# HIPAA Safe Harbor checklist — PHI pre-flight, no upload

> Scan tabular data for the 18 HIPAA Safe Harbor identifier types with column mapping and masked samples, then apply a scrub preset. Local only — not legal advice.

Pre-flight a dataset for the 18 HIPAA Safe Harbor identifier types, with column mapping and masked samples, then apply a one-click Safe Harbor scrub preset. Analysis is local only — this is a helper, not legal advice.

De-identifying health data under Safe Harbor means accounting for 18 specific identifier types — easy to miss one by eye. This checklist maps your columns against those categories and shows masked samples so you can verify what each column actually contains.

The one-click preset then scrubs the flagged fields. Treat it as a careful first pass, not a compliance guarantee: it's not legal advice, and an expert determination may still be required. For general identifiers, use the PII scrubber.

## How to

1. **Add a file.** Drop the dataset you plan to de-identify.
2. **Scan for identifiers.** Columns are mapped to the 18 Safe Harbor identifier categories with masked samples.
3. **Review.** Confirm which columns hold PHI and how they should be handled.
4. **Scrub.** Apply the Safe Harbor preset to mask or remove the flagged fields.

## FAQ

### What are the 18 Safe Harbor identifiers?

HIPAA's Safe Harbor method lists 18 identifier types — names, geographic subdivisions, dates, contact details, SSNs, record numbers, and more — that must be removed to de-identify data.

### Does passing this make my data HIPAA-compliant?

No. This is a pre-flight helper that flags likely PHI columns; it is not legal advice and doesn't certify compliance. Confirm with a qualified expert before releasing data.

### Is my data uploaded to check it?

No. The scan and any scrub run entirely in your browser, which is essential for health data that must not leave controlled systems.


## Related tools

- [PII scrubber](https://www.safepaper.app/data/pii-scrub)
- [Schema profile](https://www.safepaper.app/data/profile)
- [De-identify](https://www.safepaper.app/docs/deidentify)
- [Row deduplicator](https://www.safepaper.app/data/dedupe)

---

Canonical HTML: https://www.safepaper.app/data/hipaa-check
Markdown: https://www.safepaper.app/data/hipaa-check.md

There is no upload endpoint — your files are processed in this browser tab. Open your network tab and check.
