Skip to main content
Category: Uses and Disclosures

Required by Law Disclosures

Also known as: Disclosures Required by Law, Mandatory Disclosures Required by Law
Simply put

Under the HIPAA Privacy Rule, a covered entity is generally permitted to disclose protected health information (PHI) when a law requires it to do so, such as certain State law reporting obligations. These disclosures are allowed without the individual's authorization when they are mandated by an applicable legal requirement. Only the relevant sources in the evidence packet address this concept; readers should verify the specific scope and conditions against the current regulation.

Formal definition

'Required by Law Disclosures' refers to a permitted disclosure category under the HIPAA Privacy Rule in which a covered entity may disclose PHI as necessary to comply with an applicable legal mandate, including State law, without individual authorization. The minimum necessary standard does not apply to disclosures that are required by law, so the covered entity may disclose the PHI expressly authorized by the underlying legal requirement rather than limiting to a self-determined minimum (the specific CFR provision governing this exclusion should be confirmed against the current regulatory text). This category is distinct from disclosures permitted at the covered entity's discretion; the obligation and its scope are defined by the external law compelling the disclosure. State law, the HITECH Act, or other frameworks may impose additional or differing requirements beyond the HIPAA Privacy Rule, and this term addresses only the HIPAA permission, not any independent legal duty to disclose that arises under those other authorities.

Why it matters

Required by Law Disclosures give covered entities a clear pathway to comply with external legal mandates, such as certain State law reporting obligations, without first obtaining the individual's authorization. This matters because covered entities frequently face situations where another law compels them to share PHI, and the HIPAA Privacy Rule needs to accommodate those obligations rather than place the covered entity in the impossible position of choosing between two conflicting legal duties. Understanding this permission helps privacy officers respond confidently and lawfully when a mandatory reporting requirement is triggered.

A critical practical point is that the minimum necessary standard does not apply to disclosures that are required by law. When a legal mandate compels a disclosure, the covered entity may disclose the PHI that the underlying law expressly authorizes, rather than being required to independently narrow the disclosure to a self-determined minimum. Misunderstanding this can cause errors in both directions: withholding information the law actually requires, or improperly restricting a disclosure and thereby failing to satisfy the compelling legal obligation.

Because the scope and conditions of any given required-by-law disclosure are defined by the external law compelling it, covered entities should treat this category as a HIPAA permission that operates alongside, not in place of, the analysis of what that other law actually requires. State law, the HITECH Act, or other frameworks may impose additional or differing requirements, so the specific triggering statute, its scope, and any conditions should always be confirmed against current authority.

Who it's relevant to

Privacy Officers and Compliance Teams
Privacy officers must recognize when a disclosure falls within the required-by-law category so they can respond to mandatory reporting obligations without improperly demanding an authorization. They should also understand that the minimum necessary standard does not apply here, and instead calibrate the disclosure to what the compelling law authorizes.
Covered Entities Subject to State Reporting Laws
Healthcare providers, health plans, and clearinghouses that operate under State law reporting obligations rely on this permission to comply with those mandates. Because the scope is defined by the external law, these entities should confirm the specific requirements of each applicable statute rather than assuming a uniform standard across jurisdictions.
Legal and Regulatory Counsel
Counsel advising covered entities should map the intersection between HIPAA's permission and the independent legal duty to disclose that arises under other authorities. They should note that HIPAA permits the disclosure but does not itself create the obligation, and that State law, the HITECH Act, or other frameworks may impose additional or differing requirements that must be analyzed separately.

Inside Required by Law Disclosures

Required by Law Standard
Under the HIPAA Privacy Rule, a covered entity generally may use or disclose protected health information (PHI) without individual authorization to the extent that the use or disclosure is required by law and the use or disclosure complies with, and is limited to, the relevant requirements of that law. The term 'required by law' has a specific regulatory meaning that is narrower than common usage; readers should confirm the precise definition against the current Privacy Rule text.
Mandate vs. Permission
A 'required by law' disclosure rests on a legal mandate that compels the covered entity to act (for example, a statute, regulation, or enforceable court order), as distinguished from disclosures that a law merely permits. The distinction matters because this provision applies only where disclosure is compelled, not where it is optional.
Limited to the Requirements of the Law
Any disclosure made under this provision must comply with and be limited to the relevant requirements of the law that mandates it. The disclosure is bounded by what the underlying legal authority actually requires.
Relationship to Minimum Necessary
The minimum necessary standard does not apply to disclosures that are required by law under the HIPAA Privacy Rule. Instead, the disclosure is governed and bounded by the requirements of the law compelling it. Practitioners should nonetheless verify the applicable regulatory text, as related but distinct provisions (such as those for disclosures to public health authorities or law enforcement) may carry their own specific conditions.
Overlap with Other Permitted Disclosures
Some disclosures that are required by law may also fall within other categories the Privacy Rule addresses separately, such as disclosures for judicial and administrative proceedings, law enforcement purposes, or public health activities. Those categories can impose additional or more specific conditions, so the applicable category should be identified precisely.
Scope Limited to the Privacy Rule
This concept is a feature of the HIPAA Privacy Rule, which covers PHI in all forms including oral, paper, and electronic. It is distinct from the Security Rule, which governs only ePHI safeguards, and from the Breach Notification and Enforcement Rules.

