HIPAA is often described as a law that makes all medical information private. The real rule is more specific. The Health Insurance Portability and Accountability Act and its regulations create national standards for certain health information handled by covered entities and business associates. The core HIPAA rules appear in 45 CFR Parts 160 and 164. 1

HIPAA protects health information while still allowing health care to function. It limits how protected health information may be used or disclosed, requires safeguards, gives individuals rights over their information, and creates enforcement and breach-notification duties. It does not make every health-related fact confidential in every person’s hands, and it does not require patient authorization for every permitted disclosure.

What Do 45 CFR Parts 160 and 164 Cover?

45 CFR Part 160 contains general administrative requirements, definitions, compliance and investigation provisions, and civil money penalty procedures that support HIPAA’s Administrative Simplification rules. 45 CFR Part 164 contains several major protections:

  • The Privacy Rule in Subparts A and E regulates uses and disclosures of protected health information and creates individual rights.
  • The Security Rule in Subparts A and C protects electronic protected health information through administrative, physical, and technical safeguards.
  • The Breach Notification Rule in Subpart D requires notification after certain breaches of unsecured protected health information.

These rules work together. Privacy asks whether information may be used or disclosed. Security focuses on protecting electronic information. Breach notification addresses what must happen after certain improper acquisitions, access, uses, or disclosures.

Who Must Follow HIPAA?

HIPAA directly applies to covered entities and, for many requirements, their business associates. Covered entities include:

  • Health plans.
  • Health care clearinghouses.
  • Health care providers that transmit health information electronically in connection with a HIPAA-standard transaction, such as certain billing or eligibility transactions.

A provider does not become covered merely because the provider uses email or stores notes on a computer. The electronic transmission must relate to a transaction for which HHS adopted a standard. Many doctors, hospitals, clinics, psychologists, pharmacies, and insurers are covered, but not every person or organization offering a health-related service is. 2

A business associate is generally a person or organization outside the covered entity’s workforce that performs certain functions or services involving protected health information—for example, some billing companies, cloud vendors, consultants, claims processors, or record-storage services. A covered entity usually needs a written business associate agreement requiring appropriate protection and limiting how the information may be used or disclosed.

HIPAA Does Not Cover Everyone

HIPAA may not directly regulate information held by an employer acting as an employer, many schools, life insurers, law enforcement agencies, consumer health apps, social media companies, or a private person. Some of those records may be protected by a different law or contract. For example, many education records are governed by FERPA rather than HIPAA, and employment records maintained by a covered entity in its role as an employer are excluded from protected health information. 2

This distinction explains why saying “that is a HIPAA violation” is sometimes inaccurate. The first questions are who created or holds the information, in what role, and whether that person or organization is regulated by HIPAA.

What Is Protected Health Information?

The Privacy Rule protects individually identifiable health information held or transmitted by a covered entity or business associate in electronic, paper, or oral form. This is called protected health information, or PHI. It includes information that identifies a person—or reasonably could identify the person—and relates to:

  • The person’s past, present, or future physical or mental health or condition.
  • Health care provided to the person.
  • Past, present, or future payment for health care.

PHI may include names, addresses, dates, account numbers, photographs, diagnoses, therapy information, prescriptions, laboratory results, billing records, and conversations about care. The content does not need to reveal an unusual diagnosis. Even an appointment reminder can reveal that an identified person has a relationship with a provider.

Properly de-identified health information is not PHI. HIPAA recognizes two de-identification methods: an expert determination or removal of specified identifiers with no actual knowledge that the remaining information could identify the person. Removing only a name may not be enough when other details still point to one individual. 2

The Basic Privacy Rule

A covered entity may not use or disclose PHI unless the Privacy Rule permits or requires it or the individual provides a valid written authorization. 2 This is not the same as saying authorization is always necessary. HIPAA intentionally allows many routine and public-interest disclosures without authorization.

Treatment, Payment, and Health Care Operations

HIPAA generally allows covered entities to use and disclose PHI for treatment, payment, and health care operations—often shortened to TPO—without obtaining a separate authorization. 3

  • Treatment includes providing, coordinating, or managing health care, consultation between providers, and referrals.
  • Payment includes billing, claims, eligibility, coverage, medical necessity review, utilization review, and collection activities.
  • Health care operations include defined activities such as quality improvement, credentialing, training, auditing, compliance, care coordination, customer service, and business management.

