Skip to main content
Category: Uses and Disclosures

Permitted Uses and Disclosures

Also known as: Permitted Uses and Disclosures of PHI
Simply put

Permitted uses and disclosures are the specific situations in which the HIPAA Privacy Rule allows a covered entity to use or share protected health information (PHI) without first getting the individual's written authorization. Common examples generally include sharing information for treatment, payment, and certain healthcare operations, as well as some public health activities. In most other cases, a covered entity may only use or disclose PHI if the Privacy Rule specifically permits or requires it, or if the individual authorizes it.

Formal definition

Under the HIPAA Privacy Rule, 'permitted uses and disclosures' refers to categories of PHI use and disclosure that a covered entity may make without individual authorization, subject to applicable conditions and, where required, the minimum necessary standard. As a general baseline, a covered entity may only use or disclose PHI where the Privacy Rule specifically permits or requires it, or where the individual (or their personal representative) authorizes it. HHS guidance describes multiple national priority purposes for which use or disclosure is permitted without authorization; these generally include treatment, payment, and healthcare operations, disclosures required by law, and public health activities, among others. Some permitted disclosures require giving the individual an opportunity to agree or object, while others do not. This term is specific to the Privacy Rule and governs PHI in all forms, and is distinct from the Security Rule's safeguards for ePHI. It also does not by itself address separately regulated categories or heightened protections that may apply under the HITECH Act or state law, which can impose additional restrictions. Practitioners should verify specific permitted-use categories, conditions, and citations against the current text of the Privacy Rule and current HHS OCR guidance.

Why it matters

Permitted uses and disclosures sit at the core of how the HIPAA Privacy Rule balances protecting patient information against the practical need to deliver and pay for care. The Privacy Rule generally establishes a baseline: a covered entity may use or disclose PHI only where the rule specifically permits or requires it, or where the individual (or their personal representative) authorizes it. Understanding which situations fall within the permitted categories, and which instead require written authorization, is essential to avoiding improper disclosures that can trigger HHS OCR enforcement or state-law consequences.

Misunderstanding this framework cuts both ways. Overly restrictive interpretations can obstruct legitimate information sharing that the Privacy Rule expressly allows. HHS and ONC have both published guidance emphasizing that HIPAA supports exchange of PHI for treatment purposes, precisely because organizations sometimes withhold information they are permitted to share. Conversely, treating a permitted use as broader than it is can lead to disclosures that fall outside the rule and expose the organization to liability.

Because permitted uses and disclosures apply to PHI in all forms and are subject to conditions such as the minimum necessary standard, professionals must work from the specific permitted-use categories rather than general assumptions. The HITECH Act and state law may impose additional restrictions or heightened protections beyond the Privacy Rule, so an activity permitted under HIPAA is not automatically permissible under every applicable authority. Readers should verify specific categories, conditions, and citations against the current text of the Privacy Rule and current HHS OCR guidance.

Who it's relevant to

Privacy Officers and Compliance Staff
Privacy officers rely on the permitted-use framework to determine when PHI can be shared without authorization and when authorization is required. They typically translate these categories into policies, workflows, and staff training, and apply the minimum necessary standard where the rule requires it. They should verify specific categories and conditions against current Privacy Rule text and HHS OCR guidance.
Treating Providers and Clinical Staff
Clinicians and their teams depend on the treatment-related permitted uses to exchange PHI for patient care. HHS and ONC guidance emphasizes that HIPAA supports sharing PHI for treatment, so clinical staff benefit from understanding that many care-coordination disclosures are permitted without separate authorization, subject to applicable conditions.
Legal Counsel and Regulatory Advisors
Attorneys advising covered entities assess whether a specific use or disclosure falls within a permitted category, requires an opportunity to agree or object, or requires authorization. They also evaluate where the HITECH Act or state law may impose additional restrictions beyond the Privacy Rule, since HIPAA permission does not resolve every applicable requirement.
Public Health and Reporting Personnel
Staff who handle disclosures to public health authorities work within the permitted-use categories that allow disclosure of PHI for public health activities without individual authorization. They should confirm the specific conditions attached to these disclosures against current guidance, as permitted purposes and their limits are defined in the regulation.

Inside Permitted Uses and Disclosures

Treatment, Payment, and Health Care Operations (TPO)
Under the HIPAA Privacy Rule, covered entities are generally permitted to use and disclose protected health information (PHI) without individual authorization for their own treatment, payment, and health care operations activities. These are the core permitted purposes, though specific limitations and conditions may apply, and readers should confirm details against the current regulatory text.
Disclosures to the Individual
The Privacy Rule generally permits a covered entity to disclose PHI to the individual who is the subject of that information. This is distinct from the individual's separate access rights, which have their own requirements.
Uses and Disclosures Requiring an Opportunity to Agree or Object
Certain uses and disclosures, such as those involving facility directories or notification of family members involved in an individual's care, are generally permitted where the individual has been given an opportunity to agree or object, subject to the conditions in the rule.
Incidental Uses and Disclosures
The Privacy Rule generally permits incidental uses and disclosures that occur as a byproduct of an otherwise permitted use or disclosure, provided reasonable safeguards and the minimum necessary standard have been applied where applicable.
Public Interest and Benefit Activities
The rule identifies categories of permitted disclosures for public interest purposes (for example, certain public health, law enforcement, and other specified activities), each of which is subject to specific conditions and limitations set out in the regulation. Practitioners should verify the applicable conditions for each category.
Minimum Necessary Standard
For most permitted uses and disclosures, covered entities and business associates must generally make reasonable efforts to limit PHI to the minimum necessary to accomplish the intended purpose. Certain uses and disclosures, such as those for treatment, are typically excepted from this standard.
Distinction from Authorized Disclosures
Permitted uses and disclosures are those allowed under the Privacy Rule without a separate individual authorization. They should not be confused with uses and disclosures that require a valid HIPAA authorization, such as most uses of PHI for marketing or the sale of PHI.
Scope Limited to the Privacy Rule
The concept of permitted uses and disclosures is a Privacy Rule construct governing PHI in all forms (oral, paper, and electronic). It is distinct from Security Rule safeguard requirements, which apply only to electronic PHI.

