Skip to main content
Category: Uses and Disclosures

Sale of PHI

Also known as: Sale of Protected Health Information, Sale of Protected Health Information (PHI)
Simply put

Sale of PHI generally refers to a disclosure of protected health information where the covered entity or business associate receives payment (directly or indirectly) from the recipient in exchange for that information. Under the HIPAA Privacy Rule, this practice is generally prohibited unless the individual signs a valid authorization stating that the disclosure will result in payment to the entity making it. Because this is a specialized regulatory concept, the exact scope and exceptions should be verified against the current regulatory text.

Formal definition

Under the HIPAA Privacy Rule, a sale of PHI is generally a disclosure of protected health information in which the covered entity (or, as applicable, its business associate) directly or indirectly receives remuneration from the recipient of the PHI in exchange for that information. Such disclosures are generally prohibited absent a valid HIPAA authorization that specifically states the covered entity will receive remuneration for the disclosure. The regulatory definition and its exceptions are narrower and more specific than the ordinary meaning of 'sale'; certain permitted disclosures and exclusions may apply. Practitioners should confirm the precise definition, exceptions, and any authorization content requirements against the current Privacy Rule text and applicable HHS guidance, and note that state law or other requirements may impose additional obligations.

Why it matters

The sale of PHI restriction addresses one of the more sensitive commercial pressures in healthcare: the temptation to monetize the protected health information that flows through covered entities and business associates. Because health data can be valuable to marketers, data brokers, and other third parties, the HIPAA Privacy Rule generally prohibits disclosing PHI in exchange for remuneration unless the individual has signed a valid authorization that specifically discloses the entity will be paid for the disclosure. This gives patients transparency and a meaningful choice before their information is exchanged for value.

For compliance teams, the concept matters because the regulatory definition of 'sale' is narrower and more technical than the everyday meaning of the word. It generally turns on whether the covered entity or business associate directly or indirectly receives payment from the recipient in exchange for the PHI, and certain permitted disclosures and exclusions may apply. Misjudging whether a particular transaction qualifies as a sale, for example, in the context of transferring records upon the sale of a medical practice, or when sharing data with a vendor, can lead to disclosures made without the required authorization.

The stakes extend beyond HIPAA itself. Sale-of-PHI issues frequently intersect with FTC oversight, state privacy law, and the HITECH Act, which may impose additional or overlapping obligations. Because penalty tiers and enforcement priorities are set by HHS OCR and adjusted over time, and because state law may be more stringent, organizations should treat the sale-of-PHI prohibition as a starting point rather than a complete rulebook and verify the precise scope, exceptions, and authorization content requirements against current regulatory text.

Who it's relevant to

Privacy Officers and Compliance Teams
Privacy officers are typically responsible for evaluating whether a proposed disclosure of PHI qualifies as a sale and, if so, ensuring a valid authorization with the required remuneration statement is obtained beforehand. They should also assess whether a permitted exception applies rather than assuming any exchange of value triggers the prohibition, and verify their analysis against current Privacy Rule text.
Business Associates and Their Subcontractors
Because the sale-of-PHI prohibition can apply to business associates as well as covered entities, vendors that handle PHI need to understand that receiving payment in exchange for PHI is generally restricted. Their obligations attach through business associate agreements and applicable Privacy Rule provisions, and they should confirm how the restriction flows down to any subcontractors.
Legal Counsel Advising on Transactions
Attorneys advising on mergers, acquisitions, or the sale of a medical practice must analyze whether transferring patient records constitutes a sale of PHI under the Privacy Rule. HHS guidance addresses certain transfer scenarios, but the analysis is fact-specific, and counsel should also consider state law and other frameworks that may impose additional requirements.
Data Governance and IT Leaders
Teams responsible for data sharing arrangements, analytics partnerships, and vendor relationships should be able to identify when a data flow involves remuneration in exchange for PHI. Building this awareness into intake and contracting processes helps ensure that potentially prohibited sales are routed for legal and privacy review before any disclosure occurs.