For example, a therapist may coordinate care with another treating provider when HIPAA permits it, a clinic may submit a claim to an insurer, and a health plan may review a claim for coverage. Another law may still be stricter. Substance use disorder records protected by Part 2, separately maintained psychotherapy notes, and information protected by stronger state law require additional analysis.

Other Disclosures HIPAA May Permit

The Privacy Rule permits certain disclosures without authorization when its conditions are met. Examples include:

  • Sharing information with the individual.
  • Giving a person an opportunity to agree or object to certain disclosures involving family, friends, or facility directories.
  • Public health activities.
  • Reporting abuse, neglect, or domestic violence under applicable conditions.
  • Health oversight activities.
  • Judicial and administrative proceedings under specified rules.
  • Certain law-enforcement purposes.
  • Preventing or lessening a serious and imminent threat to health or safety under the rule’s conditions.
  • Workers’ compensation and other disclosures required by law.
  • Research conducted with authorization or an approved waiver and other required protections.

“HIPAA permits” does not necessarily mean “HIPAA requires.” A covered entity may often use professional judgment and must also consider other laws, the facts, and its notice and policies. HIPAA requires disclosure in only limited circumstances, including to the individual for certain access and accounting rights and to HHS for enforcement. 2

The Minimum Necessary Standard

When the minimum necessary standard applies, a covered entity must make reasonable efforts to use, request, or disclose only the PHI reasonably needed for the purpose. The entire chart should not be released by default when a smaller portion will do. Organizations must also use role-based access so workforce members can reach only the information needed for their jobs. 2

Minimum necessary has exceptions. It generally does not apply to disclosures to or requests by a health care provider for treatment, disclosures to the individual, uses or disclosures made under an authorization, disclosures to HHS for enforcement, uses or disclosures required by law, or those required for HIPAA administrative transactions. Even when minimum necessary does not formally apply, other confidentiality rules and good security practices may still limit access.

Psychotherapy Notes Receive Special Treatment

HIPAA defines psychotherapy notes narrowly as notes recorded by a mental health professional documenting or analyzing a counseling-session conversation that are kept separate from the rest of the medical record. They do not include medication information, session times, treatment modalities and frequency, test results, or summaries of diagnosis, functional status, treatment plan, symptoms, prognosis, and progress.

Most uses and disclosures of psychotherapy notes require the individual’s authorization, with limited exceptions. This special rule does not mean the entire behavioral health chart is a psychotherapy note, and it does not make psychotherapy notes completely immune from every lawful disclosure. 2

Your Rights Under HIPAA

When HIPAA applies, individuals have several enforceable rights. 4

Access and copies

You generally have the right to inspect and obtain a copy of PHI in a designated record set, including many medical, billing, enrollment, claims, and case-management records used to make decisions about you. Limited exceptions apply, including psychotherapy notes and information prepared for certain legal proceedings. A denial may carry review rights depending on the reason.

Amendment

You may ask a covered entity to amend information you believe is incorrect or incomplete. The provider does not have to erase an accurate professional opinion merely because you disagree, but it must follow the rule’s process and may need to let you submit a statement of disagreement.

Notice of Privacy Practices

You have the right to a notice explaining how the covered entity may use and disclose PHI, its legal duties, your rights, and how to complain. Read the notice before assuming that every internal or care-related disclosure requires a separate release.

Restrictions

You may request restrictions on uses or disclosures for treatment, payment, or health care operations and on certain disclosures to people involved in your care. A covered entity usually does not have to agree. One important exception generally requires a provider to honor a request not to disclose information to a health plan for payment or operations when the disclosure is not required by law and the individual has paid the provider in full out of pocket for that item or service.

Confidential communications

You may request contact by an alternative method or at an alternative location—for example, asking a clinic to use a particular phone number or mailing address. Providers must accommodate reasonable requests without requiring an explanation, though they may require information about how payment will be handled. Health plans have a related duty when the person states that ordinary communication could endanger them.

Accounting of disclosures

You may request an accounting of certain disclosures made during the applicable period. The accounting does not include every disclosure; common exclusions include disclosures for treatment, payment, and health care operations, disclosures to you, and disclosures made under your authorization.

Complaints without retaliation

You may complain to the covered entity and to the HHS Office for Civil Rights. HIPAA prohibits retaliation for filing a complaint, participating in an investigation, or exercising a right under the rule.

