Facility Directory
A facility directory is a listing that covered health care providers, such as hospitals, may maintain to share limited information about patients admitted to the facility. In most cases, this allows staff to tell visitors or callers where a patient is located and how they are generally doing, and to give certain information to clergy. Patients generally have the right to be informed about the directory and to restrict or opt out of some or all of these disclosures.
Under the HIPAA Privacy Rule, a facility directory is a mechanism through which a covered health care provider may use and disclose a limited set of protected health information (PHI) about a patient admitted to or receiving care at the facility. As a general matter, permitted directory information typically includes the patient's name, general location within the facility, and a general condition described in terms that do not communicate specific medical information; religious affiliation may also be maintained for disclosure to clergy. The provider must generally inform the individual of the directory's existence and provide an opportunity to agree to, object to, or restrict such uses and disclosures, subject to exceptions for emergency circumstances where the individual is incapacitated or unavailable, in which case disclosure may proceed if consistent with any prior expressed preference and with professional judgment about the individual's best interests. This is a Privacy Rule concept applicable to PHI in all forms and should not be confused with unrelated 'facility directory' listings maintained by state agencies for regulatory or licensing purposes. Practitioners should verify the specific permitted data elements, conditions, and exceptions against the current text of the Privacy Rule, and note that applicable state law may impose additional or more stringent restrictions.
Why it matters
The facility directory is one of the more visible points where patient privacy and everyday hospital operations intersect. When a visitor arrives at a hospital lobby or a family member calls asking for a loved one's room number and how they are doing, the directory is the mechanism that generally permits staff to respond. Because these disclosures happen routinely and often to people the patient has not personally identified, the Privacy Rule builds in guardrails: patients must generally be informed that a directory exists and be given a meaningful opportunity to object or restrict what is shared.
Getting the directory wrong exposes covered providers to compliance risk and can undermine patient trust. A patient may have legitimate reasons for not wanting their presence in the facility known, such as concerns about personal safety or simply a desire for privacy, and disclosing their location against those wishes can cause real harm. Conversely, being overly restrictive can frustrate legitimate visitors and clergy. The rule tries to balance these interests by limiting directory information to a narrow set of elements and by describing patient condition only in general terms that do not communicate specific medical information.
Providers should also recognize that a facility directory under the HIPAA Privacy Rule is a distinct concept and should not be confused with unrelated "facility directory" listings that state agencies maintain for licensing or regulatory purposes, such as interactive maps of licensed care facilities. Because state law may impose additional or more stringent restrictions, the permitted elements and opt-out procedures should be verified against both the current Privacy Rule text and applicable state requirements.
Who it's relevant to
Inside Facility Directory
Common questions
Answers to the questions practitioners most commonly ask about Facility Directory.