Common questions

Answers to the questions practitioners most commonly ask about Permitted Uses and Disclosures.

Does the Privacy Rule require patient authorization before any use or disclosure of PHI?
No. The Privacy Rule identifies certain permitted uses and disclosures for which no patient authorization is required, most notably uses and disclosures for treatment, payment, and health care operations. Authorization is generally required for uses and disclosures that fall outside the permitted and required categories. It is a misconception that every use of PHI must be preceded by a signed authorization. That said, some disclosures that are permitted still require the individual to have an opportunity to agree or object, and state law or other frameworks may impose additional requirements, so readers should verify against the current regulatory text.
If a use or disclosure is permitted, does that mean any amount of PHI can be shared?
Not generally. Being permitted does not exempt a use or disclosure from the minimum necessary standard, which typically requires covered entities and business associates to limit PHI to the minimum needed to accomplish the intended purpose. Important exceptions apply, such as disclosures to or requests by a health care provider for treatment, which are generally not subject to minimum necessary. Because permitted and minimum necessary are separate concepts, treating a permitted purpose as authorization to share unlimited PHI is a common error. Confirm the specific exceptions against current guidance.
How should we document that a use or disclosure fell within a permitted category?
Organizations generally maintain policies and procedures that map their routine uses and disclosures to the permitted categories, along with records supporting minimum necessary determinations where applicable. For certain disclosures, an accounting of disclosures may need to be available to the individual on request, though many treatment, payment, and operations disclosures are typically excluded from that accounting. Because documentation obligations and accounting exclusions have specific regulatory contours, and state law may add requirements, verify the current requirements before finalizing your recordkeeping approach.
Do business associates rely on the same permitted uses and disclosures as covered entities?
A business associate may generally use or disclose PHI only as permitted by its business associate agreement and as allowed under the Privacy Rule, which typically limits it to the purposes for which it was engaged. The permitted categories available to a covered entity do not automatically flow to a business associate; the obligations and allowances attach through the defined relationship and the terms of the agreement. Subcontractors are similarly bound through their own agreements. Review the specific BAA and applicable regulatory provisions for each arrangement.
How do we apply the minimum necessary standard to a permitted disclosure in practice?
In most cases, workflows are designed to restrict access and disclosure to the amount of PHI reasonably needed for the purpose, often through role-based access, standard protocols for recurring disclosures, and case-by-case review for non-routine requests. Certain disclosures, such as those for treatment or those made pursuant to a valid authorization, are generally outside the minimum necessary requirement. Because the boundaries of these exceptions are specific, organizations should confirm applicability against the current Privacy Rule text.
How do state law or other frameworks affect what counts as a permitted use or disclosure?
The Privacy Rule generally sets a federal floor, and state law or other requirements may be more stringent or provide greater protection, in which case those additional requirements typically apply on top of HIPAA. Categories such as certain sensitive information may be treated differently under other laws. Separately, frameworks like the HITRUST CSF are control frameworks and do not themselves define permitted uses and disclosures or establish HIPAA compliance. Organizations should evaluate applicable state law and other legal requirements alongside the current federal regulatory text.

Common misconceptions

Permitted means the covered entity can share PHI freely for these purposes without limits.
Being permitted to use or disclose PHI does not remove other obligations. The minimum necessary standard generally still applies (with limited exceptions such as treatment), and many permitted disclosures are subject to specific conditions and limitations in the regulation. Permitted disclosures are not unrestricted.
Any use or disclosure that seems reasonable is permitted without authorization.
Only the categories specifically identified in the Privacy Rule are permitted without authorization. Uses and disclosures that fall outside those categories, such as most marketing or the sale of PHI, generally require a valid HIPAA authorization. Practitioners should confirm which category, if any, applies to a given activity.
Business associates are free to make the same permitted uses and disclosures as the covered entity.
A business associate's permitted uses and disclosures are generally limited by the terms of its business associate agreement and by the Privacy Rule. Obligations attach through the defined relationship rather than granting the business associate the full latitude of the covered entity.

Best practices

Map each routine use and disclosure of PHI to a specific permitted category under the Privacy Rule, and document the basis; where no permitted category applies, obtain a valid HIPAA authorization.
Apply the minimum necessary standard to permitted uses and disclosures by default, and confirm which limited exceptions (such as treatment) apply before relying on them.
Implement reasonable administrative, physical, and technical safeguards to limit incidental disclosures, recognizing that permitted incidental disclosures still depend on those safeguards being in place.
Ensure business associate agreements clearly define the permitted uses and disclosures allowed to each business associate, and confirm vendors operate within those defined limits.
Train workforce members to distinguish permitted uses and disclosures from those requiring authorization, and to escalate uncertain cases before disclosing PHI.
Verify the specific conditions and limitations for each permitted category against the current Privacy Rule text, and check whether state law or the HITECH Act imposes additional requirements beyond the federal baseline.