PII may be used alone or with other sources to identify an individual. PII in conjunction with medical records (including payments for medical care) becomes Protected Health Information (PHI).
- Name (including initials)
- Address (all geographic subdivisions smaller than state: street address, city, county, zip code)
- All elements (except years) of dates related to an individual (including birthdate, admission date, discharge date, date of death, and exact age if over 89)
- Telephone numbers
- Fax number
- Email address
- Social Security Number
- Medical record number
- Health plan beneficiary number
- Account number
- Certificate or license number
- Any vehicle identifiers, including license plate
- Device identifiers and serial numbers
- Web URL
- Internet Protocol (IP) Address
- Finger or voice print
- Photographic image - Photographic images are not limited to images of the face
- Any other characteristic that could uniquely identify the individual
A data set containing any of these identifiers, or parts of the identifier, is considered “identified” |
A Limited Data Set must omit all of the HIPAA Identifiers in the left-hand column except for the following:
- City, state, zip code
- Dates of admission, discharge, service, date of birth, date of death
Ages in years, months or days or hours To re-iterate: initials are always considered PHI/PII
HIPAA – De-identified Data
All of the 18 HIPAA Identifiers in the left-hand column must be removed in order for a data set to be considered de-identified with caveats for the following:
- All geographic subdivisions smaller than a state, except for the initial three digits of the ZIP code: (1) The geographic unit formed by combining all ZIP codes with the same three initial digits contains more than 20,000 people; and (2) The initial three digits of a ZIP code for all such geographic units containing 20,000 or fewer people is changed to 000;
Ages in years and for those older than 89, all ages must be aggregated into a single category of 90 or older
|
In the context of FERPA, PII includes, but is not limited to:
- Student’s name
- The name of the student’s parent(s) or other family members
- Address of the student or student’s family
- Student’s personal identifiers, such as:
- Social Security Number;
- Student number; or
- Biometric record (i.e. Finger or voice print)
- Student’s other indirect identifiers, such as:
- Birthdate;
- Place of birth; or
- Mother’s maiden name
- Other information that, alone or in combination, is linked or linkable to a specific student that would allow a reasonable person in the school community, who does not have personal knowledge of the relevant circumstances, to identify the student with reasonable certainty
- Information requested by a person who the educational agency or
institution reasonably believes knows the identity of the student to whom the education record relates |