HIPAA Redaction: How to Remove PHI from Medical Records
HIPAA redaction means permanently removing protected health information (PHI) from a document before you share it. Under the HIPAA Privacy Rule, health information only falls outside the rules once it is properly de-identified — by removing all 18 Safe Harbor identifiers or through a documented Expert Determination (45 CFR § 164.514). A black box that merely covers the text achieves neither, because the text underneath usually survives inside the PDF.
Key takeaways
- PHI is individually identifiable health information held or transmitted by a covered entity or its business associate, in any form — electronic, paper, or oral.
- HIPAA accepts two de-identification methods: Safe Harbor (remove 18 identifier categories) and Expert Determination (documented analysis showing very small re-identification risk).
- Properly de-identified information is no longer restricted by the Privacy Rule; poorly redacted information still is.
- A black rectangle drawn over text is not redaction — the text layer underneath can often still be selected, copied, and searched.
- Redacting locally in your browser means the document never reaches a third-party server — one less copy that can leak.
What counts as PHI under HIPAA?
Protected health information (PHI) is individually identifiable health information that a HIPAA-covered entity or its business associate holds or transmits, in any form or media — electronic, paper, or oral. That is the definition the U.S. Department of Health and Human Services (HHS) uses in its Summary of the HIPAA Privacy Rule.
Three elements matter in practice:
- It relates to health: a past, present, or future physical or mental condition, the care received, or payment for that care.
- It identifies the person — or could: it names the individual, or there is a reasonable basis to believe it can be used to identify them.
- It sits with a covered entity: a health plan, healthcare clearinghouse, or provider that conducts certain transactions electronically — or with their business associates.
In a typical medical record, PHI is everywhere: name, address, date of birth, Social Security number, medical record number, insurance details, test results, diagnoses, clinician notes. A diagnosis floating free is not PHI; a diagnosis tied to an identifiable person is.
HIPAA formally binds covered entities and their business associates, but its definitions travel further: lawyers preparing discovery, insurers, researchers, and patients forwarding their own files all treat the 18-identifier list as the working standard for what to remove before a medical document changes hands.
What is the HIPAA de-identification standard?
Health information stops being PHI when it no longer identifies anyone, and the Privacy Rule accepts exactly two ways to get there, set out in 45 CFR § 164.514: Expert Determination and Safe Harbor. Once information is properly de-identified, HHS is explicit that there are "no restrictions on the use or disclosure of de-identified health information."
The two methods work very differently:
| Safe Harbor | Expert Determination | |
|---|---|---|
| Legal basis | 45 CFR § 164.514(b)(2) | 45 CFR § 164.514(b)(1) |
| What it requires | Remove all 18 listed identifier categories; have no actual knowledge that what remains could identify the individual | A person with appropriate knowledge of accepted statistical and scientific methods determines the re-identification risk is very small, and documents methods and results |
| Who does it | Anyone who can follow the checklist | A qualified expert, often a statistician |
| Cost and effort | Low; mechanical | Higher; specialist work |
| Data detail kept | Blunt — dates, ZIP codes, and ages over 89 are heavily generalized | Often better — the expert can keep more detail where the risk stays small |
| Typical use | Releasing documents and records | Research datasets where dates and geography matter |
Which method fits depends on the purpose. Safe Harbor destroys the fields researchers often need most — dates and geography — so large studies pay for Expert Determination. For a clinic, employer, or law firm releasing documents, Safe Harbor is the practical route because anyone can execute the checklist.
Note that not every disclosure requires full de-identification. Records shared under a patient's written authorization or a court order follow their own permissions, tempered by the Privacy Rule's minimum-necessary standard: do not disclose more than the purpose requires. Redaction is how you enforce that limit on an actual document.
