Skip to main content
Category: Uses and Disclosures

Emergency Disclosures

Also known as: Disclosures in Emergency Situations, Disclosures in Emergency Preparedness Situations
Simply put

Emergency disclosures refer to situations where a covered entity may share protected health information (PHI) without the usual authorization during emergencies, such as public health events or to help respond to a crisis. Even in these situations, the amount of information shared generally must be limited to what is reasonably needed. Specific rules can vary depending on the circumstances and the type of information involved, so the applicable regulatory guidance should be consulted.

Formal definition

Under the HIPAA Privacy Rule, emergency disclosures describe permitted disclosures of PHI by covered entities in emergency or emergency-preparedness situations, including certain public health purposes. Such disclosures generally remain subject to the minimum necessary standard, meaning covered entities must limit the PHI disclosed to that reasonably necessary to accomplish the intended purpose, except where an exception to minimum necessary applies. This term addresses only the Privacy Rule's permissible-disclosure framework for PHI in all forms and does not, by itself, encompass Security Rule safeguards for ePHI. Additional or stricter requirements may apply under other authorities, such as 42 CFR Part 2 for substance use disorder records (which imposes its own medical-emergency disclosure documentation obligations) and applicable state laws (for example, provisions governing emergency disclosure of mental health information); practitioners should verify the specific requirements against the current regulatory text.

Why it matters

Emergencies, whether a natural disaster, a disease outbreak, or an individual medical crisis, create pressure to share health information quickly, sometimes before the usual consent or authorization processes can be followed. The HIPAA Privacy Rule anticipates this by permitting certain disclosures of protected health information (PHI) without individual authorization in emergency and emergency-preparedness situations, including for specified public health purposes. For compliance professionals, understanding this framework matters because it defines a narrow, permission-based path for sharing information during a crisis while still preserving the individual's privacy interests.

A common misconception is that an emergency suspends HIPAA's requirements entirely. It does not. Even when a disclosure is permitted, it generally remains subject to the minimum necessary standard, meaning the covered entity must limit what it shares to the PHI reasonably needed for the intended purpose (unless a recognized exception to minimum necessary applies). Getting this balance wrong in either direction carries risk: over-disclosure can result in a Privacy Rule violation, while under-disclosure can impede a legitimate emergency response. Clear internal guidance helps staff act appropriately under time pressure.

The stakes are heightened by overlapping authorities that impose their own, sometimes stricter, requirements. Substance use disorder records governed by 42 CFR Part 2 carry a distinct medical-emergency disclosure framework with its own documentation obligations, and state laws may add requirements, such as limiting emergency disclosures of mental health information to the minimum necessary to initiate or seek emergency hospitalization. Because these rules can differ from and add to the HIPAA baseline, professionals should confirm the specific obligations against the current regulatory text for the type of information and jurisdiction involved.

Who it's relevant to

Privacy Officers and Compliance Staff
Privacy officers translate the Privacy Rule's emergency-disclosure permissions into practical, defensible internal procedures. They are responsible for ensuring staff understand when authorization-free disclosures are permitted, how the minimum necessary standard applies, and where overlapping authorities such as 42 CFR Part 2 or state law impose stricter obligations. They should confirm requirements against current regulatory text rather than relying on a general assumption that emergencies relax the rules.
Clinical and Front-Line Workforce
Physicians, nurses, and other staff who respond to crises need clear guidance on what they may share and with whom during an emergency. Because these disclosures generally remain subject to minimum necessary, front-line workers benefit from concrete examples and escalation paths so they can act quickly without over-disclosing PHI.
Behavioral Health and SUD Program Staff
Programs handling substance use disorder records under 42 CFR Part 2 or mental health information under state law face additional emergency-disclosure requirements beyond the HIPAA baseline. For Part 2 records, this can include creating written documentation immediately after a medical-emergency disclosure. Staff in these settings should treat the HIPAA framework as a floor and verify the specific Part 2 and state-law obligations that apply.
Emergency Preparedness and Public Health Coordinators
Those planning for disasters, outbreaks, and other emergency-preparedness scenarios rely on this framework to determine what PHI can be shared for public health and response purposes. They should build minimum-necessary considerations into response plans and coordinate with legal and privacy teams to account for any additional authorities that apply.

Inside Emergency Disclosures

Treatment-Related Emergency Disclosures
Under the HIPAA Privacy Rule, a covered entity may generally disclose PHI without individual authorization when necessary to provide treatment in an emergency, including to other providers involved in the individual's care. This applies to PHI in all forms, not only ePHI.
Disclosures to Avert a Serious Threat
The Privacy Rule generally permits disclosures, consistent with applicable law and ethical standards, that a covered entity believes in good faith are necessary to prevent or lessen a serious and imminent threat to the health or safety of a person or the public, made to those reasonably able to prevent or lessen the threat.
Disaster Relief Disclosures
The Privacy Rule generally allows disclosure of PHI to public or private entities authorized by law or charter to assist in disaster relief efforts, to coordinate notification of family or those involved in the individual's care regarding location, condition, or death.
Notification of Family and Others Involved in Care
In emergency circumstances where the individual is incapacitated or unavailable, a covered entity may generally use professional judgment to determine whether disclosure to family members, relatives, or others involved in care is in the individual's best interest.
Minimum Necessary Considerations
Many emergency disclosures remain subject to the minimum necessary standard, though treatment disclosures are generally excepted. Practitioners should distinguish treatment purposes from other permitted purposes when applying this limitation.
Relationship to Waivers and Enforcement Discretion
During declared public health emergencies, HHS OCR may issue limited enforcement discretion or waive certain sanctions under specified conditions. Any such measures are time-limited and scope-limited and should be confirmed against current OCR guidance for the applicable event.

