Can "anonymized" health data still identify you?
“Don’t worry, the data is anonymized.” Anyone who shares health data has heard this. The mechanism behind it is weaker than it sounds.
How de-identification is supposed to work
Under HIPAA, the central mechanism for enabling research on health records is de-identification: strip the 18 listed identifiers (names, addresses below state level, almost all dates, ID numbers and the like), or have an expert certify that the re-identification risk is “very small”, and the record is no longer protected health information. It can then be shared without the patient’s authorisation. The assumption is that without identifiers, the record no longer points back to a person.
Why it fails
Removing direct identifiers is not enough. A systematic review of re-identification attacks found that about a quarter of records were re-identified on average, a third in the health-data attacks, almost always in datasets that had only been stripped of names and other direct identifiers rather than de-identified to a formal standard. Later work showed that 15 demographic attributes are enough to re-identify 99.98% of Americans. A birth date here, a postcode there, a rare diagnosis, an admission date: none of these is a name, but together they can narrow a record down to one person.
Breaches of protected health information reported to the US federal regulator since 2009 had, by the end of 2025, exposed the records of more than one billion people (people are counted once per breach, so the total is not a count of distinct persons). Once a de-identified dataset leaks, anyone holding other data about you can attempt the combination.
The trade-off
The standard response to re-identification risk is to strip more: coarser dates, broader regions, fewer fields. But every field removed also removes scientific value, and the usual institutional response, tightening rules and access controls, has slowed research without clearly improving privacy: two-thirds of US epidemiologists surveyed said the HIPAA Privacy Rule had made research more difficult while only a quarter thought it had enhanced participants’ privacy, and Finland’s secondary-use law was followed by an estimated 47% drop in new data permits in 2023. De-identification asks one mechanism to deliver privacy and research value at the same time, and it delivers neither fully.
The alternative: consent instead of anonymisation
There is another way to make health data usable for research: don’t pretend it isn’t personal. Keep the record whole, under the person’s control, and let research happen through explicit, revocable consent, with every access logged.
Health Data Safe is built this way: data stays under the patient’s control on open-source infrastructure, a researcher’s access requires a time-limited, purpose-specific consent record, and every access event is logged with the accessor’s identity and scope. Nothing is stripped from the record, so it keeps its full scientific value; the protection comes from governance.
See How it works for the mechanics, or read how this compares to the laws protecting health data in Europe.
Sources
- U.S. Code of Federal Regulations, 45 CFR § 164.514, Standard: de-identification of protected health information (Safe Harbor and Expert Determination). ecfr.gov
- El Emam K, Jonker E, Arbuckle L, Malin B (2011). A systematic review of re-identification attacks on health data. PLoS ONE 6(12): e28071. doi:10.1371/journal.pone.0028071
- Rocher L, Hendrickx JM, de Montjoye Y-A (2019). Estimating the success of re-identifications in incomplete datasets using generative models. Nature Communications 10: 3069. doi:10.1038/s41467-019-10933-3
- U.S. Department of Health and Human Services, Office for Civil Rights. Breach Portal: breaches of unsecured protected health information affecting 500 or more individuals (2009 to present). ocrportal.hhs.gov
- Ness RB (2007). Influence of the HIPAA Privacy Rule on health research. JAMA 298(18): 2164–2170. doi:10.1001/jama.298.18.2164
- Brück O, Sanmark E, Ponkilainen V, et al. (2024). European health regulations reduce registry-based research. Health Research Policy and Systems 22: 135. doi:10.1186/s12961-024-01228-1