Permitted Uses and Disclosures
Permitted uses and disclosures are the specific situations in which the HIPAA Privacy Rule allows a covered entity to use or share protected health information (PHI) without first getting the individual's written authorization. Common examples generally include sharing information for treatment, payment, and certain healthcare operations, as well as some public health activities. In most other cases, a covered entity may only use or disclose PHI if the Privacy Rule specifically permits or requires it, or if the individual authorizes it.
Under the HIPAA Privacy Rule, 'permitted uses and disclosures' refers to categories of PHI use and disclosure that a covered entity may make without individual authorization, subject to applicable conditions and, where required, the minimum necessary standard. As a general baseline, a covered entity may only use or disclose PHI where the Privacy Rule specifically permits or requires it, or where the individual (or their personal representative) authorizes it. HHS guidance describes multiple national priority purposes for which use or disclosure is permitted without authorization; these generally include treatment, payment, and healthcare operations, disclosures required by law, and public health activities, among others. Some permitted disclosures require giving the individual an opportunity to agree or object, while others do not. This term is specific to the Privacy Rule and governs PHI in all forms, and is distinct from the Security Rule's safeguards for ePHI. It also does not by itself address separately regulated categories or heightened protections that may apply under the HITECH Act or state law, which can impose additional restrictions. Practitioners should verify specific permitted-use categories, conditions, and citations against the current text of the Privacy Rule and current HHS OCR guidance.
Why it matters
Permitted uses and disclosures sit at the core of how the HIPAA Privacy Rule balances protecting patient information against the practical need to deliver and pay for care. The Privacy Rule generally establishes a baseline: a covered entity may use or disclose PHI only where the rule specifically permits or requires it, or where the individual (or their personal representative) authorizes it. Understanding which situations fall within the permitted categories, and which instead require written authorization, is essential to avoiding improper disclosures that can trigger HHS OCR enforcement or state-law consequences.
Misunderstanding this framework cuts both ways. Overly restrictive interpretations can obstruct legitimate information sharing that the Privacy Rule expressly allows. HHS and ONC have both published guidance emphasizing that HIPAA supports exchange of PHI for treatment purposes, precisely because organizations sometimes withhold information they are permitted to share. Conversely, treating a permitted use as broader than it is can lead to disclosures that fall outside the rule and expose the organization to liability.
Because permitted uses and disclosures apply to PHI in all forms and are subject to conditions such as the minimum necessary standard, professionals must work from the specific permitted-use categories rather than general assumptions. The HITECH Act and state law may impose additional restrictions or heightened protections beyond the Privacy Rule, so an activity permitted under HIPAA is not automatically permissible under every applicable authority. Readers should verify specific categories, conditions, and citations against the current text of the Privacy Rule and current HHS OCR guidance.
Who it's relevant to
Inside Permitted Uses and Disclosures
Common questions
Answers to the questions practitioners most commonly ask about Permitted Uses and Disclosures.