Common questions

Answers to the questions practitioners most commonly ask about Emergency Disclosures.

Does HIPAA prohibit disclosing PHI during an emergency without patient authorization?
No. This is a common misconception. The Privacy Rule generally permits certain disclosures of PHI without individual authorization in emergency situations, such as for treatment purposes or to persons involved in the individual's care when the individual is incapacitated or unavailable. The rule is designed to permit, not obstruct, appropriate emergency response. That said, permitted disclosures are subject to conditions, and the minimum necessary standard applies to many (though not all) disclosures. Readers should confirm the specific permission being relied upon against the current regulatory text and consider any additional state-law requirements.
Does declaring an emergency suspend all HIPAA obligations for a covered entity?
No. An emergency, including a public health emergency, does not broadly suspend HIPAA. Certain limited waivers of specified Privacy Rule provisions may be issued by the appropriate federal authority under defined circumstances, but such waivers are typically narrow in scope, time-limited, and tied to particular conditions. The Security Rule's protections for ePHI and the broader framework generally remain in effect. Covered entities should not assume blanket relief and should verify the precise terms and duration of any waiver against current official guidance.
How should staff determine what PHI to disclose to family members when a patient is incapacitated?
In most cases, when a patient is incapacitated or otherwise unable to agree or object, a covered entity may exercise professional judgment to determine whether disclosing PHI to a family member or other person involved in the individual's care is in the patient's best interest, and may generally disclose only the PHI directly relevant to that person's involvement. Documenting the basis for the judgment is a common practice. Because the applicable conditions can be nuanced, staff should follow organizational policy and consult privacy officers where the situation is unclear.
What should an emergency disclosure policy include for frontline clinical and intake staff?
An emergency disclosure policy typically identifies the permitted purposes for disclosure (such as treatment or care coordination), describes how to apply professional judgment when a patient cannot consent, addresses the minimum necessary standard where it applies, and specifies documentation expectations. It should also clarify escalation paths to a privacy officer and note where state law may impose stricter requirements. Organizations often reinforce these points through training so staff can act promptly without overstepping permitted uses and disclosures.
Should emergency disclosures be documented, and if so, how?
Documenting the disclosure and the reasoning behind it is generally advisable, both to support consistent decision-making and to address accounting-of-disclosure considerations that may apply depending on the type of disclosure. Records typically capture what was disclosed, to whom, the purpose, and the basis for any professional judgment exercised. Specific accounting and retention obligations should be confirmed against the current regulatory text and organizational retention policies, and readers should verify whether a particular disclosure type falls within accounting requirements.
How do emergency disclosures interact with the Security Rule when PHI is electronic?
The Privacy Rule governs whether an emergency disclosure of PHI is permitted, while the Security Rule continues to govern how ePHI is protected during transmission and access. A disclosure being permissible under the Privacy Rule does not remove the need to apply appropriate administrative, physical, and technical safeguards to any ePHI involved. In practice, organizations align their emergency access procedures with Security Rule requirements, and should verify their specific safeguard obligations against the current regulatory text.

Common misconceptions

In an emergency, HIPAA is suspended and any disclosure of PHI is permitted.
HIPAA is not suspended in emergencies. The Privacy Rule contains specific permitted-disclosure provisions that apply, and covered entities must still act within those provisions, exercise professional judgment, and generally observe applicable safeguards. Any OCR enforcement discretion during declared emergencies is limited in scope and duration and should be verified against current guidance.
Emergency disclosure permissions apply the same way to every vendor that handles the data.
The Privacy Rule's emergency-disclosure permissions run to covered entities. Business associates act on behalf of covered entities and their permitted uses and disclosures are governed by the business associate agreement and the Rule; obligations attach through those defined relationships rather than to any vendor generically.
Because disclosure is permitted in an emergency, it must be unlimited and unrestricted.
Permitted does not mean unlimited. Except for treatment purposes, the minimum necessary standard generally still applies, and state law, the HITECH Act, or professional ethical standards may impose additional requirements beyond the federal HIPAA baseline.

Best practices

Document the specific Privacy Rule basis relied upon for each emergency disclosure (for example, treatment, serious threat, or disaster relief) and the professional judgment exercised at the time.
Apply the minimum necessary standard to non-treatment emergency disclosures, and clearly identify when a disclosure qualifies as a treatment disclosure that is generally excepted.
Confirm whether any HHS OCR enforcement discretion or waiver applies to a declared emergency, and verify its exact scope and expiration against current OCR guidance rather than assuming broad relief.
Ensure business associate agreements address how vendors may use or disclose PHI in emergency scenarios, since their permissions flow through those agreements rather than directly from the Rule.
Check applicable state law, the HITECH Act, and relevant professional ethical standards, which may impose stricter requirements than the federal HIPAA baseline.
Train workforce members on distinguishing permitted emergency disclosures from a general suspension of HIPAA, and reinforce that permitted does not mean unrestricted.