HIPAA: What You Can and Can’t Disclose

HIPAA, the Health Insurance Portability and Accountability Act, has been around since 1996. One of its primary directives is to protect the privacy and security of patients’ health information.

Specific organizations and individuals, referred to as “Covered Entities,” are subject to the Privacy Rules and include healthcare providers, health plans, healthcare clearing houses, and business associates.

These organizations are responsible for maintaining the privacy and confidentiality of patient information.

Of course, that doesn’t mean PHI (Personal Health Information) is always safe and protected; violations do occur.

Violations of HIPAA occur across all types and sizes of organizations, although breaches in larger organizations tend to receive more publicity.

Smaller organizations, including private practices, often unintentionally violate HIPAA regulations.

This may happen in several ways, including:

  • Forgetting to obtain proper authorization before releasing records
  • Unauthorized access to PHI… accessing health records without a legitimate reason
  • Lack of adequate protection of electronic records: weak or no access controls or security protocols, etc.
  • Inadequate or no training of staff
  • Lack of proper risk assessment to uncover vulnerabilities in practice workflows and systems
  • Mishandling of records, e.g., leaving records in exam rooms or public areas where people can access them

While mistakes and omissions happen, healthcare providers and their staff must understand what can be disclosed, under what circumstances, and what cannot be disclosed.

Unfortunately, smaller offices may be at a disadvantage and more vulnerable to potential violations because they typically have fewer resources available.

There is no IT or training department, and no risk assessment professional to step in. Usually, the provider and staff are it!

What Can Be Released

Now, let’s review which information can be released and which cannot.

Ultimately, the buck stops with you; you are accountable for obeying the law, and therefore, it’s essential that you know what’s in the law.

HIPAA applies to all formats, including spoken, written, electronic, and visual, and includes the following PHI, Protected Health Information:

  • Patient names, addresses, phone numbers
  • Social Security numbers
  • Dates (birth, admission, discharge, death)
  • Medical records and diagnoses
  • Insurance information
  • Any identifiable health data related to past, present, or future health conditions

 You Can Release PHI

  • Directly to the patient
    Patients have the right to access their medical records.
  • For treatment, payment, and healthcare operations (TPO)
    Sharing information with another provider for continuity of care
    For purposes of internal quality control reviews
    Submitting claims to insurance for payment
  • Authorization is not needed when records are requested by law
    Public health reporting (e.g., infectious disease)
    Reporting abuse, neglect, or domestic violence
    Subpoenas or court orders (with proper documentation)
  • Authorization/a signed release is required from business associates who work with you:
    If you work with a third party, such as a billing company or an EHR vendor, you can share PHI with them only if a signed Business Associate Agreement (BAA) is in place.

You Are Not Allowed to Release PHI Without Written Authorization

  • To employers, even if an employer is paying the bill, without written authorization from the patient, you are not allowed to share information.
  • If a patient wishes to share personal health information with family, friends, attorneys, employers, etc., authorization to release records is required and must be specific and in writing.  Unless the patient has granted permission or it’s a clear emergency, avoid disclosure, even if it “should be okay.”
  • For marketing purposes, on social media or marketing materials. Do not disclose patient stories, photos, or testimonials without signed consent on file.
  • For 50 years after a person’s death, HIPAA protection remains in force. Information can only be released with the authorization of the deceased’s family or personal representative. There are exceptions to this rule, including organ donation, research, or law enforcement requests.
  • Without proper verification of the recipient. Always confirm the identity and proper authority of the person requesting the information.

Mental Health And Communicable Disease Information

When it comes to highly sensitive information like mental health and communicable diseases, HIPAA imposes stricter rules.

Mental Health Information Can Be Disclosed

  • To other treating providers (for continuity of care)
    You may share mental health information with another healthcare provider involved in the patient’s treatment without patient authorization; however, you must use professional judgment and disclose only what’s minimally necessary.
  • To prevent serious harm
    If a patient poses a serious and imminent threat to themselves or others, you can disclose information to appropriate parties (e.g., law enforcement, family, crisis response teams) to prevent harm.
  • To parents or legal guardians of minors
    In most states, parents can access a minor’s mental health information unless the minor is legally permitted to consent to treatment on their own (e.g., emancipation, mature minor doctrine, substance use treatment). Know what’s in your state law

Mental Health Information That Cannot Be Disclosed

  • Therapy notes, which have extra protection under HIPAA. These are separate from the rest of the medical record and cannot be disclosed without the patient’s explicit written authorization (except for legal or safety exceptions).
  • Disclosures to employers or family members are not allowed without specific consent.

Communicable Disease Disclosure is Allowed or Required

  • Public health reporting
    HIPAA allows or may require disclosure of certain infectious or communicable diseases (like HIV, TB, STIs, COVID-19) to local or state health departments.
  • Partner notification, in some cases, providers are allowed or required to notify partners at risk of exposure (e.g., with HIV/STIs), usually through public health departments.
  • School or daycare notifications of certain communicable conditions, including measles or meningitis, may be reported to schools/daycares to prevent outbreaks, in line with state law.

