HIPAA uses and disclosures of PHI law article featured image showing a male healthcare compliance officer reviewing a HIPAA Privacy Policy binder at a conference table, with a horizontal bar chart of the PHI disclosure framework categories in the top panel.

HIPAA Privacy: Role-Based Training III: Uses and Disclosures of PHI

LAW: HIPAA Compliance
HIPAA Privacy: Role-Based Training III: Uses and Disclosures of PHI
The HIPAA Privacy Rule does not prohibit all uses and disclosures of protected health information. It establishes a structured framework of permitted purposes, required authorisations, and role-specific obligations that determine when PHI can flow, who must authorise it, and what documentation must exist. This article explains that framework in practical terms for compliance officers, healthcare administrators, privacy officers, and the workforce members they train.
Legal Disclaimer
This article provides educational information about HIPAA’s uses and disclosures framework. It does not constitute legal advice. HIPAA requirements are complex, frequently updated by HHS guidance, and their application depends on the specific facts of each situation. Consult qualified legal or compliance counsel for guidance specific to your organisation.
18
Permitted Uses Without Auth
45 CFR 164.512 lists 12 specific public interest and benefit activities for which PHI may be used or disclosed without individual authorisation. Treatment, payment, and operations add three more core permitted purposes. Twelve additional national priority purposes are addressed separately in the Privacy Rule.
Source: HHS | HIPAA Privacy Rule
TPO
Core Permitted Purposes
Treatment, Payment, and Healthcare Operations (TPO) are the three foundational permitted purposes under 45 CFR 164.506. Covered entities may use and disclose PHI for TPO without individual authorisation, subject to the minimum necessary standard. These three purposes account for the vast majority of routine PHI flows in healthcare settings.
MNS
Minimum Necessary Standard
Even where a use or disclosure is permitted, covered entities must make reasonable efforts to limit PHI to the minimum necessary to accomplish the intended purpose under 45 CFR 164.502(b). The minimum necessary standard does not apply to disclosures to treating providers, uses required by law, or disclosures to the individual themselves.

Law Summary: The Framework for Uses and Disclosures of PHI

The HIPAA Privacy Rule, codified at 45 CFR Part 164, does not operate as a blanket prohibition on sharing health information. Instead, it establishes a permission structure with three tiers: uses and disclosures that are required, uses and disclosures that are permitted without authorisation, and uses and disclosures that require individual authorisation. Understanding which tier applies to a given situation is the core practical skill the Privacy Rule demands of everyone who works with PHI.

Required Disclosures
Covered entities must disclose PHI in two circumstances: to the individual when they request access to their own records under 45 CFR 164.524, and to HHS when it is conducting a compliance investigation or review under 45 CFR 164.502(a)(2). These are not optional. They are affirmative obligations that cannot be withheld except in the specific circumstances the Privacy Rule identifies.
Permitted Without Authorisation
Uses and disclosures for Treatment, Payment, and Healthcare Operations (TPO) are permitted without individual authorisation under 45 CFR 164.506. Additional national priority purposes under 45 CFR 164.512 permit disclosures for public health, law enforcement, research, and other specified activities. Each has its own conditions and minimum necessary requirements.
Requires Individual Authorisation
Any use or disclosure that does not fall within a required or permitted category requires a written authorisation from the individual under 45 CFR 164.508. Authorisations must meet specific content requirements, must not be conditioned on treatment in most circumstances, and are revocable by the individual at any time before the use or disclosure takes place.
Incidental Uses and Disclosures
Incidental uses or disclosures that occur as a by-product of an otherwise permitted use or disclosure are not violations of the Privacy Rule, provided the covered entity has applied reasonable safeguards and adhered to the minimum necessary standard. A nurse discussing a patient’s care within earshot of others is not a violation if reasonable precautions were in place.

