What de-identification is
HIPAA's de-identification standard is at 45 CFR 164.514(a) and (b). Data that meets it is not PHI, so the Privacy Rule's limits on use and disclosure stop applying. That is why de-identified data is used for research, analytics, and vendor testing. The two accepted methods are Safe Harbor and Expert Determination.
Safe Harbor requires removing 18 identifiers. They include names, geography smaller than a state, all dates except year, and ages over 89. Phone, fax, email, and Social Security, medical record, health plan, and account numbers go too. So do license numbers, vehicle and device IDs, URLs, IP addresses, biometrics such as voice prints, full-face photos, and any other unique code. The first three ZIP digits may stay if that area holds more than 20,000 people.
Expert Determination lets a qualified statistical expert apply methods that make re-identification risk very small, and document the analysis. It can keep more detail, such as dates. A limited data set is different: it keeps dates and some geography, is still PHI, and needs a data use agreement. Free text, call audio, and small populations are hard to de-identify reliably.