skills/clinical-reports/references/privacy_and_deidentification.md
This reference documents a review process. It is not legal advice, a technical de-identification service, or evidence of HIPAA compliance.
HHS guidance under 45 CFR 164.514(b) describes two methods:
A local script cannot perform Expert Determination, establish “no actual knowledge,” or decide whether an organization is a covered entity or business associate.
The responsible privacy professional must review the exact regulation and HHS guidance. The categories include:
Removal of obvious patterns is insufficient. Initials, partial identifiers, metadata, free text, rare events, small cells, unusual dates, images, and combined quasi-identifiers may still identify a person.
HHS states that covered entities generally take reasonable steps to limit uses, disclosures, and requests for PHI to the minimum necessary for the purpose. HHS also lists exceptions, including certain treatment disclosures, disclosures to the individual, authorized uses/disclosures, uses/disclosures required for HIPAA administration, HHS enforcement, and uses/disclosures required by law.
Do not apply the phrase mechanically. The responsible privacy/legal reviewer determines scope, exceptions, authorization, waiver, limited-data-set rules, and any more protective law or policy.
assets/deidentification_process_checklist.json and scripts/check_deidentification.py verify that required process fields are documented. They deliberately:
COMPLIANT, SAFE, or DEIDENTIFIED;The strongest successful result is PROCESS_DOCUMENTED_REVIEW_REQUIRED.
Publication consent, research consent, HIPAA authorization, IRB/Privacy Board waiver, and permission to use an image are distinct. Do not infer one from another or generate a stock assertion.
Record only the status and local documentation reference verified by the responsible human. Never store a signed consent form or direct identifier in this skill’s assets, tests, or example manifests.
If real PHI is unexpectedly present: