De-identification is harder than it looks
De-identification is harder than it looks
Teams evaluating ambient scribes — or any workflow that sends clinical text to a vendor — often reach for a comforting sentence: “We’ll just de-identify it.” Under HIPAA, de-identification is a method, not a feeling. Getting it wrong means you still have protected health information (PHI) and still need the agreements and safeguards that go with PHI.
Educational post only. clinicgpt.ai offers no BAA and does not process PHI as a product. Official rules live at HHS, not on this blog.
Two methods, not infinite vibes
HHS describes two de-identification paths in its guidance on methods for de-identification of PHI (HHS de-identification guidance; as of 2026-07-21):
Expert Determination. A person with appropriate knowledge of statistics and re-identification risk documents that the risk is very small for the intended use. This is real work with a real memo — not a Slack emoji.
Safe Harbor. Remove enumerated identifiers (names, many geographic details, elements of dates tied to an individual, contact and device numbers, full-face photos, and the rest of the HHS list) and have no actual knowledge that the remaining information could identify the person.
If you cannot point to one of these methods as actually performed, you should assume the data is still PHI.
Why clinical transcripts fight you
Voice is identifying. Even when a transcript has no name, audio may. “De-identified transcript” does not automatically mean “de-identified recording.”
Dates leak. Visit dates, ages over 89 rules, admission timelines — Safe Harbor is picky about dates for a reason.
Rare combinations re-identify. Diagnosis + town + occupation + school name can be enough even after the legal name is gone.
Free text is sticky. Clinicians dictate unique stories. Models and humans both leave in details that tables would have dropped.
Third parties appear. Spouse names, employer incidents, other treating clinicians — identifiers that are not “the patient” still create risk.
Ambient systems make the problem larger
Ambient capture often includes:
- Waiting-room or hallway audio if mics are poorly placed
- Family members who did not sign the same consent
- Screen-sharing or telehealth UI chrome
- Automatically logged metadata (device IDs, IP-ish telemetry, account emails)
A policy that says “we strip names from the SOAP note before sending to the analytics warehouse” does nothing for the raw audio bucket retained “for quality.”
What practices should ask vendors
- Do you claim de-identification for training or analytics? Which HIPAA method, documented where?
- Is audio retained after the note is signed? For how long?
- Can support staff replay visits? Is that access logged?
- If you “anonymize for model improvement,” is that still under a BAA as PHI processing, or have you truly exited PHI?
- What happens to backups?
For BAAs and business associate basics, start with HHS HIPAA professional materials (as of 2026-07-21) and our page AI scribes and HIPAA.
What not to do
- Paste real charts into public demos or consumer chatbots “because we removed the name”
- Assume hashing a medical record number equals Safe Harbor
- Treat SOC 2 as de-identification
- Rely on a vendor blog post without the method memo or BAA language
A worked example (synthetic)
Suppose a transcript reads: “48-year-old high-school principal in rural County X, only person in the district with condition Y, follow-up after hospitalization on March 3 for medication Z.” Even with the legal name removed, re-identification risk may remain high for anyone who knows the community. Safe Harbor’s date and geography rules exist precisely because stories identify people. Expert Determination would need to confront that risk explicitly — not hand-wave it because “we use an LLM to rewrite names.”
Ambient audio of the same visit could still contain the principal’s voice, a spouse using a first name, or a school mascot in the background. The transcript “cleanup” did not touch the object store holding the wav/mp3.
Analytics and “model improvement” clauses
Read commercial terms for:
- Whether customer content may train foundation models
- Whether outputs may be used to improve the service for others
- Whether “aggregated/de-identified” is defined with a HIPAA method reference
- How long training copies persist after contract end
If the clause is vague, assume PHI processing continues under the BAA and negotiate retention. If the vendor claims data leaves PHI status, ask for the Expert Determination summary or Safe Harbor procedure — not a marketing adjective.
How clinicgpt.ai sidesteps the issue
The demo runs in the browser and is not a PHI pipeline. That is a product absence, not a de-identification achievement. Still use synthetic text when experimenting (how this demo works). If you need a real ambient tool, evaluate vendors with a clear-eyed checklist: evaluating an AI scribe vendor.
Bottom line
De-identification is a compliance project with standards of proof. Ambient audio is one of the hardest inputs to de-identify well. Budget time for counsel and privacy review early — cheaper than discovering after go-live that your “anonymous” corpus was never anonymous.
Sources (as of 2026-07-21)
- HHS — De-identification guidance
- HHS — HIPAA for Professionals
- HHS — Business associate sample provisions
This post was drafted by AI and reviewed by our editorial team. Last updated 2026-07-21.