The 18 Safe Harbor identifiers: a redaction checklist
Under the de-identification Safe Harbor (45 CFR § 164.514(b)(2)), you must remove 18 categories of identifiers — the patient's, and also those of the patient's relatives, employers, and household members. HHS lists them as:
- Names
- All geographic subdivisions smaller than a state: street address, city, county, precinct, ZIP code, and equivalent geocodes (the first three ZIP digits may remain if that three-digit area contains more than 20,000 people; otherwise they become 000)
- All elements of dates (except year) directly related to the individual — birth date, admission date, discharge date, date of death — and all ages over 89, which must be aggregated into a single "90 or older" category
- Telephone numbers
- Fax numbers
- Email addresses
- Social Security numbers
- Medical record numbers
- Health plan beneficiary numbers
- Account numbers
- Certificate and license numbers
- Vehicle identifiers and serial numbers, including license plate numbers
- Device identifiers and serial numbers
- Web URLs
- IP addresses
- Biometric identifiers, including fingerprints and voiceprints
- Full-face photographs and any comparable images
- Any other unique identifying number, characteristic, or code
Two categories surprise almost everyone: dates (everything except the year must go) and geography (even a ZIP code is too specific unless the three-digit exception applies). A redaction pass that only caught names and Social Security numbers has not de-identified anything.
Removing the 18 categories is necessary but not sufficient: you must also have no actual knowledge that what remains could identify the person, alone or combined with other information. A note reading "the mayor's 12-year-old son" contains no name and still fails. Item 18 is the catch-all — a rare diagnosis or an unusual occupation can single someone out as surely as a phone number.
Why is a black box not de-identification?
Drawing a black rectangle over PHI hides it on screen — it does not remove it from the file. A PDF stores text separately from graphics: an annotation or drawn shape sits on top of the text layer, so the "redacted" name is still selectable, searchable, and available to anyone who copies the page into a text editor. This is the most common redaction failure — in short, a black box is not redaction.
Medical records add two traps:
- Scanned records with OCR. Many EHR exports and scanned charts carry an invisible OCR text layer. Cover the image, and the invisible text stays behind.
- Metadata. A PDF can carry author, title, and creation tool in fields no page displays, leaking PHI without a single visible word — removing metadata from the PDF is part of the job.
Real PHI redaction removes information instead of covering it: delete the underlying text objects, or rasterize the page into a flat image in which the covered content no longer exists. Rasterization is the blunt, verifiable option — there is no text layer left to leak.
What happens when PHI leaks?
A breach of unsecured PHI triggers the HIPAA Breach Notification Rule: notify every affected individual, report to HHS (within 60 days when 500 or more people are affected), and for breaches affecting more than 500 residents of a state, notify prominent media. The HITECH Act also requires HHS to publish breaches of 500 or more on a public portal — where journalists and plaintiffs' lawyers read them.
Enforcement is real money. In 2018, Anthem paid $16 million to HHS's Office for Civil Rights — a record HIPAA settlement — after cyberattackers stole the electronic PHI of almost 79 million people, then the largest U.S. health data breach in history. The scale has only grown: the February 2024 ransomware attack on Change Healthcare exposed the health data of an estimated 190 million people, the largest healthcare data breach on record.
Those were hacking incidents, not redaction mistakes — but they frame the risk calculus for HIPAA redaction work. Every copy of a record on someone else's server is a copy you no longer control, including the one created when a medical document is uploaded to a web tool to "quickly black something out." A document that never leaves your device cannot end up in anyone else's breach notification.
A practical HIPAA redaction workflow
When you redact medical records for release, a defensible workflow has six steps — and none of them involves uploading the record anywhere:
- Work on a copy. Keep the original record intact and untouched.
- Decide what must go before you start. For a de-identified release, that is all 18 Safe Harbor categories; for a disclosure under authorization or court order, map redactions to what the recipient is entitled to see (minimum necessary).
- Mark every instance, then do a second pass. PHI hides in headers, footers, fax cover sheets, lab-report margins, and handwritten notes, not just the obvious fields.
- Export with a method that destroys data, not one that covers it. Use true redaction or a rasterizing export in a PDF redaction tool that processes files locally — never a drawing tool's rectangle.