Common questions

Answers to the questions practitioners most commonly ask about Required by Law Disclosures.

Does the minimum necessary standard apply to disclosures that are required by law?
No. The minimum necessary standard does not apply to disclosures required by law. Under the Privacy Rule at 45 CFR 164.502(b)(2), disclosures required by law are among the categories expressly excepted from the minimum necessary requirement. In practice, a covered entity generally discloses the protected health information that the law demands, and the scope of what may be disclosed is defined by the applicable legal requirement itself rather than by a separate minimum necessary analysis. Note that where a disclosure is permitted but not strictly required by law, minimum necessary and other conditions may still apply, so it is important to confirm that the specific disclosure actually falls within the required by law category.
If a disclosure is required by law, does that mean the covered entity must always disclose the information?
The required by law permission authorizes a covered entity to disclose PHI to the extent the disclosure is compelled by law, but the term describes a specific regulatory category rather than a general obligation to hand over information on request. The disclosure must be genuinely mandated by a statute, regulation, or enforceable legal directive, and generally must be limited to the relevant requirements of that law. Certain disclosures, such as those in response to court orders, subpoenas, or law enforcement requests, are addressed by separate provisions of the Privacy Rule that carry their own conditions. Readers should verify which specific provision applies before treating a request as required by law, and should confirm whether state law imposes additional or different requirements.
How should a covered entity determine whether a particular request is actually required by law?
Generally, the covered entity should identify the specific legal authority that mandates the disclosure, such as a statute, regulation, court order, or other enforceable legal process, and confirm that the authority actually compels disclosure rather than merely permits it. It is advisable to document the legal basis relied upon. Because some requests may fall under other Privacy Rule provisions with distinct conditions, such as those for judicial proceedings or law enforcement, careful characterization matters. Consulting legal counsel is typically prudent when the mandatory nature of a request is unclear, and state law should be checked for additional obligations.
How much information can be disclosed under the required by law permission?
Because the minimum necessary standard does not apply to required by law disclosures, the covered entity generally discloses PHI to the extent required by the applicable law. The scope is defined by what the law itself compels rather than by an independent minimum necessary determination. That said, disclosing information beyond what the law requires would fall outside this permission, so the disclosure should track the relevant requirements of the legal mandate. Where uncertainty exists about the intended scope, verifying the terms of the specific legal authority is recommended.
Should required by law disclosures be documented, and if so, how?
Documentation is generally advisable to demonstrate the basis for the disclosure and to support accounting of disclosures obligations where they apply. In practice, covered entities often record the legal authority relied upon, the information disclosed, the recipient, and the date. Whether a particular required by law disclosure must be included in an accounting of disclosures depends on the applicable regulatory provisions, so readers should confirm the current requirements. Retaining supporting records also helps address any later questions from HHS OCR or other authorities.
What is the relationship between required by law disclosures under HIPAA and state law requirements?
State law may independently mandate certain disclosures, and such state mandates can themselves qualify as required by law under the Privacy Rule. In some cases state law imposes obligations that go beyond HIPAA, and where state and federal requirements differ, both may need to be reconciled, with more stringent protections for individuals sometimes controlling. Because these interactions can be complex, covered entities should verify the specific state law requirements applicable to a given disclosure and consult counsel where the interplay is unclear.

Common misconceptions

The minimum necessary standard still applies to required-by-law disclosures, so a covered entity must independently limit the PHI it releases.
The minimum necessary requirement does not apply to disclosures that are required by law under the HIPAA Privacy Rule. Such disclosures are instead governed by, and limited to, the requirements of the law that compels them. Practitioners should still confirm the exact scope of what the underlying law requires and verify against the current regulatory text.
Any law, request, or subpoena that asks for PHI qualifies as 'required by law.'
The provision applies only where a law actually mandates the disclosure, not where disclosure is merely permitted or informally requested. A demand that does not compel disclosure may fall under a different Privacy Rule category with its own conditions, so the legal basis must be identified precisely before relying on this provision.
A required-by-law disclosure lets a covered entity release whatever PHI is asked for.
The disclosure must comply with and be limited to the relevant requirements of the mandating law. The scope of PHI released is bounded by what that law actually requires rather than by an open-ended request.

Best practices

Confirm that a genuine legal mandate exists compelling the disclosure, and distinguish it from a law that merely permits disclosure before relying on the required-by-law provision.
Limit each disclosure to what the mandating law actually requires, documenting the specific legal authority and the scope it defines.
Identify whether the disclosure also falls within another Privacy Rule category (such as judicial proceedings, law enforcement, or public health), since those categories may impose additional specific conditions that must be met.
Recognize that the minimum necessary standard does not apply to required-by-law disclosures, while still verifying the precise scope defined by the underlying law and by the current regulatory text.
Maintain documentation of the legal basis, the requester, and the PHI disclosed to support accountability and any accounting-of-disclosures obligations.
Verify obligations against the current Privacy Rule text and applicable state law or HITECH Act provisions, which may impose additional or more stringent requirements beyond HIPAA.