LAW: HIPAA Compliance
The HIPAA Privacy Rule does not prohibit all uses and disclosures of protected health information. It establishes a structured framework of permitted purposes, required authorisations, and role-specific obligations that determine when PHI can flow, who must authorise it, and what documentation must exist. This article explains that framework in practical terms for compliance officers, healthcare administrators, privacy officers, and the workforce members they train.
Legal Disclaimer
This article provides educational information about HIPAA’s uses and disclosures framework. It does not constitute legal advice. HIPAA requirements are complex, frequently updated by HHS guidance, and their application depends on the specific facts of each situation. Consult qualified legal or compliance counsel for guidance specific to your organisation.
18
Permitted Uses Without Auth
45 CFR 164.512 lists 12 specific public interest and benefit activities for which PHI may be used or disclosed without individual authorisation. Treatment, payment, and operations add three more core permitted purposes. Twelve additional national priority purposes are addressed separately in the Privacy Rule.
Source: HHS | HIPAA Privacy Rule
TPO
Core Permitted Purposes
Treatment, Payment, and Healthcare Operations (TPO) are the three foundational permitted purposes under 45 CFR 164.506. Covered entities may use and disclose PHI for TPO without individual authorisation, subject to the minimum necessary standard. These three purposes account for the vast majority of routine PHI flows in healthcare settings.
Source: HHS | TPO Disclosures Guidance
MNS
Minimum Necessary Standard
Even where a use or disclosure is permitted, covered entities must make reasonable efforts to limit PHI to the minimum necessary to accomplish the intended purpose under 45 CFR 164.502(b). The minimum necessary standard does not apply to disclosures to treating providers, uses required by law, or disclosures to the individual themselves.
Source: HHS | Minimum Necessary Guidance
Law Summary: The Framework for Uses and Disclosures of PHI
The HIPAA Privacy Rule, codified at 45 CFR Part 164, does not operate as a blanket prohibition on sharing health information. Instead, it establishes a permission structure with three tiers: uses and disclosures that are required, uses and disclosures that are permitted without authorisation, and uses and disclosures that require individual authorisation. Understanding which tier applies to a given situation is the core practical skill the Privacy Rule demands of everyone who works with PHI.
Required Disclosures
Covered entities must disclose PHI in two circumstances: to the individual when they request access to their own records under 45 CFR 164.524, and to HHS when it is conducting a compliance investigation or review under 45 CFR 164.502(a)(2). These are not optional. They are affirmative obligations that cannot be withheld except in the specific circumstances the Privacy Rule identifies.
Permitted Without Authorisation
Uses and disclosures for Treatment, Payment, and Healthcare Operations (TPO) are permitted without individual authorisation under 45 CFR 164.506. Additional national priority purposes under 45 CFR 164.512 permit disclosures for public health, law enforcement, research, and other specified activities. Each has its own conditions and minimum necessary requirements.
Requires Individual Authorisation
Any use or disclosure that does not fall within a required or permitted category requires a written authorisation from the individual under 45 CFR 164.508. Authorisations must meet specific content requirements, must not be conditioned on treatment in most circumstances, and are revocable by the individual at any time before the use or disclosure takes place.
Incidental Uses and Disclosures
Incidental uses or disclosures that occur as a by-product of an otherwise permitted use or disclosure are not violations of the Privacy Rule, provided the covered entity has applied reasonable safeguards and adhered to the minimum necessary standard. A nurse discussing a patient’s care within earshot of others is not a violation if reasonable precautions were in place.
Who Must Comply
Entity Type
Relationship to Privacy Rule
Training Obligation
Covered entities (health plans, providers, clearinghouses)
Directly bound by all Privacy Rule provisions
Must train all workforce members
Business Associates
Bound by BAA and directly by the Privacy Rule since 2013 HIPAA Omnibus Rule
Must train workforce on applicable provisions
Subcontractors of Business Associates
Treated as Business Associates; bound by downstream BAA
Must train on applicable uses and disclosures
Hybrid entities (partial covered entity functions)
Privacy Rule applies only to the healthcare component; must isolate PHI flows
Healthcare component workforce only
Source: HHS | Covered Entities and Business Associates
Applicable Standards
Key Regulatory References
45 CFR 164.502: The core uses and disclosures provision. Establishes the general rule (use and disclosure only as permitted or required), the required disclosures to individuals and HHS, and the minimum necessary standard.
