Uses and disclosures, minimum necessary, patient rights, and the operational workflows each one demands.
What the Privacy Rule is
The Privacy Rule, at 45 CFR Part 164 Subpart E, governs all protected health information in any form — spoken, paper, electronic — held by covered entities and, in relevant part, business associates. Where the Security Rule asks “is ePHI protected from unauthorised access?”, the Privacy Rule asks the prior question: “was this use or disclosure permitted at all, and did the individual get the rights the rule grants them?” A perfectly secured system can still violate the Privacy Rule with every query it serves, if the people querying it have no permissible purpose.
The organisational scaffolding the rule requires: a designated Privacy Officer, workforce training on the policies, a complaint process, safeguards for PHI in all forms (this is where paper and verbal privacy live), and documentation kept six years — the same retention discipline as everything else in HIPAA.
Permitted uses and disclosures
Treatment, payment, and healthcare operations do not require authorisation. Nearly everything else does, and marketing and sale of PHI have specific heightened rules.
The rule’s structure is a permission system with three layers. Treatment, payment, and healthcare operations (TPO) are the broad lane — a clinician consulting a colleague, a claim going to a payer, internal quality review. A middle layer of specifically permitted disclosures covers public health reporting, disclosures required by law, and similar defined situations, each with its own conditions. Everything else requires a valid written authorisation from the individual: specific about what is disclosed, to whom, for what purpose, with an expiry, signed and dated, and revocable. Marketing uses and any sale of PHI sit behind heightened authorisation requirements precisely because they are where commercial incentives push hardest.
The operational failure is rarely a deliberate impermissible disclosure. It is the accumulation of casual ones: PHI in a support ticket to a vendor without a BAA, a testimonial used without authorisation, patient details in an analytics tool “just for debugging”. A workforce that can articulate the three layers catches most of these before they happen — which is the practical case for training that goes beyond the annual video.
Minimum necessary
Applies to most uses and disclosures but not to treatment. Operationally this means role-based access, not blanket access with a policy saying be careful.
Minimum necessary requires that uses, disclosures, and requests involve the least PHI reasonably needed for the purpose. The treatment exception exists because clinicians should never be rationing information at the bedside; almost everything else is in scope. Turning the principle into a programme means three concrete things: role-based access profiles that define which classes of PHI each role can see (this is where the Privacy Rule and the Security Rule’s access controls meet); standard protocols for routine, recurring disclosures so each one is not re-reasoned from scratch; and individual review for non-routine requests. The anti-pattern OCR sees constantly is the flat-access organisation — everyone can open every record, with a policy asking them nicely not to. Access logs at such an organisation are a liability inventory.
Patient rights
Access within 30 days, amendment, restriction requests, accounting of disclosures, confidential communications, and the right to a paper Notice of Privacy Practices.
Each right implies a workflow, and the workflow is what compliance actually consists of:
- Access — individuals can inspect and obtain a copy of PHI in their designated record set, within 30 days (one 30-day extension with written notice), in the form and format they request if readily producible, for no more than a reasonable, cost-based fee.
- Amendment — individuals can request corrections; you may deny on defined grounds, but the denial must be written, and the individual can file a statement of disagreement that travels with the record.
- Restriction — individuals can request limits on uses and disclosures; most requests may be declined, but the restriction on disclosures to a health plan for services paid fully out of pocket must be honoured.
- Accounting of disclosures — a list of certain disclosures over the prior six years, which you can only produce if you have been logging them all along.
- Confidential communications — reasonable requests to be contacted by alternative means or at alternative locations must be accommodated.
- The Notice — a plainly written Notice of Privacy Practices describing uses, disclosures, and rights, provided and posted as the rule prescribes, on paper if asked.
The access right in practice
Right-of-access enforcement has been one of OCR’s most consistently pursued areas. The failure mode is almost always operational: no owner, no clock, no record.
The pattern in enforcement is consistent: a patient asks for records, the request bounces between departments or vendors, deadlines pass, the patient complains to OCR, and the organisation cannot show when the request arrived or what happened to it. None of that requires bad faith — only the absence of a workflow. The fix is correspondingly unglamorous: one named owner for access requests, a log capturing every request with its receipt date, a clock that alerts before day 30, a defined designated record set so scope arguments do not consume the window, and fee practices reviewed against the cost-based standard. If part of your record set lives with a vendor or EHR, your BAA must oblige them to support these timelines, because the 30 days are yours regardless of where the data sits.
Where the Privacy Rule meets your programme
For business associates, the Privacy Rule arrives mostly via contract: your BAA defines your permitted uses, and exceeding them is both a breach of contract and a regulatory violation. For covered entities, the rule is the reason your policy set cannot stop at security topics — notice, minimum necessary, authorisations, and patient-rights procedures belong in the core policy library, with the same versioning, acknowledgement, and six-year retention as the rest.
Verbal and paper PHI — the forgotten half
Because the Security Rule dominates compliance conversations, teams forget that the Privacy Rule’s safeguards obligation covers PHI in every form. The waiting-room conversation audible at reception, the schedule printout on the desk, the whiteboard with patient names, the voicemail left with a family member — each is a Privacy Rule question no encryption setting answers. The rule expects reasonable safeguards proportionate to your operations: lowered voices and positioned screens, locked storage for paper, a fax and mail verification habit, and a policy on leaving messages. Incidental disclosures that occur despite reasonable safeguards are permitted; the same disclosures without the safeguards are violations. It is a low bar, but it must be documented and trained like everything else — and it is the half of the rule a walk-through audit tests first.
Where SuperHIPAA fits
Everything above is work. The platform does the parts that are mechanical — evidence collection, acknowledgement tracking, register maintenance, renewal reminders — and our team does the parts that need judgement. You keep the parts that need to be yours.
Start where you are
Take the free readiness assessment — 24 questions, about eight minutes, no call required. You get a scored report identifying which required specifications you are missing and what to fix first. If it turns out you are further along than you thought, we will tell you that too.