Who Must Comply

Entity Type
Relationship to Privacy Rule
Training Obligation
Covered entities (health plans, providers, clearinghouses)
Directly bound by all Privacy Rule provisions
Must train all workforce members
Business Associates
Bound by BAA and directly by the Privacy Rule since 2013 HIPAA Omnibus Rule
Must train workforce on applicable provisions
Subcontractors of Business Associates
Treated as Business Associates; bound by downstream BAA
Must train on applicable uses and disclosures
Hybrid entities (partial covered entity functions)
Privacy Rule applies only to the healthcare component; must isolate PHI flows
Healthcare component workforce only

Applicable Standards

Key Regulatory References
45 CFR 164.502: The core uses and disclosures provision. Establishes the general rule (use and disclosure only as permitted or required), the required disclosures to individuals and HHS, and the minimum necessary standard.
45 CFR 164.506: Permitted uses and disclosures for Treatment, Payment, and Healthcare Operations. Defines each term and sets out the conditions for disclosure to other covered entities for these purposes.
45 CFR 164.508: Authorisation requirements. Specifies the eight required elements of a valid authorisation and the three elements required for compound authorisations involving research.
45 CFR 164.510: Uses and disclosures requiring opportunity to agree or object. Covers facility directories, disclosures to family and friends, and disaster relief situations.
45 CFR 164.512: The twelve national priority purposes: public health, abuse reporting, health oversight, judicial proceedings, law enforcement, decedents, organ donation, research, serious threat prevention, essential government functions, workers’ compensation, and others.
Source: HHS OCR | 45 CFR Parts 160 and 164

Key Definitions

Use
Under HIPAA, “use” refers to the sharing, employment, application, utilisation, examination, or analysis of PHI within an entity that maintains the information. A physician reviewing a patient’s chart is a use. A billing clerk pulling records to prepare a claim is a use. Use is internal to the covered entity or business associate.
Disclosure
A “disclosure” is the release, transfer, provision of access to, or divulging of PHI in any manner to persons or entities outside the entity holding the information. Sending records to a specialist is a disclosure. Responding to a subpoena for medical records is a disclosure. The distinction between use and disclosure matters because different Privacy Rule provisions govern each.
Minimum Necessary
The minimum necessary standard requires covered entities to make reasonable efforts to limit PHI to the minimum needed to accomplish the intended purpose. Workforce members should access only the PHI relevant to their role. Blanket access to complete records is not appropriate where a narrower access class would serve the purpose. Policies must define what categories of workers may access what categories of PHI.
Authorisation
An authorisation under 45 CFR 164.508 is a written permission from the individual for a specific use or disclosure that is not otherwise permitted or required. It must describe the PHI to be used or disclosed, identify the person(s) authorised to make the use or disclosure, identify the purpose, include an expiration date, and advise the individual of their right to revoke. Defective authorisations do not permit the use or disclosure.

Employer Responsibilities: Role-Based Training Requirements

The Privacy Rule’s training requirement at 45 CFR 164.530(b) requires covered entities to train all members of their workforce on the policies and procedures with respect to PHI required by the Privacy Rule. Training must occur no later than the compliance date for the covered entity, within a reasonable period of time after a person joins the workforce, and when material changes occur to policies or procedures. Role-based training is not explicitly required by the regulation but is the standard approach that HHS guidance recommends and that audits consistently expect.

1
Define role-based access categories
Policies must identify the categories of PHI each workforce role may access and the purposes for which access is permitted. A registration clerk’s access profile differs from a treating physician’s. Defining these categories in policy is the foundation of minimum necessary compliance and role-based training design.
2
Document training completion
45 CFR 164.530(j) requires covered entities to maintain documentation of training provided. This means records of who was trained, on what content, by what method, and on what date. HHS audits routinely request these records. The absence of training documentation is a Privacy Rule violation independent of whether actual training occurred.
3
Train on specific role scenarios
General HIPAA training teaches the law. Role-specific training teaches what the law means for a given job function. A billing specialist needs to understand what information they may access for claim preparation and what they may not forward to external parties. A researcher needs to understand de-identification and the research exception under 45 CFR 164.512(i).
4
Update training when policies change
The Privacy Rule requires retraining when material changes are made to policies or procedures affecting PHI. Changes in technology, new disclosure categories, updated BAA obligations, or new regulatory guidance from HHS all qualify as material changes that may trigger retraining obligations. The retraining obligation applies within a reasonable period of the change.

