Emergency Disclosures
Emergency disclosures refer to situations where a covered entity may share protected health information (PHI) without the usual authorization during emergencies, such as public health events or to help respond to a crisis. Even in these situations, the amount of information shared generally must be limited to what is reasonably needed. Specific rules can vary depending on the circumstances and the type of information involved, so the applicable regulatory guidance should be consulted.
Under the HIPAA Privacy Rule, emergency disclosures describe permitted disclosures of PHI by covered entities in emergency or emergency-preparedness situations, including certain public health purposes. Such disclosures generally remain subject to the minimum necessary standard, meaning covered entities must limit the PHI disclosed to that reasonably necessary to accomplish the intended purpose, except where an exception to minimum necessary applies. This term addresses only the Privacy Rule's permissible-disclosure framework for PHI in all forms and does not, by itself, encompass Security Rule safeguards for ePHI. Additional or stricter requirements may apply under other authorities, such as 42 CFR Part 2 for substance use disorder records (which imposes its own medical-emergency disclosure documentation obligations) and applicable state laws (for example, provisions governing emergency disclosure of mental health information); practitioners should verify the specific requirements against the current regulatory text.
Why it matters
Emergencies, whether a natural disaster, a disease outbreak, or an individual medical crisis, create pressure to share health information quickly, sometimes before the usual consent or authorization processes can be followed. The HIPAA Privacy Rule anticipates this by permitting certain disclosures of protected health information (PHI) without individual authorization in emergency and emergency-preparedness situations, including for specified public health purposes. For compliance professionals, understanding this framework matters because it defines a narrow, permission-based path for sharing information during a crisis while still preserving the individual's privacy interests.
A common misconception is that an emergency suspends HIPAA's requirements entirely. It does not. Even when a disclosure is permitted, it generally remains subject to the minimum necessary standard, meaning the covered entity must limit what it shares to the PHI reasonably needed for the intended purpose (unless a recognized exception to minimum necessary applies). Getting this balance wrong in either direction carries risk: over-disclosure can result in a Privacy Rule violation, while under-disclosure can impede a legitimate emergency response. Clear internal guidance helps staff act appropriately under time pressure.
The stakes are heightened by overlapping authorities that impose their own, sometimes stricter, requirements. Substance use disorder records governed by 42 CFR Part 2 carry a distinct medical-emergency disclosure framework with its own documentation obligations, and state laws may add requirements, such as limiting emergency disclosures of mental health information to the minimum necessary to initiate or seek emergency hospitalization. Because these rules can differ from and add to the HIPAA baseline, professionals should confirm the specific obligations against the current regulatory text for the type of information and jurisdiction involved.
Who it's relevant to
Inside Emergency Disclosures
Common questions
Answers to the questions practitioners most commonly ask about Emergency Disclosures.