Communicable Disease Disclosure Requiring Authorization

  • Informing a patient’s employer, roommate, or family member about their infectious disease status, unless it is required by law, or the patient has given written authorization.
  • Sharing HIV status, for example, outside of permitted channels without clear legal backing may violate HIPAA and state law.
  • Some states have stricter privacy protections than HIPAA, especially for mental health, HIV/Aids, and substance use.
  • When state law is more protective than HIPAA, you must follow state law, the stricter standard.

Common Mistakes to Avoid

When the office gets hectic, it’s easy to make mistakes. Here are some things to avoid, regardless of how busy it gets or how stressed you and your staff feel.

  • Discussing patients in public areas (front desk, hallways, waiting area)
  • Faxing/emailing to the wrong number/email
  • Leaving voicemail messages with detailed personal information
  • Sending unencrypted emails containing PHI
  • Not following the Minimum Necessary Rule and providing too much information to third parties… Sending all or too much information to satisfy a request for records by insurance or third parties, instead of sending only the minimum necessary. Submitting more than the minimum necessary information may constitute a HIPAA violation.
  • Lack of developing proper policies that outline the use of PHI to only submit the minimum necessary information, upon requests for records.

Consequences of HIPAA Violations…

HIPAA violations can lead to serious consequences, including fines, criminal charges, and, of course, professional damage, even for small practices.

The Office for Civil Rights (OCR) at the Department of Health & Human Services enforces HIPAA, using a tiered penalty structure based on the intent and the severity of the violation.

Here is an overview of what could happen when you break HIPAA rules, published by the HIPAA Journal.

Best Practices

I think it’s safe to say that nobody reading this article wants to violate HIPAA rules intentionally.

But mistakes can and do happen.

To minimize or avoid them altogether, it’s best to act proactively and adopt best practices when it comes to HIPAA.

How to protect your practice…

  • Always verify the identity of the requester before releasing any information
  • Obtain proper authorization
  • Follow the minimum necessary disclosure requirements
  • Keep authorization forms on file
  • Have Business Associate Agreements (BAAs) in place
  • Train staff regularly on HIPAA guidelines and updates
  • Set clear expectations regarding HIPAA
  • Conduct periodic security risk assessments
  • Review and update your privacy policies regularly
  • Document policies, procedures, and incident responses
  • Use secure systems (EHR, email, cloud storage)
  • Encrypt devices and protect mobile access

In Summary…

Knowing what you can and cannot release under HIPAA isn’t just about avoiding fines. It’s about protecting the privacy of your patients and building trust with them.

And of course, it’s about staying within the law.

Stay informed and up-to-date about all things HIPAA so you know your responsibilities. Stay alert, exercise caution, and take proactive measures.

And…

Never disclose more information than necessary, and only after obtaining the proper authorizations.


Tell us what you think, we’d love to hear from you…


By Johanna Hofmann, MBA, MAc., EAMP; regular contributor to the NPBusiness blog.

Leave a Reply


Your email address will not be published. Required fields are marked

This site uses Akismet to reduce spam. Learn how your comment data is processed.

  1. Wow this is amazing and timely!

    Specifically, this point above, "To employers, even if an employer is paying the bill, without written authorization from the patient, you are not allowed to share information."

    I just had a conversation TODAY with a colleague who sends this information without written consent and thought it was within the scope of HIPAA. I am sending her this information now!

    I do have 2 follow up questions:

    1- Doing CDL physicals which are "credentialed" by the FMCSA (Federal motor carrier safety administration). As a provider we log ALL results on their database which is protocol. But I always have patients call and ask for their medical certification card to be faxed to a local DMV. This is identifying they are medically cleared for driving with this level credential, has name, address, license number and any medical restrictions (glasses, diabetic waiver etc) and my name and signature.

    To fax to the DMV, do we need a written consent? I called FMCSA to ask 3 times now over the last 5 years and they say they are not an expert in HIPAA and consult someone else. Haven't found anyone to clarify this! Thanks!

    2- Our office has a HIPAA compliant text option with SPRUCE Health. Verbally we always tell the pt to download the app to send secure messages. Beyond that, 99% of pt's just text us from their phone to our SPRUCE app. Often this is photo's (like rashes etc).
    Since we are always verbalizing the modality which ensures their privacy, but they opt to just text, is that acceptable?
    I suspect it is when they send to us. But then if I respond, is that the same? Do we need this to be in the consents they sign as a new patient?

    Like if I say, "that looks like hives, lets schedule you an appt" or "are you still taking Synthroid at 100mcg", would that be a breach if they weren't on SPRUCE app?

  2. Great questions Rachel.
    1. I would say you need a ROI to send to the DMV. They are not part of the healthcare team for this persons care. If possible, give them the card at the time of the appointment, and let them do what they want with it.

    2. If they send info, it’s on them. It’s good to let them know it’s not private when they do this, and if they want privacy, use the secure app or send the message via a portal. That said, we all know patients share their rash photos on Facebook, etc. If they do, it’s on them. However, your responses should be limited to calling the office or scheduling an appointment so we can discuss something along those lines. (I once had a patient find an email address that was not healthcare-related and send me a very long, detailed, sensitive health history. It concerned me, but then I was not the one sharing the info, or even commenting. I simply picked up the phone and scheduled an appointment and shared with her that her information is not private when she does that.)

{"email":"Email address invalid","url":"Website address invalid","required":"Required field missing"}