Employee Rights Under HIPAA’s Uses and Disclosures Framework

Individuals Have the Right To
Covered Entities Cannot
Request an accounting of disclosures made without authorisation (45 CFR 164.528) for the six years prior to the request
Withhold the accounting of disclosures except for disclosures made for treatment, payment, and operations and certain other exceptions
Revoke an authorisation at any time before the use or disclosure takes place (45 CFR 164.508(b)(5))
Act on a revoked authorisation for uses or disclosures not yet completed when the revocation was received
Request restrictions on uses and disclosures of PHI for treatment, payment, or operations beyond what the Privacy Rule requires (45 CFR 164.522)
Refuse to agree to a restriction on disclosure to health plans for treatment the individual has paid for in full out of pocket (45 CFR 164.522(a)(1)(vi))
Request that disclosures be made by alternative means or to an alternative location (45 CFR 164.522(b))
Condition treatment on the individual agreeing to uses or disclosures beyond what is required for treatment, payment, and operations, except in limited circumstances

Common Violations in Uses and Disclosures

Most Frequently Cited Disclosure Violations
Impermissible disclosures to third parties without authorisation Highest Frequency
Disclosures to employers, family members, media, or other third parties without valid authorisation or applicable exception. HHS OCR enforcement cases consistently identify this as the most common category of Privacy Rule violation. Often occurs when workforce members incorrectly assume a relationship with the third party justifies the disclosure.
Failure to apply minimum necessary standard High Frequency
Providing complete medical records when a summary would serve the purpose. Granting system-wide PHI access to workforce members whose roles require access only to specific data elements. Routine disclosure of more information than necessary for the claimed purpose.
Using defective or expired authorisations Common
Proceeding with a use or disclosure based on an authorisation that is missing required elements, that has been revoked, or that has passed its expiration date. Workforce members responsible for obtaining and verifying authorisations are often not trained on the eight required elements under 45 CFR 164.508(c).
Disclosures beyond the scope of a valid authorisation Common
Disclosing PHI beyond what the authorisation specifies, to recipients not identified in the authorisation, or for purposes not stated in the authorisation. A valid authorisation for one purpose does not authorise uses or disclosures for a different purpose.

Penalties and Consequences

HHS OCR enforces the Privacy Rule through a four-tier civil monetary penalty structure established by the HITECH Act and codified at 42 USC 1320d-5. The tiers reflect the level of culpability, ranging from violations where the covered entity did not know and could not have known, to violations involving wilful neglect that are not corrected within a specified period.

Tier
Description
Annual Cap
Tier 1
Did not know and could not have known
$25,000 per identical violation
Tier 2
Reasonable cause; not wilful neglect
$100,000 per identical violation
Tier 3
Wilful neglect; corrected within 30 days
$250,000 per identical violation
Tier 4
Wilful neglect; not corrected within 30 days
$1,500,000 per identical violation

Criminal penalties under 42 USC 1320d-6 apply to individuals who knowingly obtain or disclose PHI in violation of HIPAA, with penalties escalating to up to 10 years imprisonment for disclosures made with intent to sell, transfer, or use PHI for commercial advantage, personal gain, or malicious harm.

