US

HIPAA: Privacy Rule

Privacy Rule [45 CFR 164.500-534]

Rule: Covered entities may only use or disclose PHI as permitted by the Privacy Rule, typically requiring patient authorization except for treatment, payment, and healthcare operations.

Permitted Uses Without Authorization

CategoryDescriptionCitation
TreatmentProvision of healthcare§164.506
PaymentBilling, claims, eligibility§164.506
Healthcare operationsQuality, training, compliance§164.506
Required by lawCourt orders, law enforcement§164.512(a)
Public healthDisease reporting, FDA§164.512(b)
Health oversightAudits, investigations§164.512(d)
Judicial proceedingsSubpoenas, court orders§164.512(e)
ResearchWith IRB/Privacy Board approval§164.512(i)

Authorization Required

Uses not listed above require valid written authorization:

  • Marketing
  • Sale of PHI
  • Psychotherapy notes (with limited exceptions)
  • Most research uses
  • Disclosures to employers

Valid Authorization Must Include

  1. Description of PHI to be disclosed
  2. Who is authorized to disclose
  3. Who will receive the information
  4. Purpose of disclosure
  5. Expiration date
  6. Individual’s signature and date
  7. Right to revoke statement
  8. Notice authorization is voluntary

Minimum Necessary Standard [§164.502(b)]

Rule: Limit PHI use, disclosure, and requests to the minimum necessary to accomplish the intended purpose.

ApplicationRequirement
Internal usesIdentify who needs access based on role
DisclosuresLimit to minimum needed for purpose
RequestsOnly request what’s necessary

Exceptions to minimum necessary:

  • Treatment disclosures
  • Disclosures to the individual
  • Uses authorized by individual
  • Uses required by law

Notice of Privacy Practices [§164.520]

Covered entities must provide notice describing:

  • How PHI may be used and disclosed
  • Individual’s privacy rights
  • Entity’s legal duties
  • How to file complaints

Citation

45 CFR Part 164 Subpart E — Privacy of Individually Identifiable Health Information

Contains public sector information licensed under the Open Government Licence v3.0 where applicable. This is not legal advice. Always refer to official sources for authoritative text.

llms.txt