---
title: How does data de-identification work?
description: By de-identifying data that includes protected health information (PHI), your business can limit the scope of liability under HIPAA. Learn more about achieving compliance with data protection laws through a de-identification process in this blog post.
image: https://safe.truevault.com/hubfs/Blog%20Images/Holypsud....png
---

<https://safe.truevault.com/>

- [CCPA](https://safe.truevault.com/learn/ccpa/what-is-the-ccpa)
- [GDPR Compliance](https://safe.truevault.com/gdpr-guide)
- [HIPAA](https://safe.truevault.com/learn/hipaa)
- [HIPAA Compliance](https://safe.truevault.com/blog/hipaa-compliance-checklist-download.html)
- [Personally Identifiable Information](https://safe.truevault.com/blog/what-is-pii)
- [PHI](https://safe.truevault.com/protected-health-information)

- [Resources](https://safe.truevault.com/learn/)
- Login
  
  [TrueVault Safe Log in to TrueVault Safe](https://console.truevault.com) [TrueVault Polaris Log in to TrueVault Polaris](https://polaris.truevault.com)

- [Resources](https://safe.truevault.com/learn/)
- Login

- Login
- [TrueVault Safe Log in to TrueVault Safe](https://console.truevault.com)
- [TrueVault Polaris Log in to TrueVault Polaris](https://polaris.truevault.com)

[Blog](https://safe.truevault.com/blog)

- [Home](https://www.truevault.com/index.html)
- [Blog](https://safe.truevault.com/blog)

![<span id="hs_cos_wrapper_name" class="hs_cos_wrapper hs_cos_wrapper_meta_field hs_cos_wrapper_type_text" style="" data-hs-cos-general-type="meta_field" data-hs-cos-type="text" >How does data de-identification work?</span>](https://safe.truevault.com/hubfs/Blog%20Images/Holypsud....png)

# How does data de-identification work?

By Sara Kassabian/ Published on October 16, 2018

Previously, we answered a commonly asked question: What constitutes as protected health information (PHI)? This time, we take our series a step further, and explain how de-identifying PHI will allow your business to work with health behavior data without liability.

Let’s return to the original equation:

PHI = Personally Identifiable Information (PII) + health information.

Most companies only need the health information component. The PII is extraneous. By [de-identifying the data](https://blog.truevault.com/data-de-identification-an-easier-way-to-hipaa-compliance.html) (i.e., removing the PII from the equation), the liability for businesses working with health data is dramatically reduced. Below is a hypothetical example that casts the roles of Covered Entity, Business Associate, and Data Subject in a de-identification scenario.

## De-identifying PHI in Gotham City

In our example: ACME Research is the Business Associate; Gotham City Department of Health is the Covered Entity.

Now, let’s say the Gotham City Department of Health (Covered Entity) hired ACME Research (Business Associate) to conduct an epidemiological study about the prevalence of PTSD in the city.

Traditionally, ACME Research would receive full patient records, which is PHI, from Gotham City Department of Health to begin its analysis. Because it is handling PHI, ACME Health is forced to accept the full compliance requirements of HIPAA.

But the reality is, ACME does not need patients' full medical record, which includes PII such as their name and exact address, to conduct their research. ACME only needs non-identifying demographic and medical information to stratify the data in search of trends. In other words, ACME is taking on compliance and data security burdens unnecessarily.

## Holy pseudonymization, Batman!

By removing the PII from the health information, a process called pseudonymization (or more generally, de-identification, tokenization), the researchers at ACME no longer have to worry about having PHI in their system, because the de-identified data does not confer the same levels of protection under HIPAA.

![bruce-wayne-deidentified (1)](https://safe.truevault.com/hs-fs/hubfs/bruce-wayne-deidentified%20(1).png?width=300&name=bruce-wayne-deidentified%20(1).png)

Let’s explore an example of patient record:

Bruce Wayne is diagnosed with PTSD = PHI

Next, we pseudonymize it.

