Removing Personally Identifiable Information

Review the following checklist before depositing your dataset to ensure that any personally identifiable information (PII) has been removed.

  1. Personal information that, if exposed, can lead to identity theft. 
    “Personal information” means the first name or first initial and last name in combination with and linked to any one or more of the following data elements about the individual:
    1. Social security number;
    2. Driver’s license number or state identification card number issued in lieu of a driver’s license number;
    3. Passport number; or
    4. Financial account number, or credit card or debit card number.
       
  2. Personally Identifiable Information (PII) is information that, if exposed, can be used on its own or with other information to identify, contact, or locate a single person, or to identify an individual in context:
    1. Name, such as full name, maiden name, mother’s maiden name, or alias;
    2. Personal identification number, such as social security number (SSN), passport number, driver’s license number, taxpayer identification number, patient identification number, and financial account or credit card number;
    3. Address information, such as street address or email address;
    4. Asset information, such as Internet Protocol (IP) or Media Access Control (MAC) address or other host-specific persistent static identifier that consistently links to a particular person or small, well-defined group of people;
    5. Telephone numbers, including mobile, business, and personal numbers;
    6. Personal characteristics, including photographic image (especially of face or other distinguishing characteristic), x-rays, fingerprints, or other biometric image or template data (e.g., retina scan, voice signature, facial geometry);
    7. Information identifying personally owned property, such as vehicle registration number or title number and related information;
    8. Information about an individual that is linked or linkable to one of the above (e.g., date of birth, place of birth, race, religion, weight, activities, geographical indicators, employment information, medical information, education information, financial information);
    9. Other FERPA-protected data not otherwise covered specifically in this list.
       
  3. Health information that, if exposed, can reveal an individual’s health condition and/or history of health services use.  
    “Health information,” also known as “protected health information (PHI),” includes health records combined in any way with one or more of the following data elements about the individual:
    1. Names;
    2. All geographic subdivisions smaller than a State, including street address, city, county, precinct, zip code, and their equivalent geocodes, except for the initial three digits of a zip code if, according to the current publicly available data from the Bureau of the Census the geographic unit formed by combining all zip codes with the same three initial digits contains more  than 20,000 people, and the initial three digits of a zip code for all such geographic units containing 20,000 or fewer people is changed to 000;
    3. All elements of dates (except year) for dates directly related to an individual, including birth date, admission date, discharge date, date of death; and all ages over 89 and all elements of dates (including year) indicative of such age, except that such ages and elements may be aggregated into a single category of age 90 or older;
    4. Telephone numbers;
    5. Fax numbers;
    6. Electronic mail addresses;
    7. Social security numbers;
    8. Medical record numbers;
    9. Health plan beneficiary numbers;
    10. Account numbers;
    11. Certificate/license numbers;
    12. Vehicle identifiers and serial numbers, including license plate numbers;
    13. Device identifiers and serial numbers;
    14. Web Universal Resource Locators (URLs);
    15. Internet Protocol (IP) address numbers;
    16. Biometric identifiers, including finger and voice prints;
    17. Full face photographic images and any comparable images; and
    18. Any other unique identifying number, characteristic, or code

Refer to University Policy 1114, Data Stewardship, Appendix A, Protected Data Types, and GMU ITS's Highly Sensitive Data FAQ.