Skip to main content
Category: Regulatory Framework

Privacy Rule

Also known as: HIPAA Privacy Rule, Standards for Privacy of Individually Identifiable Health Information
Simply put

The HIPAA Privacy Rule is a federal standard that protects individuals' medical records and other personal health information. It applies to health plans, health care providers, and related organizations, and it sets limits on how this information may be used and shared. Unlike the HIPAA Security Rule, which covers only electronic information, the Privacy Rule generally protects health information in all forms, including oral, paper, and electronic.

Formal definition

The HIPAA Privacy Rule establishes national standards to protect individuals' medical records and other individually identifiable health information. It protects all 'individually identifiable health information' (PHI) held or transmitted by a covered entity or its business associate, and governs the permitted and required uses and disclosures of PHI. The Rule applies to covered entities such as health plans and health care providers, with obligations extending to business associates through defined relationships. Its scope covers PHI in any form or medium (oral, paper, and electronic), which distinguishes it from the Security Rule, whose scope is limited to electronic PHI (ePHI). The Privacy Rule also permits certain disclosures, such as sharing PHI with public health authorities authorized by law to collect or receive it. Readers should note that state law and the HITECH Act may impose additional requirements beyond the federal Privacy Rule, and specific provisions should be verified against the current regulatory text.

Why it matters

The Privacy Rule is foundational to how healthcare organizations handle personal health information because it governs the uses and disclosures of protected health information (PHI) in all forms, oral, paper, and electronic. This broad scope distinguishes it from the Security Rule, which is limited to electronic PHI (ePHI). For compliance professionals, understanding where the Privacy Rule applies is essential to determining what practices are permitted, what requires patient authorization, and where limits on sharing information take effect. A misunderstanding of these boundaries can lead an organization to improperly disclose information or, conversely, to withhold information that the Rule actually permits to be shared.

The Privacy Rule also carries practical significance because it defines the permitted and required uses and disclosures that keep everyday healthcare operations lawful. For example, the Rule allows the existing practice of sharing PHI with public health authorities that are authorized by law to collect or receive such information, which supports functions like disease surveillance and public health reporting. Getting these permissions right matters both for regulatory compliance and for the legitimate flow of information that healthcare and public health systems depend on.

Readers should note that the federal Privacy Rule is often not the whole picture. State law and the HITECH Act may impose additional or stricter requirements, and organizations that only account for the federal baseline may still fall short of their full legal obligations. Specific provisions, permitted disclosures, and any thresholds should be verified against the current regulatory text and applicable state law rather than assumed from a general summary.

Who it's relevant to

Privacy Officers and Compliance Teams
Privacy officers are responsible for operationalizing the Privacy Rule's standards across an organization, including managing permitted and required uses and disclosures of PHI in all forms. They must account for oral, paper, and electronic information, not just electronic data, and should verify how state law and the HITECH Act may add requirements beyond the federal baseline.
Covered Entities: Health Plans and Health Care Providers
Health plans and health care providers are directly subject to the Privacy Rule and must ensure that their uses and disclosures of individually identifiable health information stay within permitted or required categories. They also determine when patient authorization is needed and when disclosures, such as those to authorized public health authorities, are permitted.
Business Associates
Business associates are bound by Privacy Rule obligations through their defined relationships with covered entities, typically formalized through business associate agreements. Because PHI protected under the Rule can be transmitted or held by a business associate, these organizations should understand which specific obligations flow to them rather than assuming HIPAA applies to them in the same way it applies to covered entities.
Public Health Authorities and Reporting Staff
Public health authorities that are authorized by law to collect or receive PHI benefit from the Privacy Rule's provision permitting such disclosures. Staff involved in disease surveillance and reporting should understand the scope and limits of these permitted disclosures and confirm them against current regulatory text and applicable law.
Legal Counsel and Regulatory Advisors
Attorneys and advisors interpreting HIPAA obligations must distinguish the Privacy Rule's all-forms scope from the Security Rule's ePHI-only scope, and should flag where the HITECH Act or state law imposes stricter or additional requirements. Enforcement authority rests with HHS OCR, and specific provisions should always be checked against the current regulation.

