{"@context":"https://schema.org","@type":"Article","headline":"Part 2 patient-identifying information","description":"Learn what can identify a Part 2 patient directly or by reference to other information and how to control contextual, coded, and indirect identifiers.","url":"https://finnihealth.com/resources/glossary/part-2-patient-identifying-information","datePublished":"2026-08-17T00:00:00.000Z","dateModified":"2026-08-24T00:00:00.000Z","author":{"@type":"Organization","name":"Finni Health Editorial Team"},"publisher":{"@type":"Organization","name":"Finni Health","url":"https://www.finnihealth.com"},"isPartOf":{"@type":"CollectionPage","name":"ABA and Practice Operations Glossary","url":"https://www.finnihealth.com/resources/glossary"},"breadcrumb":{"@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Resources","item":"https://www.finnihealth.com/resources"},{"@type":"ListItem","position":2,"name":"Glossary","item":"https://www.finnihealth.com/resources/glossary"},{"@type":"ListItem","position":3,"name":"Part 2 patient-identifying information","item":"https://finnihealth.com/resources/glossary/part-2-patient-identifying-information"}]}}
Glossary term

Part 2 patient-identifying information

Learn what can identify a Part 2 patient directly or by reference to other information and how to control contextual, coded, and indirect identifiers.

5
min read
Updated
August 23, 2026
Sources checked
August 23, 2026
ยท View sources
Also called

SUD direct indirect identifiers identity determined with reasonable accuracy

Patient identifying information under Part 2 includes a name, address, Social Security number, fingerprints, photograph, or similar information through which a patient's identity can be determined with reasonable accuracy, directly or by reference to other information. The definition reaches contextual and linkable identifiers, so removing a name alone may leave information capable of identifying the patient.

Editorial approval scope: The team checked current source fidelity, scope boundaries, dates, arithmetic, reader usefulness, practical workflow, and general-information limitations.

Use the current disclosure framework

The HHS Part 2 final-rule fact sheet notes that the 2024 rule permits certain disclosures to public health authorities when records are de-identified according to HIPAA Privacy Rule standards. That specific pathway does not turn removal of a name into a universal Part 2 safe harbor. The Federal Register final rule supplies the adopted rule and agency discussion behind the codified provisions. Document the precise authority for the contemplated disclosure, the de-identification method it requires, and the qualified reviewer. Then compare the output with the current eCFR before release, especially when narratives, small cells, location, or dates remain.

Identification can be direct or indirect

42 CFR 2.11 focuses on reasonable accuracy. Review dates, locations, rare events, family details, provider or program identity, record numbers, device data, images, voices, codes, free text, small groups, and linkable combinations.

Context changes the classification

The same field can carry different identification risk by recipient, geography, available reference data, cohort size, and surrounding content. Record the data set, context, recipient, purpose, linkage sources, decision owner, and date.

Minimization should follow the authorized purpose

Remove, generalize, mask, or segregate unnecessary identifiers while preserving clinical or operational utility. Apply the specific Part 2 permission, consent, court order, security, notice, and downstream-use rules.

Review the message and context together

Identification risk is broader than a name field. A date, uncommon event, exact location, photograph, voice clip, quotation, provider name, or small cohort can identify a person when combined with public information or data already held by the recipient. Review the complete disclosure as the recipient will see it, including filenames, metadata, free text, headers, and linked tables.

The relevant question is whether identity can be determined with reasonable accuracy, directly or by reference to other information. Document who performed that assessment, which recipient and context were considered, what linkage sources were reasonably available, and when the decision was made. A conclusion for a large statewide report may not fit a neighborhood-level extract of the same fields.

Separate data minimization from de-identification

Minimization removes information that the authorized purpose does not need. Masking or replacing direct identifiers can reduce exposure, but those steps alone do not necessarily take information outside the Part 2 definition. A coded identifier can remain identifying when a key exists or when surrounding facts permit linkage.

When an exception or workflow depends on a specific de-identification standard, apply that standard with its own qualified review and documentation. Avoid borrowing a HIPAA label, statistical claim, or vendor setting without confirming that it satisfies the authority used for the Part 2 disclosure.

Design a repeatable identity review

Start with the proposed recipient, purpose, minimum fields, geography, dates, cohort size, narrative content, and external reference sources. Inspect direct identifiers, quasi-identifiers, rare combinations, embedded media, document properties, and row-level linkability. Record the fields removed or generalized and any residual risk accepted by the authorized owner.

Controls should follow the output after approval. Limit downloads, onward sharing, screenshots, and recombination with other data. Use expiration, access logging, contractual limits, and deletion where appropriate. Reassess when the data set, audience, linkage environment, or intended use changes.

Address common edge cases

Publicly known facts can identify a patient when a disclosure confirms that the person received SUD diagnosis, treatment, or referral. Aggregates can remain revealing when a cell represents one or very few people. Free-text notes and quoted statements often carry identity clues missed by field-based scans. Synthetic or transformed data also needs review if it reproduces traceable records or preserves rare combinations.

Example

Twenty proposed exports receive identity review. Sixteen pass direct, indirect, code, metadata, and context checks; four remain linkable through dates or quotations. Readiness is 16 of 20 exports.

Patient-identifying information checklist

  • review direct identifiers, indirect clues, context, metadata, and linkage sources;
  • identify the actual recipient and the information already available to them;
  • minimize fields before applying any de-identification method;
  • document the authority, method, reviewer, residual risk, and date;
  • control recombination, onward disclosure, exports, and retained copies; and
  • repeat the analysis after a material change in data, audience, or purpose.

This definition is not a universal de-identification test or a permission to disclose. Part 2 provisions, HIPAA when applicable, state law, contracts, and the specific purpose may impose additional requirements. Close cases need a Part 2 privacy officer and experienced counsel.

Related terms

Sources

Beyond the glossary

Take the next step with clarity

Whether you are finding care, growing as a clinician, or building a stronger ABA practice, Finni brings the people, tools, and support together to help you move forward.

Start or grow your ABA practice with Finni