HL7v2 Message De-identification for sending to HHS Protect

Introduction

This page describes a de-identification approach for HL7v2 messages. De-identification supports transmission of messages to CDC's HHS Protect system, the federal health system that receives at-home test results.

De-identification is typically performed by the Data Hub that serves as an intermediary between the mobile testing application and HHS Protect.

Unlike messages sent to federal health systems, messages sent to state and local public health systems are not de-identified.

Principles of de-identification

At-home test reporting data can be reasonably assumed to fall under HIPAA guidelines. These guidelines and de-identification strategies can be found on the HHS website .

Defining where PHI exists in the message

HL7v2 message elements that are changed in the de-identification process are outlined in the table below. Several elements that are not intended to contain PHI are also removed to address potential inclusion of PHI in those elements erroneously. This includes removal of some fields that are not part of the MARS HL7v2 Implementation Guide , in case those fields are present and contain PHI.

SegmentComponentTitleChange
PID3.1Patient IDRemove if PID-3.5 does not equal "PI", "PT", or "SID"; else, no change
PID5.1Patient last nameIf empty, no change; else, modify to "DeIdentified"
PID5.2Patient first nameIf empty, no change; else, modify to "DeIdentified"
PID5.3Patient middle nameIf empty, no change; else, modify to "DeIdentified"
PID5.4Patient name suffixRemove
PID5.7Patient name type codeRemove
PID7.1Patient DOBIf empty, no change; else, modify to "DeIdentified"
PID11.1Patient street addressIf empty, no change; else, modify to "DeIdentified"
PID11.2Patient street address 2If empty, no change; else, modify to "DeIdentified"
PID11.3Patient cityIf empty, no change; else, modify to "DeIdentified"
PID13.4Patient emailIf empty, no change; else, modify to "DeIdentified"
PID13.6Patient phone area codeIf empty or "111", no change; else, modify to "DeIdentified"
PID13.7Patient local phoneIf empty or "1111111", no change; else, modify to "DeIdentified"
ORCAll ORC fieldsCommon Order segmentRemove
OBR2.1Placer order numberRemove
OBR3.1Filler order numberRemove
OBR16.1Ordering provider IDRemove
OBR16.2Ordering provider last nameRemove
OBR16.3Ordering provider first nameRemove
OBR17.2Order callback telecom use codeRemove
OBR17.3Order callback telecom equipment typeRemove
OBR17.4Order callback emailRemove
OBR17.6Order callback phone area codeRemove
OBR17.7Order callback local phoneRemove
OBX14.1Observation date and timeRemove
OBX24.1Test performing organization street addressRemove
OBX24.2Test performing organization street address 2Remove
OBX24.3Test performing organization cityRemove
OBX24.4Test performing organization stateRemove
OBX24.5Test performing organization zip codeRemove
OBX24.6Test performing organization countryRemove
OBX24.7Test performing organization address typeRemove
OBX24.8Test performing organization other geographic designationRemove
OBX24.9Test performing organization countyRemove
NTEAll NTE fieldsNotes and Comments segmentRemove
NK1All NK1 fieldsNext of Kin / Associated Parties segmentRemove