayatz and Pitman estimators, and the places identifiers hide.
Saved in your browser only — no account, no server.