Protecting Electronic Health Information

The Security Rule applies specifically to electronic PHI, or ePHI. Covered entities and business associates must use administrative, physical, and technical safeguards designed to protect confidentiality, integrity, and availability. They must protect against reasonably anticipated threats, improper uses or disclosures, and workforce noncompliance. 5

HIPAA does not prescribe one identical security setup for every organization. Safeguards are designed to be scalable based on factors such as size, complexity, capabilities, technical infrastructure, costs, and risks. Examples may include risk analysis, access controls, workforce training, device and facility protections, authentication, audit controls, contingency planning, and transmission security.

What Happens After a Breach?

A breach is generally an impermissible acquisition, access, use, or disclosure of unsecured PHI that compromises its security or privacy, unless an exception applies or the organization demonstrates through the required risk assessment that there is a low probability the PHI was compromised. The Breach Notification Rule may require notice to affected individuals, HHS, and, for certain large breaches, the media.

Not every privacy mistake is legally a reportable breach, but every suspected incident should be reported promptly through the organization’s privacy or security process so it can be investigated, contained, documented, and evaluated.

Common HIPAA Misunderstandings

  • “A patient must sign before two providers can discuss treatment.” HIPAA usually permits provider-to-provider disclosures for treatment without authorization, although another law may be stricter.
  • “HIPAA prevents a family member from telling the provider anything.” HIPAA regulates the covered entity’s handling of PHI; it does not prevent a relative from offering information to the provider.
  • “If someone says my diagnosis aloud, it is automatically a HIPAA violation.” It depends on who disclosed it, in what role, and under what circumstances.
  • “I own the original medical chart.” Patients generally have access and copy rights, but state law usually determines ownership of the physical or electronic record.
  • “A subpoena always means the whole chart must be released.” Judicial disclosures have conditions, and state privilege, Part 2, or another law may require additional protection.
  • “HIPAA blocks required child-abuse reports.” HIPAA permits disclosures required by law and has provisions addressing abuse and neglect. State reporting law determines the reporting duty.

How HIPAA Works With Michigan Mental Health Law and Part 2

HIPAA is a federal floor, not always the final answer. State laws that provide greater privacy protection or stronger privacy rights may remain effective. Michigan Mental Health Code Section 748 protects records and information acquired while providing qualifying mental health services. 6

42 CFR Part 2 may protect records identifying a patient as having or having had a substance use disorder when the records come from a qualifying federally assisted Part 2 program. Part 2 has special restrictions on using records in proceedings against the patient. A Michigan behavioral health provider may therefore need to analyze HIPAA, Section 748, Part 2, professional privilege, and mandatory-reporting laws before releasing information.

If You Think Your HIPAA Rights Were Violated

  1. Write down the date, people involved, information affected, and what happened.
  2. Contact the provider or health plan’s privacy officer and request its complaint procedure.
  3. Keep copies of requests, responses, notices, and authorizations.
  4. File a complaint with the HHS Office for Civil Rights. A complaint generally must be written and filed within 180 days of when you knew of the act, although OCR may extend the period for good cause. 7
  5. Seek legal advice when the issue caused significant harm or involves litigation, employment, custody, discrimination, identity theft, or another law.

OCR can investigate covered entities and business associates, but it cannot enforce HIPAA against a person or organization that HIPAA does not regulate. Another privacy, consumer-protection, licensing, education, employment, or state law may still apply.

The Main Point

HIPAA does not prohibit all sharing of health information. It creates rules for covered entities and business associates: use or disclose PHI only as permitted or authorized, safeguard it, limit it to the minimum necessary when that standard applies, respond to individual rights, and address breaches and complaints. The most useful starting questions are: Who holds the information? Is that person or organization covered by HIPAA? Is the information PHI? What purpose and rule authorize the use or disclosure? Does another law provide stronger protection?

References

  1. U.S. Department of Health and Human Services. “The HIPAA Privacy Rule.”
  2. U.S. Department of Health and Human Services. “Summary of the HIPAA Privacy Rule.”
  3. U.S. Department of Health and Human Services. “Uses and Disclosures for Treatment, Payment, and Health Care Operations.”
  4. U.S. Department of Health and Human Services. “Your Rights Under HIPAA.”
  5. U.S. Department of Health and Human Services. “Summary of the HIPAA Security Rule.”
  6. Michigan Legislature. “MCL 330.1748: Confidentiality.”
  7. U.S. Department of Health and Human Services, Office for Civil Rights. “How to File a Health Information Privacy or Security Complaint.”