Compliance Checklist

Policies and Procedures
Written uses and disclosures policy identifies all TPO purposes and applicable 164.512 exceptions
Minimum necessary policy defines access categories by workforce role
Authorisation forms contain all eight required elements under 45 CFR 164.508(c)
Accounting of disclosures procedure is documented and tested
Training
All workforce members trained on uses and disclosures policies at hire
Role-specific training covers each role’s specific access categories and permitted purposes
Training records retained showing content, date, and attendees
Refresher training triggered by material policy changes
Monitoring and Enforcement
Access logs reviewed periodically for workforce members accessing PHI outside their role category
Disclosure log maintained for non-TPO disclosures to support accounting requests
Workforce sanctions policy applied consistently for Privacy Rule violations
Complaints about improper disclosures investigated and documented

Key Takeaways

The permission framework has three tiers, not two
Most workforce training frames HIPAA as a binary: with authorisation you can share, without authorisation you cannot. The actual framework has three categories: required disclosures, permitted disclosures without authorisation, and disclosures requiring authorisation. Missing the middle tier, particularly the TPO permitted purposes and 45 CFR 164.512 exceptions, leads to both over-restriction that impedes care and under-restriction that creates violations.
Minimum necessary applies even when the disclosure is permitted
A common compliance misconception is that identifying a permitted purpose for a disclosure ends the analysis. It does not. The minimum necessary standard applies to most permitted uses and disclosures, including those for TPO. Policies must define what “minimum necessary” means in practice for each disclosure category, and access controls must enforce those definitions rather than leaving them to individual judgment.
Role-based training is not a training format preference; it is a compliance strategy
General HIPAA awareness training teaches the existence of the permission framework. It does not teach a registration clerk which disclosures are permitted in their specific context, or teach a researcher what the de-identification safe harbour requires. The gap between knowing HIPAA exists and knowing how it applies to your specific job function is where most workforce-level violations originate. Role-based training closes that gap by connecting the regulatory framework to the actual decisions each role makes.

Frequently Asked Questions

Can a covered entity disclose PHI to a patient’s family member without authorisation?
Yes, in specific circumstances under 45 CFR 164.510(b). A covered entity may disclose PHI to a family member, close friend, or other person identified by the individual if the individual has either agreed to or has been given an opportunity to object and has not objected. When the individual is not present or is incapacitated, the covered entity may use professional judgment to determine whether disclosure is in the individual’s best interest and limit the disclosure to what is relevant to the family member’s involvement in the individual’s care.

What is the difference between an authorisation and a consent under HIPAA?
HIPAA eliminated the general consent requirement for uses and disclosures for TPO when the Privacy Rule took effect. Consents for treatment, if required by state law or facility policy, are a separate matter from HIPAA authorisations. A HIPAA authorisation under 45 CFR 164.508 is a specific written permission for a particular use or disclosure that is not otherwise permitted by the Privacy Rule. It has eight required elements, is revocable, and does not expire unless an expiration date or event is specified in the document.

Does the minimum necessary standard apply to disclosures for treatment purposes?
No. The Privacy Rule explicitly exempts disclosures to healthcare providers for treatment purposes from the minimum necessary standard under 45 CFR 164.502(b)(2). This reflects the practical reality that treating providers may need access to a patient’s complete record to provide appropriate care. The minimum necessary standard does apply to TPO disclosures other than treatment disclosures to providers, and to most disclosures under 45 CFR 164.512.

How long must covered entities retain documentation of HIPAA training?
Under 45 CFR 164.530(j), six years from the date of creation or the date it was last in effect, whichever is later. For ongoing programmes, training records remain subject to this requirement for six years after the most recent entry. The absence of retained training documentation is itself a Privacy Rule violation independent of whether training actually occurred.

Government and Regulatory Sources

Related VelSafe Articles

Applying the Framework in Practice

The uses and disclosures framework in the HIPAA Privacy Rule is not particularly complex as regulatory frameworks go, but it does require that everyone who handles PHI know which tier their specific activities fall into. Workforce members who default to “we need authorisation for everything” over-restrict information flows that are legitimately permitted and may impede care coordination. Those who default to “we can share if there is a good reason” under-restrict and create violation exposure. Role-based training that maps the specific uses and disclosures each job function actually performs to the applicable regulatory tier is what produces consistent, defensible decisions across the workforce. Find more HIPAA compliance resources at velsafe.com.

Tags: No tags

Add a Comment

Your email address will not be published. Required fields are marked *