“Patient J^g7xz(3hG9!?6x is diagnosed with PTSD” is not PHI because the PII has been stripped from the data. Now, it is just health data that ACME Health can use for their study without ever having to worry about building a HIPAA compliant application in which to store it.

 Store the PHI in TrueVault

Even after the health data is de-identified, the original, identifying medical information ought to be stored somewhere that is HIPAA compliant and secure so it can be re-identified later if needed.

This is where [Business Associate Agreements (BAA)](https://safe.truevault.com/resources/compliance/what-is-a-business-associate) come into play.

ACME Research may not have the resources to build their own HIPAA compliant application to store the PHI that drives their business. The company can sign a BAA with a company like TrueVault to accomplish their business goals without having to worry about HIPAA compliance.

To help ACME Research achieve its goal and limit the scope of HIPAA compliance for the company, TrueVault would use our [Tokenization Engine](https://blog.truevault.com/tokenization-engine) to do the following:

1. Tokenization Engine will collect the data from Gotham City Department of Health on behalf of ACME health, which includes the medical record for Bruce Wayne: “Bruce Wayne is diagnosed with PTSD.”
2. Tokenization Engine will de-identify the data, so it now reads “Patient J^g7xz(3hG9!?6x is diagnosed with PTSD”. The PII is stored in our SecureVault or removed entirely, whichever ACME Research prefers.
3. Tokenization Engine will then send the de-identified data to ACME.

TrueVault inherits our clients’ risk by transferring and/or storing all PHI in SecureVault, our HIPAA compliant data solution. Because the PHI will never touch ACME Research's servers, the scope of compliance concerns for the company is limited. Our team keeps up with the laws governing PHI to ensure that our clients alway stay compliant with federal regulation.

### Latest Posts

## [Should Utah's Privacy Law Be on Your Radar?](https://safe.truevault.com/blog/utah-privacy-law-does-it-apply)

 Phillip Walters  / November 17, 2022

## [Connecticut’s Privacy Law: Does It Apply to Your Business?](https://safe.truevault.com/blog/connecticut-privacy-law-does-it-apply)

 Phillip Walters  / November 10, 2022

## [Global Privacy Control: A New Requirement for Compliance](https://safe.truevault.com/blog/global-privacy-control)

 Phillip Walters  / November 7, 2022

## [A Cookie Banner Isn't Enough for CCPA Compliance](https://safe.truevault.com/blog/a-cookie-banner-isnt-enough)

 Phillip Walters  / October 27, 2022

## [Why CCPA Compliance Matters to HR](https://safe.truevault.com/blog/why-ccpa-matters-to-hr)

 Phillip Walters  / October 21, 2022

### Mailing List

### Company

- [Blog](https://safe.truevault.com/blog)
- [Contact Us](https://safe.truevault.com/contact-us-2019)
- [Careers](https://truevault.workable.com)
- [HIPAA Compliance Checklist](https://safe.truevault.com/blog/hipaa-compliance-checklist-download.html)
- [PDF: Developers Guide to HIPAA compliance](https://my.leadpages.net/leadbox/14472b173f72a2%3A131fd12f8b46dc/5760820306771968/)

### Developers

- [Patterns](https://safe.truevault.com/patterns)
- [Documentation](https://docs.truevault.com/)
- [Quick Start Guide](https://safe.truevault.com/quick-start-guide)
- [Secure Infrastructure](https://safe.truevault.com/secure-infrastructure)
- [API Overview](https://safe.truevault.com/api-overview)

### Latest Posts

### Contact Us

201 Mission Street, 12th Floor  
 San Francisco, CA 94105  
 Email: [hello@truevault.com](mailto:hello@truevault.com)

2024 © All Rights Reserved.  [Privacy Policy](https://privacy.truevault.com/privacy-policy)  |  [Terms of Use](https://www.truevault.com/legal/truevault-terms-of-use)  |  [Supplemental Terms](https://www.truevault.com/legal/truevault-supplemental-terms-of-use)<https://www.truevault.com/legal/truevault-terms-of-use> | [California Privacy Notice](https://privacy.truevault.com/privacy-policy#california-privacy-notice)