45 CFR 164.506: Permitted uses and disclosures for Treatment, Payment, and Healthcare Operations. Defines each term and sets out the conditions for disclosure to other covered entities for these purposes.
45 CFR 164.508: Authorisation requirements. Specifies the eight required elements of a valid authorisation and the three elements required for compound authorisations involving research.
45 CFR 164.510: Uses and disclosures requiring opportunity to agree or object. Covers facility directories, disclosures to family and friends, and disaster relief situations.
45 CFR 164.512: The twelve national priority purposes: public health, abuse reporting, health oversight, judicial proceedings, law enforcement, decedents, organ donation, research, serious threat prevention, essential government functions, workers’ compensation, and others.
Source: HHS OCR | 45 CFR Parts 160 and 164
Key Definitions
Use
Under HIPAA, “use” refers to the sharing, employment, application, utilisation, examination, or analysis of PHI within an entity that maintains the information. A physician reviewing a patient’s chart is a use. A billing clerk pulling records to prepare a claim is a use. Use is internal to the covered entity or business associate.
Disclosure
A “disclosure” is the release, transfer, provision of access to, or divulging of PHI in any manner to persons or entities outside the entity holding the information. Sending records to a specialist is a disclosure. Responding to a subpoena for medical records is a disclosure. The distinction between use and disclosure matters because different Privacy Rule provisions govern each.
Minimum Necessary
The minimum necessary standard requires covered entities to make reasonable efforts to limit PHI to the minimum needed to accomplish the intended purpose. Workforce members should access only the PHI relevant to their role. Blanket access to complete records is not appropriate where a narrower access class would serve the purpose. Policies must define what categories of workers may access what categories of PHI.
Authorisation
An authorisation under 45 CFR 164.508 is a written permission from the individual for a specific use or disclosure that is not otherwise permitted or required. It must describe the PHI to be used or disclosed, identify the person(s) authorised to make the use or disclosure, identify the purpose, include an expiration date, and advise the individual of their right to revoke. Defective authorisations do not permit the use or disclosure.
Employer Responsibilities: Role-Based Training Requirements
The Privacy Rule’s training requirement at 45 CFR 164.530(b) requires covered entities to train all members of their workforce on the policies and procedures with respect to PHI required by the Privacy Rule. Training must occur no later than the compliance date for the covered entity, within a reasonable period of time after a person joins the workforce, and when material changes occur to policies or procedures. Role-based training is not explicitly required by the regulation but is the standard approach that HHS guidance recommends and that audits consistently expect.
1
Define role-based access categories
Policies must identify the categories of PHI each workforce role may access and the purposes for which access is permitted. A registration clerk’s access profile differs from a treating physician’s. Defining these categories in policy is the foundation of minimum necessary compliance and role-based training design.
2
Document training completion
45 CFR 164.530(j) requires covered entities to maintain documentation of training provided. This means records of who was trained, on what content, by what method, and on what date. HHS audits routinely request these records. The absence of training documentation is a Privacy Rule violation independent of whether actual training occurred.
3
Train on specific role scenarios
General HIPAA training teaches the law. Role-specific training teaches what the law means for a given job function. A billing specialist needs to understand what information they may access for claim preparation and what they may not forward to external parties. A researcher needs to understand de-identification and the research exception under 45 CFR 164.512(i).
4
Update training when policies change
The Privacy Rule requires retraining when material changes are made to policies or procedures affecting PHI. Changes in technology, new disclosure categories, updated BAA obligations, or new regulatory guidance from HHS all qualify as material changes that may trigger retraining obligations. The retraining obligation applies within a reasonable period of the change.
