It does, see my other comment. It means employees CANNOT deanonymize the data. If done properly, the key is off network and off premises, only retrievable with a lot of red tape.
Then it isn't anonymized. It can't be unmaskable by any procedure and anonymous at the same time. You need to stop calling it anonymous and call it what it is:
Bound to an individual, but not actionable via the collecting agency without outside input.
So how many carriers do you know that do this properly?