Glossary
What is de-identification?
De-identification is the general process of removing or transforming the details in a record that identify a person: removing direct identifiers such as names and ID numbers, and reducing quasi-identifiers such as dates, locations and occupations. It is an umbrella term. Pseudonymization is one form; anonymization is the irreversible end of it. A de-identified record can still be re-identified if enough detail remains.
Last reviewed · 4 sources
What the standards include
HIPAA's Safe Harbor method is one concrete de-identification recipe: it removes a list of identifiers "of the individual or of relatives, employers, or household members", from names and "all geographic subdivisions smaller than a State" to "all elements of dates (except year)". Ontario's IPC guidelines take a risk-based approach instead, classing variables as direct identifiers or quasi-identifiers and transforming each accordingly.
NIST SP 800-188 prefers the word de-identification to anonymization because of the inconsistent ways "anonymization" is used.
Common techniques
- Removal or masking of direct identifiers
- Replacement with pseudonyms (pseudonymization)
- Generalization: an age range instead of a birth date, a region instead of a city
- Top and bottom coding of outliers, such as HIPAA's "90 or older"
- Suppression of rare values that single someone out
Its limit
De-identification reduces risk; it does not end it. The Article 29 Working Party's opinion on anonymisation techniques shows how partial values, such as the first digits of a postcode, can still place a person.
Where PiBye fits
How PiBye handles this
PiBye de-identifies client documents by pseudonymization on your Mac and shows you every replacement, so you can reduce the quasi-identifiers a specific task does not need before the copy goes to an AI.
1.0.1 · macOS 14.8.5 or later · Apple Silicon · 1.1 GB
Frequently asked questions
Is de-identified data the same as anonymous data?
No. De-identified data may still be reversible or re-identifiable. Anonymous data is the narrower, irreversible case.
Does HIPAA de-identification apply to a law firm?
HIPAA governs covered entities and their business associates. Its Safe Harbor list is still a useful, concrete reference for which details identify people.
Sources
- 45 CFR § 164.514: other requirements relating to uses and disclosures of protected health information, Legal Information Institute, Cornell Law School. Checked 25 September 2026.
- De-identification Guidelines for Structured Data, Information and Privacy Commissioner of Ontario, June 2016. Checked 25 September 2026.
- NIST SP 800-188: De-Identifying Government Datasets, National Institute of Standards and Technology, September 2023. Checked 25 September 2026.
- Opinion 05/2014 on Anonymisation Techniques (WP216), Article 29 Data Protection Working Party, April 10, 2014. Checked 25 September 2026.