Employee Rights Under HIPAA’s Uses and Disclosures Framework
Individuals Have the Right To
Covered Entities Cannot
Request an accounting of disclosures made without authorisation (45 CFR 164.528) for the six years prior to the request
Withhold the accounting of disclosures except for disclosures made for treatment, payment, and operations and certain other exceptions
Revoke an authorisation at any time before the use or disclosure takes place (45 CFR 164.508(b)(5))
Act on a revoked authorisation for uses or disclosures not yet completed when the revocation was received
Request restrictions on uses and disclosures of PHI for treatment, payment, or operations beyond what the Privacy Rule requires (45 CFR 164.522)
Refuse to agree to a restriction on disclosure to health plans for treatment the individual has paid for in full out of pocket (45 CFR 164.522(a)(1)(vi))
Request that disclosures be made by alternative means or to an alternative location (45 CFR 164.522(b))
Condition treatment on the individual agreeing to uses or disclosures beyond what is required for treatment, payment, and operations, except in limited circumstances
Source: HHS | HHS Privacy Rule Guidance
Common Violations in Uses and Disclosures
Most Frequently Cited Disclosure Violations
Impermissible disclosures to third parties without authorisation
Highest Frequency
Disclosures to employers, family members, media, or other third parties without valid authorisation or applicable exception. HHS OCR enforcement cases consistently identify this as the most common category of Privacy Rule violation. Often occurs when workforce members incorrectly assume a relationship with the third party justifies the disclosure.
Failure to apply minimum necessary standard
High Frequency
Providing complete medical records when a summary would serve the purpose. Granting system-wide PHI access to workforce members whose roles require access only to specific data elements. Routine disclosure of more information than necessary for the claimed purpose.
Using defective or expired authorisations
Common
Proceeding with a use or disclosure based on an authorisation that is missing required elements, that has been revoked, or that has passed its expiration date. Workforce members responsible for obtaining and verifying authorisations are often not trained on the eight required elements under 45 CFR 164.508(c).
Disclosures beyond the scope of a valid authorisation
Common
Disclosing PHI beyond what the authorisation specifies, to recipients not identified in the authorisation, or for purposes not stated in the authorisation. A valid authorisation for one purpose does not authorise uses or disclosures for a different purpose.
Source: HHS OCR | HHS OCR Resolution Agreements
Penalties and Consequences
HHS OCR enforces the Privacy Rule through a four-tier civil monetary penalty structure established by the HITECH Act and codified at 42 USC 1320d-5. The tiers reflect the level of culpability, ranging from violations where the covered entity did not know and could not have known, to violations involving wilful neglect that are not corrected within a specified period.
Tier
Description
Annual Cap
Tier 1
Did not know and could not have known
$25,000 per identical violation
Tier 2
Reasonable cause; not wilful neglect
$100,000 per identical violation
Tier 3
Wilful neglect; corrected within 30 days
$250,000 per identical violation
Tier 4
Wilful neglect; not corrected within 30 days
$1,500,000 per identical violation
Source: HHS OCR | HHS OCR Enforcement Highlights
Criminal penalties under 42 USC 1320d-6 apply to individuals who knowingly obtain or disclose PHI in violation of HIPAA, with penalties escalating to up to 10 years imprisonment for disclosures made with intent to sell, transfer, or use PHI for commercial advantage, personal gain, or malicious harm.
Compliance Checklist
Policies and Procedures
Written uses and disclosures policy identifies all TPO purposes and applicable 164.512 exceptions
Minimum necessary policy defines access categories by workforce role
Authorisation forms contain all eight required elements under 45 CFR 164.508(c)
Accounting of disclosures procedure is documented and tested
Training
All workforce members trained on uses and disclosures policies at hire
Role-specific training covers each role’s specific access categories and permitted purposes
Training records retained showing content, date, and attendees
Refresher training triggered by material policy changes
Monitoring and Enforcement
Access logs reviewed periodically for workforce members accessing PHI outside their role category
Disclosure log maintained for non-TPO disclosures to support accounting requests
Workforce sanctions policy applied consistently for Privacy Rule violations
Complaints about improper disclosures investigated and documented
Key Takeaways
The permission framework has three tiers, not two
Most workforce training frames HIPAA as a binary: with authorisation you can share, without authorisation you cannot. The actual framework has three categories: required disclosures, permitted disclosures without authorisation, and disclosures requiring authorisation. Missing the middle tier, particularly the TPO permitted purposes and 45 CFR 164.512 exceptions, leads to both over-restriction that impedes care and under-restriction that creates violations.
Minimum necessary applies even when the disclosure is permitted
A common compliance misconception is that identifying a permitted purpose for a disclosure ends the analysis. It does not. The minimum necessary standard applies to most permitted uses and disclosures, including those for TPO. Policies must define what “minimum necessary” means in practice for each disclosure category, and access controls must enforce those definitions rather than leaving them to individual judgment.