- Remove metadata on export. Title, author, and creation-tool fields must go with the page content.
- Verify the output. Open the exported file, select all, copy, paste into a text editor, and search for the patient's surname and record number. If anything appears, the redaction failed.
You can run this entire workflow in SladdPDF, a free browser-based redaction tool. It processes files locally with JavaScript and WebAssembly — nothing is uploaded to any server, and it works offline once the page has loaded. Secure mode rasterizes each page on export, destroying the underlying text, layers, and hidden objects, and metadata can be stripped in the same pass.
Two honest caveats. The free version exports at standard resolution; print-quality 300 DPI export needs a Pro license — there is no page limit. And SladdPDF is a general-purpose redaction tool, not a certified healthcare product — no such certificate exists anyway: HHS states plainly that it does not certify any product as "HIPAA compliant." What makes a disclosure compliant is your process: knowing what counts as PHI, removing all of it, verifying the result. A tool's job is to make the removal permanent and keep the file on your device.
This article is general guidance, not legal advice.
Redact PHI without uploading anything
SladdPDF runs entirely in your browser — files are never uploaded to a server. Free with no page limit; Pro unlocks high-resolution 300 DPI export.
Redact a PDF nowFrequently asked questions
What is the difference between redaction and de-identification?
Redaction removes specific content from a single document. De-identification is HIPAA's legal standard for health information that no longer identifies anyone. Under 45 CFR § 164.514 there are only two ways to get there: remove all 18 Safe Harbor identifiers, or have a qualified expert document that the re-identification risk is very small. A document with a few names blacked out is redacted, but usually not de-identified.
What are the 18 HIPAA identifiers?
Names; geographic units smaller than a state; dates (except year) and ages over 89; telephone numbers; fax numbers; email addresses; Social Security numbers; medical record numbers; health plan beneficiary numbers; account numbers; certificate and license numbers; vehicle identifiers; device identifiers; URLs; IP addresses; biometric identifiers; full-face photographs; and any other unique identifying number, characteristic, or code. All 18 must be removed for Safe Harbor de-identification.
Is covering PHI with a black box enough for HIPAA?
No. A drawn rectangle only hides text visually; the text layer underneath usually remains in the PDF and can be selected, copied, or extracted. Proper redaction deletes the underlying text or rasterizes the page to a flat image, and also removes document metadata. Several public redaction failures have happened exactly this way.
Do I need to redact records a patient requests about themselves?
Generally no. HIPAA's right of access (45 CFR § 164.524) gives patients broad access to their own records, and disclosures to the individual are exempt from the minimum-necessary standard. Redaction becomes relevant when records go to third parties — courts, insurers, researchers, employers — or when a record contains information about other people.
Is SladdPDF HIPAA certified?
No, and no software is: HHS does not certify any product as HIPAA compliant. SladdPDF is a general-purpose redaction tool, not a healthcare product. Its advantage is architectural: files are processed locally in your browser and never uploaded, so no third party receives the document. Compliance always depends on your own process. The free version redacts with no page limit; Pro unlocks high-resolution 300 DPI export.
- HHS — Guidance Regarding Methods for De-identification of Protected Health Information in Accordance with the HIPAA Privacy Rule
- HHS — Summary of the HIPAA Privacy Rule
- HHS — Breach Notification Rule
- HHS — Minimum Necessary Requirement
- HHS — Individuals' Right under HIPAA to Access their Health Information, 45 CFR § 164.524
- HHS — What You Should Know About OCR HIPAA Privacy Rule Guidance Materials (no product certification)
- HHS — Anthem Pays OCR $16 Million in Record HIPAA Settlement Following Largest Health Data Breach in History (October 15, 2018)
- HHS Office for Civil Rights — Breach Portal: breaches of unsecured PHI affecting 500 or more individuals
- HIPAA Journal — 2024 Healthcare Data Breach Report