Inside Privacy Rule

Scope Across All Forms of PHI
The Privacy Rule governs protected health information (PHI) in all forms, including oral, paper, and electronic. This is broader than the Security Rule, which applies only to electronic PHI (ePHI).
Permitted Uses and Disclosures
Establishes the circumstances under which covered entities may use or disclose PHI, generally including treatment, payment, and health care operations, as well as certain other permitted and required disclosures. Uses and disclosures outside those permitted typically require patient authorization.
Minimum Necessary Standard
Generally requires that covered entities limit uses, disclosures, and requests of PHI to the minimum necessary to accomplish the intended purpose, with certain exceptions such as disclosures for treatment.
Individual Rights
Grants individuals rights with respect to their PHI, which typically include the right to access and obtain copies of their records, to request amendments, to receive an accounting of certain disclosures, and to request restrictions and confidential communications.
Notice of Privacy Practices
Requires covered entities to provide individuals with notice describing how their PHI may be used and disclosed and outlining the individual's rights.
Business Associate Obligations Through Agreements
Where a covered entity engages a vendor that creates, receives, maintains, or transmits PHI on its behalf, obligations generally flow to that business associate through a business associate agreement rather than the Rule regulating every vendor by default.
Administrative Requirements
Requires covered entities to implement privacy policies and procedures, designate a privacy official, train workforce members, and establish safeguards and complaint processes to support Privacy Rule compliance.

Common questions

Answers to the questions practitioners most commonly ask about Privacy Rule.

Does the Privacy Rule only apply to electronic health information?
No. This is a common point of confusion with the Security Rule. The Security Rule governs only electronic protected health information (ePHI), whereas the Privacy Rule generally applies to protected health information (PHI) in all forms, including oral, paper, and electronic. Verbal disclosures and paper records fall within the Privacy Rule's scope even though they are outside the Security Rule.
Does the Privacy Rule directly regulate every vendor that handles patient information?
Not directly. HIPAA obligations attach through defined relationships rather than to any party that touches data. A vendor generally becomes subject to Privacy Rule requirements when it functions as a business associate, with obligations flowing through a business associate agreement. Subcontractors of business associates can be similarly bound. A vendor that does not meet the definition of a business associate is typically not regulated by the Privacy Rule in that capacity, though other laws may apply.
How does the Privacy Rule apply to disclosures made verbally in a clinical setting?
Because the Privacy Rule covers PHI in all forms, oral disclosures are within its scope. Covered entities are generally expected to apply reasonable safeguards to incidental disclosures, such as those that may occur during ordinary treatment discussions. The specific expectations should be confirmed against the current regulatory text, as reasonableness depends on the circumstances.
What should an organization consider when determining a permitted use or disclosure under the Privacy Rule?
In general, the Privacy Rule permits certain uses and disclosures without individual authorization, such as those for treatment, payment, and health care operations, while others require authorization. Many disclosures are also subject to the minimum necessary standard. Organizations should evaluate the purpose of each disclosure and confirm the applicable category against the current regulation, since specific conditions and exceptions apply.
How does the Privacy Rule interact with state privacy laws?
The Privacy Rule generally establishes a federal baseline, and state laws that are more stringent may impose additional requirements. Organizations should not assume Privacy Rule compliance alone satisfies all obligations; the HITECH Act and applicable state law may add further requirements. Where laws differ, readers should confirm which standard controls in their jurisdiction.
Does implementing the HITRUST CSF demonstrate compliance with the Privacy Rule?
No. The HITRUST CSF is a certifiable control framework maintained by a private organization, and certification is not a legal requirement. While it can support an organization's privacy and security program, it does not by itself establish HIPAA Privacy Rule compliance, which is a legal obligation enforced by HHS OCR. Organizations should treat the two as related but distinct and verify requirements against the current regulation and the current CSF version.

Common misconceptions

The Privacy Rule only applies to electronic records or computer systems.
The Privacy Rule covers PHI in all forms, including oral, paper, and electronic. It is the Security Rule, a separate rule, that is limited to electronic PHI (ePHI).
HIPAA directly regulates every vendor or third party that touches patient data.
Privacy Rule obligations generally attach through defined relationships. A vendor typically becomes subject to obligations as a business associate, and those obligations flow through a business associate agreement rather than applying automatically to any party handling data.
Achieving HITRUST CSF certification means an organization is compliant with the Privacy Rule.
HITRUST is a private organization and its CSF is a certifiable control framework, not a legal requirement. Certification does not by itself establish HIPAA Privacy Rule compliance, which is enforced by HHS OCR. Certification may support a compliance program but should not be treated as a substitute for meeting the regulatory requirements.

Best practices

Maintain written privacy policies and procedures that address permitted uses and disclosures, individual rights, and the minimum necessary standard, and review them against the current regulatory text.
Apply the minimum necessary standard to routine uses, disclosures, and requests of PHI, keeping in mind exceptions such as disclosures for treatment.
Ensure a current business associate agreement is in place before sharing PHI with vendors that create, receive, maintain, or transmit PHI on your behalf, since obligations flow through these agreements.
Establish clear, documented processes for handling individual rights requests, including access, amendment, accounting of disclosures, and restriction requests.
Provide and keep current a Notice of Privacy Practices, and train workforce members on privacy policies and their obligations.
Confirm any specific figures, deadlines, or citations against the current HHS regulation, and check whether state law or the HITECH Act imposes additional requirements beyond the Privacy Rule.