Skip to main content
Category: Uses and Disclosures

Facility Directory

Also known as: Patient Directory, Hospital Directory
Simply put

A facility directory is a listing that covered health care providers, such as hospitals, may maintain to share limited information about patients admitted to the facility. In most cases, this allows staff to tell visitors or callers where a patient is located and how they are generally doing, and to give certain information to clergy. Patients generally have the right to be informed about the directory and to restrict or opt out of some or all of these disclosures.

Formal definition

Under the HIPAA Privacy Rule, a facility directory is a mechanism through which a covered health care provider may use and disclose a limited set of protected health information (PHI) about a patient admitted to or receiving care at the facility. As a general matter, permitted directory information typically includes the patient's name, general location within the facility, and a general condition described in terms that do not communicate specific medical information; religious affiliation may also be maintained for disclosure to clergy. The provider must generally inform the individual of the directory's existence and provide an opportunity to agree to, object to, or restrict such uses and disclosures, subject to exceptions for emergency circumstances where the individual is incapacitated or unavailable, in which case disclosure may proceed if consistent with any prior expressed preference and with professional judgment about the individual's best interests. This is a Privacy Rule concept applicable to PHI in all forms and should not be confused with unrelated 'facility directory' listings maintained by state agencies for regulatory or licensing purposes. Practitioners should verify the specific permitted data elements, conditions, and exceptions against the current text of the Privacy Rule, and note that applicable state law may impose additional or more stringent restrictions.

Why it matters

The facility directory is one of the more visible points where patient privacy and everyday hospital operations intersect. When a visitor arrives at a hospital lobby or a family member calls asking for a loved one's room number and how they are doing, the directory is the mechanism that generally permits staff to respond. Because these disclosures happen routinely and often to people the patient has not personally identified, the Privacy Rule builds in guardrails: patients must generally be informed that a directory exists and be given a meaningful opportunity to object or restrict what is shared.

Getting the directory wrong exposes covered providers to compliance risk and can undermine patient trust. A patient may have legitimate reasons for not wanting their presence in the facility known, such as concerns about personal safety or simply a desire for privacy, and disclosing their location against those wishes can cause real harm. Conversely, being overly restrictive can frustrate legitimate visitors and clergy. The rule tries to balance these interests by limiting directory information to a narrow set of elements and by describing patient condition only in general terms that do not communicate specific medical information.

Providers should also recognize that a facility directory under the HIPAA Privacy Rule is a distinct concept and should not be confused with unrelated "facility directory" listings that state agencies maintain for licensing or regulatory purposes, such as interactive maps of licensed care facilities. Because state law may impose additional or more stringent restrictions, the permitted elements and opt-out procedures should be verified against both the current Privacy Rule text and applicable state requirements.

Who it's relevant to

Hospitals and Covered Health Care Providers
Facilities that admit or treat patients are the primary maintainers of directories. They must decide what limited information to include, train front-desk and switchboard staff on what can be shared, and ensure patients are informed and given a chance to opt out or restrict disclosures. They should also account for the emergency exception when a patient is incapacitated or unavailable.
Privacy Officers and Compliance Staff
Privacy and compliance professionals are responsible for building the policies and procedures that govern directory disclosures, documenting how patients are informed and how their objections are captured, and verifying that permitted data elements and conditions align with the current Privacy Rule text and any more stringent state law requirements.
Registration and Front-Line Staff
Admitting clerks, switchboard operators, and volunteers who field visitor and caller inquiries apply the directory rules in real time. They need clear guidance on which elements may be disclosed, how to describe a patient's general condition, and how to honor a patient's decision to restrict or opt out.
Patients and Their Representatives
Patients generally have the right to be informed about the directory and to agree to, object to, or restrict some or all directory disclosures, including whether their presence in the facility is shared at all. Understanding these rights helps patients protect their privacy while still allowing visitors or clergy to reach them when they wish.

Inside Facility Directory

Directory Information Elements
A facility directory maintained by a covered entity, such as a hospital, generally includes limited information about a patient: the individual's name, location within the facility, condition described in general terms that does not communicate specific medical information, and religious affiliation.
Permitted Disclosures
Under the HIPAA Privacy Rule, directory information (other than religious affiliation) may generally be disclosed to persons who ask for the individual by name. Religious affiliation is typically disclosed only to members of the clergy.
Opportunity to Object
The Privacy Rule generally requires that the individual be informed of the information to be included in the directory and the persons to whom it may be disclosed, and be given the opportunity to restrict or prohibit some or all of the uses and disclosures.
Emergency and Incapacity Provisions
When an individual is incapacitated or in an emergency situation, the Privacy Rule generally permits a covered entity to use professional judgment to determine whether directory disclosure is in the individual's best interest, consistent with any prior expressed preference known to the entity.
Scope Within the Privacy Rule
Facility directories are a Privacy Rule concept addressing PHI in the context of a covered entity's facility. This concept is distinct from the Security Rule, which governs only electronic PHI, and does not itself address breach notification or enforcement matters.

