Sale of PHI
Sale of PHI generally refers to a disclosure of protected health information where the covered entity or business associate receives payment (directly or indirectly) from the recipient in exchange for that information. Under the HIPAA Privacy Rule, this practice is generally prohibited unless the individual signs a valid authorization stating that the disclosure will result in payment to the entity making it. Because this is a specialized regulatory concept, the exact scope and exceptions should be verified against the current regulatory text.
Under the HIPAA Privacy Rule, a sale of PHI is generally a disclosure of protected health information in which the covered entity (or, as applicable, its business associate) directly or indirectly receives remuneration from the recipient of the PHI in exchange for that information. Such disclosures are generally prohibited absent a valid HIPAA authorization that specifically states the covered entity will receive remuneration for the disclosure. The regulatory definition and its exceptions are narrower and more specific than the ordinary meaning of 'sale'; certain permitted disclosures and exclusions may apply. Practitioners should confirm the precise definition, exceptions, and any authorization content requirements against the current Privacy Rule text and applicable HHS guidance, and note that state law or other requirements may impose additional obligations.
Why it matters
The sale of PHI restriction addresses one of the more sensitive commercial pressures in healthcare: the temptation to monetize the protected health information that flows through covered entities and business associates. Because health data can be valuable to marketers, data brokers, and other third parties, the HIPAA Privacy Rule generally prohibits disclosing PHI in exchange for remuneration unless the individual has signed a valid authorization that specifically discloses the entity will be paid for the disclosure. This gives patients transparency and a meaningful choice before their information is exchanged for value.
For compliance teams, the concept matters because the regulatory definition of 'sale' is narrower and more technical than the everyday meaning of the word. It generally turns on whether the covered entity or business associate directly or indirectly receives payment from the recipient in exchange for the PHI, and certain permitted disclosures and exclusions may apply. Misjudging whether a particular transaction qualifies as a sale, for example, in the context of transferring records upon the sale of a medical practice, or when sharing data with a vendor, can lead to disclosures made without the required authorization.
The stakes extend beyond HIPAA itself. Sale-of-PHI issues frequently intersect with FTC oversight, state privacy law, and the HITECH Act, which may impose additional or overlapping obligations. Because penalty tiers and enforcement priorities are set by HHS OCR and adjusted over time, and because state law may be more stringent, organizations should treat the sale-of-PHI prohibition as a starting point rather than a complete rulebook and verify the precise scope, exceptions, and authorization content requirements against current regulatory text.
Who it's relevant to
Inside Sale of PHI
Common questions
Answers to the questions practitioners most commonly ask about Sale of PHI.