Role-based training is not a training format preference; it is a compliance strategy
General HIPAA awareness training teaches the existence of the permission framework. It does not teach a registration clerk which disclosures are permitted in their specific context, or teach a researcher what the de-identification safe harbour requires. The gap between knowing HIPAA exists and knowing how it applies to your specific job function is where most workforce-level violations originate. Role-based training closes that gap by connecting the regulatory framework to the actual decisions each role makes.
Frequently Asked Questions
Can a covered entity disclose PHI to a patient’s family member without authorisation?
Yes, in specific circumstances under 45 CFR 164.510(b). A covered entity may disclose PHI to a family member, friend, or other person identified by the patient if the patient is present and either agrees or does not object. If the patient is not present or cannot agree, the covered entity may disclose PHI when, in its professional judgement, doing so is in the patient’s best interest.
What is the difference between an authorisation and a consent under HIPAA?
HIPAA eliminated the general consent requirement for uses and disclosures for treatment, payment, and operations when the Privacy Rule was finalised. An authorisation under 45 CFR 164.508 is a specific document required for uses and disclosures not otherwise permitted: it must identify the information, the person authorised to disclose and receive it, the purpose, an expiration date, and the patient’s right to revoke. Consent is a separate, optional document some providers choose to use for their own administrative purposes.
Does the minimum necessary standard apply to disclosures for treatment purposes?
No. The Privacy Rule explicitly exempts disclosures to healthcare providers for treatment purposes from the minimum necessary requirement. A physician requesting records from another provider for treatment purposes is not required to limit the request. The exemption recognises that clinical care decisions require access to complete clinical information.
How long must covered entities retain documentation of HIPAA training?
Under 45 CFR 164.530(j), documentation must be retained for six years from the date of creation or the date it was last in effect, whichever is later. This applies to policies and procedures, training records, and documentation of complaints and investigations. The retention requirement begins running from the date the document was last in effect, not the date it was created.
What is the TPO exception and what does it cover?
The treatment, payment, and operations exception permits covered entities to use and disclose PHI without patient authorisation for a wide range of internal and inter-entity activities. Treatment includes clinical care by any healthcare provider involved in the patient’s care. Payment includes billing, claims adjudication, and prior authorisation. Operations includes quality assessment, training programmes, accreditation activities, and fraud detection. The TPO exception is the broadest permitted category and covers most routine healthcare uses of PHI.
When does a disclosure to a law enforcement agency require patient authorisation?
Most law enforcement disclosures are permitted without authorisation under 45 CFR 164.512(f), which allows disclosures in response to a court order, warrant, subpoena, or administrative request with specific guarantees; for identification and location purposes; to report crimes on premises; and in limited emergency circumstances. However, disclosures that go beyond these specific categories require either patient authorisation or a specific legal mandate. Covered entities should consult legal counsel before disclosing PHI in response to informal law enforcement requests.
What are the consequences of failing to provide a patient access to their records within the required timeframe?
The right of access under 45 CFR 164.524 requires covered entities to act on a request within 30 days, with one 30-day extension if the entity notifies the patient of the delay and the reason. Failure to respond within the required period is a Privacy Rule violation. HHS OCR has made right of access enforcement a priority and has resolved dozens of cases with financial penalties for access failures, with civil monetary penalties ranging from several thousand to over $200,000 per investigation depending on the volume of violations and the covered entity’s history.
Government and Regulatory Sources
Government and Regulatory Sources
- HHS. HIPAA Privacy Rule (45 CFR Parts 160 and 164): full regulatory text and HHS guidance index.
- HHS OCR. Permitted Disclosures for TPO: guidance on treatment, payment, and operations disclosures.
- HHS OCR. Minimum Necessary Requirement Guidance: practical guidance on applying the minimum necessary standard.
- HHS OCR. HIPAA Enforcement Highlights: annual enforcement data, complaint statistics, and resolution summaries.
- HHS. Covered Entities and Business Associates: guidance on determining covered entity and business associate status.
Research and Industry Sources
- Health Care Compliance Association (HCCA): professional standards and benchmarking data for HIPAA compliance programmes.
Related VelSafe Articles
VelSafe
Master HIPAA Privacy Requirements
Understanding HIPAA uses and disclosures is essential for every covered entity and business associate. Find practical compliance guidance and training resources at VelSafe.
Explore VelSafe Resources