Common questions

Answers to the questions practitioners most commonly ask about Facility Directory.

Does a facility directory require patient authorization before their information can be included?
No. Under the HIPAA Privacy Rule, a covered entity generally may maintain a facility directory without obtaining written authorization, provided the patient is informed and given the opportunity to object (agree or restrict) the use of their information for directory purposes. This differs from the common assumption that all disclosures of PHI require signed authorization. In emergency situations or when the patient is incapacitated, the rule provides limited flexibility to include directory information when doing so is consistent with any prior expressed preference and is in the patient's best interest, though the patient should be given the opportunity to object once practicable. Readers should verify the specific conditions against the current regulatory text.
Can a facility directory disclose any patient information to anyone who asks?
No. The scope of what may be disclosed through a facility directory is limited. Directory information typically includes the patient's name, general location in the facility, and a general condition description that does not communicate specific medical information. Religious affiliation may be disclosed to members of the clergy under the applicable provisions. For persons other than clergy who ask for the patient by name, disclosure is generally limited to directory information. The directory is not a mechanism for releasing detailed clinical PHI, and it should not be treated as such. Confirm the precise permitted data elements against the current Privacy Rule text.
How should a facility give patients the opportunity to object to directory inclusion?
The Privacy Rule generally requires that the patient be informed of the directory information that may be included and the persons to whom it may be disclosed, and be given the opportunity to restrict or prohibit some or all of the uses and disclosures. In practice, this is often handled during the admission or registration process. The opportunity to object may be documented in the patient record. Facilities should establish a consistent workflow so that patient preferences, including opt-outs, are captured and honored across the organization. Note that state law may impose additional requirements.
What should staff do when a patient is incapacitated at admission and cannot state a directory preference?
When a patient is incapacitated or an emergency treatment circumstance prevents obtaining the opportunity to object, the Privacy Rule generally permits a covered entity to use or disclose directory information if doing so is consistent with any known prior expressed preference of the patient and is in the patient's best interest as determined in the exercise of professional judgment. The patient should be given the opportunity to object as soon as it is practicable to do so. Facilities should document such determinations and train staff on applying professional judgment consistently.
How do facility directory practices interact with the Security Rule when the directory is maintained electronically?
The facility directory itself is a Privacy Rule concept governing permitted uses and disclosures. When directory information is stored or maintained as ePHI in an electronic system, the Security Rule's administrative, physical, and technical safeguards generally apply to that electronic information. In practice this means access controls, audit provisions, and other safeguards should protect the electronic directory data, even though the decision about what may be disclosed is governed by the Privacy Rule. The two rules address different aspects and should be applied together.
How should a facility handle requests when a patient has opted out of the directory?
When a patient has restricted or prohibited directory disclosures, the facility should honor that preference and generally should not confirm the patient's presence or disclose directory information to callers or visitors asking for the patient by name. Staff workflows, scripts, and system flags should be designed so that opt-out preferences are visible to the personnel who field such inquiries. Consistent training and documented procedures help ensure preferences are applied reliably. Facilities should also consider whether state law imposes additional handling requirements.

Common misconceptions

A patient's condition can be shared in detail through the facility directory.
The directory generally permits only a general description of condition (for example, terms such as good, fair, or serious) rather than specific medical information. Detailed clinical information is not part of the permitted directory disclosure.
Directory information can never be disclosed without the patient's written authorization.
The facility directory operates on an opportunity-to-object basis rather than requiring written authorization. Individuals are generally informed and given the chance to restrict or prohibit disclosures, and in emergency or incapacity situations the covered entity may exercise professional judgment. Readers should verify specific requirements against the current Privacy Rule text.
The facility directory rules apply to every vendor or entity that handles patient location data.
The facility directory provisions apply to covered entities under the HIPAA Privacy Rule. Business associates and subcontractors are governed through business associate agreements and their defined relationships, not directly by the directory provisions.

Best practices

Inform patients at or before admission about the information to be included in the facility directory and the persons to whom it may be disclosed, and document the opportunity provided to restrict or prohibit such disclosures.
Establish clear procedures for staff to verify that a requester is asking for a patient by name before releasing directory information, and limit disclosures to the general condition and location elements permitted.
Restrict disclosure of religious affiliation to members of the clergy and train staff accordingly, as this element is treated differently from other directory information.
Develop written guidance for handling incapacitated patients and emergency situations, including how staff should exercise professional judgment and honor any prior expressed patient preferences.
Maintain records of patient objections or opt-outs so that staff can readily confirm whether a given patient's information may be disclosed.
Review directory practices against the current Privacy Rule text and any applicable state law, since state requirements or other frameworks may impose additional restrictions beyond HIPAA.