HIPAA Limited Data Set: Identifiers, Agreements, and Penalties

A HIPAA limited data set is protected health information with 16 categories of direct identifiers removed, leaving dates, city and zip-code level geography, and other indirect information intact. A covered entity can share one for research, public health, or healthcare operations without a patient authorization, but only after signing a data use agreement with the recipient. The dataset is still protected health information under HIPAA, which is what separates it from fully de-identified data and keeps enforcement penalties on the table if it is mishandled.

The 16 Identifiers That Must Be Removed

Under 45 CFR § 164.514(e)(2), a limited data set must exclude 16 categories of direct identifiers, and the exclusion covers not only the patient but also their relatives, employers, and household members. Miss one and the dataset does not qualify.1eCFR. 45 CFR 164.514 – Other Requirements Relating to Uses and Disclosures of Protected Health Information – Section: (e)

  • Names
  • Postal address information more specific than town or city, state, and zip code
  • Telephone numbers
  • Fax numbers
  • Email addresses
  • Social Security numbers
  • Medical record numbers
  • Health plan beneficiary numbers
  • Account numbers
  • Certificate and license numbers
  • Vehicle identifiers and serial numbers, including license plate numbers
  • Device identifiers and serial numbers
  • Web URLs
  • IP addresses
  • Biometric identifiers, including fingerprints and voiceprints
  • Full-face photographs and any comparable images

What Can Stay in the Dataset

The whole reason to use a limited data set instead of stripping the file down further is that several analytically useful elements are allowed to remain:

  • Dates directly related to the individual, including birth, death, admission, and discharge dates
  • Geographic information at the level of city or town, state, county, precinct, and five-digit zip code
  • Any unique identifying code or number that is not on the list of 16 excluded categories, such as a study-assigned participant code

Keeping full dates and zip codes is what makes the data workable for tracking patterns across time and geography.1eCFR. 45 CFR 164.514 – Other Requirements Relating to Uses and Disclosures of Protected Health Information – Section: (e)

How It Differs From De-Identified Data

This distinction gets confused constantly, and the confusion has consequences. A limited data set is still protected health information. De-identified data is not. That single fact controls who can access the data, what paperwork is required, and what happens if something goes wrong.

The Safe Harbor method of de-identification removes 18 identifier categories rather than 16. The two additional requirements matter. Safe Harbor strips all date elements except year for dates related to the individual, groups ages over 89 into a single “90 or older” category, and removes all geographic subdivisions smaller than a state. The only geographic data Safe Harbor permits is the first three digits of a zip code, and only when that three-digit zone contains more than 20,000 people. The covered entity must also have no actual knowledge that the remaining information could identify anyone.2U.S. Department of Health and Human Services. Guidance Regarding Methods for De-identification of Protected Health Information in Accordance with the HIPAA Privacy Rule

HIPAA also recognizes a second de-identification route called Expert Determination, in which a qualified statistician certifies that the risk of identifying any individual is very small and documents the analysis for the Office for Civil Rights on request.2U.S. Department of Health and Human Services. Guidance Regarding Methods for De-identification of Protected Health Information in Accordance with the HIPAA Privacy Rule

Once data is truly de-identified by either method, the Privacy Rule no longer applies to it. No data use agreement is required, no restrictions on onward disclosure, no HIPAA penalties. A limited data set stays inside the HIPAA framework because it retains enough information to carry re-identification risk. If a project can run on de-identified data, that path involves far less regulatory overhead. If the analysis needs full dates or zip codes, a limited data set with a proper agreement is the route.

When Sharing Is Allowed

A covered entity can use or disclose a limited data set only for three purposes: research, public health, or healthcare operations. If the intended use does not fit one of those categories, the data cannot go out as a limited data set.3eCFR. 45 CFR 164.514 – Other Requirements Relating to Uses and Disclosures of Protected Health Information – Section: (e)(3)

Research means systematic investigation designed to develop or contribute to generalizable knowledge. Public health activities include disease surveillance, outbreak investigation, and similar work by authorized public health agencies. Healthcare operations is the broadest and most frequently misunderstood category, covering quality assessment and improvement, practitioner performance evaluation, training, medical review, legal services, fraud and abuse detection, cost-management analysis, and general administrative functions.4eCFR. 45 CFR 164.501 – Definitions

One boundary worth flagging: a researcher receiving a limited data set is not a business associate of the covered entity, and a business associate agreement is not required for this type of disclosure. The data use agreement stands on its own.5U.S. Department of Health and Human Services. Business Associates

The Data Use Agreement

No limited data set leaves a covered entity without a signed data use agreement. Under 45 CFR § 164.514(e)(4), the covered entity must obtain satisfactory assurance in writing that the recipient will only use the data for permitted purposes. The agreement has to identify the permitted uses and disclosures, name who is allowed to use or receive the data, and bind the recipient to five operational commitments.6eCFR. 45 CFR 164.514 – Other Requirements Relating to Uses and Disclosures of Protected Health Information – Section: (e)(4)

The recipient must agree to:

  • Not use or further disclose the information beyond what the agreement permits or the law requires
  • Use appropriate safeguards to prevent unauthorized use or disclosure
  • Report to the covered entity any use or disclosure outside the agreement
  • Ensure that any agents or subcontractors with access to the data agree to the same restrictions
  • Not attempt to identify the individuals in the data or contact them

The no-re-identification and no-contact requirement is absolute. Even accidental discovery of identifying information does not permit the recipient to act on it.

The covered entity’s job does not end at signature. If it learns that the recipient has violated the agreement, it must take steps to cure the violation or terminate the arrangement. If the violation cannot be cured, the covered entity must report the problem to the Department of Health and Human Services. Sitting on a known breach is itself an enforcement risk.

Penalties When the Rules Are Broken

Because a limited data set is still protected health information, mishandling it exposes the covered entity and, in some cases, individuals to the full range of HIPAA penalties.

Civil Penalties

HHS adjusts the civil penalty amounts annually for inflation. As of January 2026, the four tiers are:7Federal Register. Annual Civil Monetary Penalties Inflation Adjustment

  • No knowledge of the violation and no reasonable way to have known: $145 to $73,011 per violation, up to $2,190,294 per calendar year for identical violations
  • Reasonable cause and not willful neglect: $1,461 to $73,011 per violation, same annual cap
  • Willful neglect, corrected within 30 days of discovery: $14,602 to $73,011 per violation, same annual cap
  • Willful neglect, not corrected within 30 days: minimum $73,011 per violation, same annual cap

The gap between the third and fourth tiers is the practical lesson. Finding a problem and fixing it inside 30 days sets a floor of $14,602 per violation. Leaving it uncorrected pushes the floor to $73,011, five times higher.

Criminal Penalties

Criminal prosecution reaches individuals who knowingly obtain or disclose individually identifiable health information without authorization. The tiers scale with intent:8Office of the Law Revision Counsel. 42 USC 1320d-6 – Wrongful Disclosure of Individually Identifiable Health Information

  • Knowing violation: fines up to $50,000, up to one year in prison, or both
  • Offense committed under false pretenses: fines up to $100,000, up to five years in prison, or both
  • Offense committed for commercial advantage, personal gain, or malicious harm: fines up to $250,000, up to ten years in prison, or both

Criminal liability attaches to individuals, not only to organizations. An employee who accesses a limited data set and sells the underlying patient information faces the top tier regardless of what safeguards the employer had in place.