Inside Sale of PHI

Definition of Sale of PHI
Under the HIPAA Privacy Rule, a sale of protected health information generally refers to a disclosure of PHI by a covered entity or business associate where the entity receives direct or indirect remuneration in exchange for the PHI. The remuneration is the defining element; readers should verify the precise definition against the current regulatory text.
Authorization Requirement
In most cases, a sale of PHI requires a valid authorization from the individual, and that authorization must generally state that the disclosure will result in remuneration to the covered entity or business associate. This is a heightened requirement beyond ordinary permitted uses and disclosures.
Statutory and Regulatory Exceptions
The Privacy Rule generally identifies specific circumstances that are excluded from the definition of sale, such as certain disclosures for public health, research (limited to a cost-based fee), treatment and payment, and disclosures to the individual. The exact list and any applicable fee limitations should be confirmed against the current CFR text.
Remuneration Scope
Remuneration may be financial or non-financial and may be direct or indirect. The presence of remuneration in exchange for the PHI is what typically triggers the sale-of-PHI provisions rather than the mechanics of how the PHI is transferred.
Applicability to Business Associates
The restrictions on the sale of PHI apply to covered entities and, through the flow-down obligations of business associate agreements, to business associates and their subcontractors that handle PHI on behalf of a covered entity.

Common questions

Answers to the questions practitioners most commonly ask about Sale of PHI.

Does 'sale of PHI' only refer to transactions where a covered entity receives cash for patient records?
No. Under the HIPAA Privacy Rule, sale of PHI is generally defined more broadly than a straightforward cash-for-records transaction. It typically refers to disclosures where the covered entity or business associate receives direct or indirect remuneration in exchange for the PHI. Remuneration is not limited to money and may include other forms of consideration. Because the regulatory meaning differs from the common usage of 'sale,' readers should confirm the specific definition against the current regulatory text.
If a disclosure doesn't count as a 'sale,' does that mean no authorization or other requirements apply?
Not necessarily. The sale-of-PHI provisions generally require a specific authorization for disclosures that qualify as a sale, but a disclosure falling outside that definition may still be governed by other parts of the Privacy Rule. Other disclosures may require an authorization, may be permitted under specified conditions, or may be subject to minimum necessary and other requirements. Treating a transaction as 'not a sale' does not exempt it from the rest of the Privacy Rule, and state law or the HITECH Act may impose additional requirements.
When does an authorization generally need to reference that a disclosure involves remuneration?
In most cases, where a disclosure qualifies as a sale of PHI, the required authorization is generally expected to state that the disclosure will result in remuneration to the covered entity. Because the precise content requirements are set by the regulatory text, you should verify the current authorization requirements against the applicable regulation before relying on a specific form.
Are there disclosures involving payment that are generally not treated as a sale of PHI?
Yes. The Privacy Rule generally recognizes certain exceptions where a payment or exchange of value does not cause a disclosure to be treated as a sale, such as for specified purposes permitted under the rule. The scope and conditions of these exceptions are defined in the regulatory text, so the applicability of any exception to a particular arrangement should be confirmed against the current regulation and, where appropriate, with counsel.
How do sale-of-PHI obligations flow to business associates?
A business associate that receives remuneration in exchange for PHI is generally subject to the sale-of-PHI provisions, and these obligations typically attach through the business associate agreement and the underlying regulatory requirements. A covered entity should ensure its business associate agreements address permitted uses and disclosures so that a business associate does not sell PHI outside what is authorized. Subcontractors handling PHI are generally bound by similar terms flowed down through their own agreements.
Does obtaining HITRUST certification satisfy the sale-of-PHI requirements under HIPAA?
No. HITRUST is a private organization and the HITRUST CSF is a certifiable control framework; certification does not by itself establish HIPAA compliance and is not a legal requirement. The sale-of-PHI provisions are a legal obligation enforced by HHS OCR under the Privacy Rule, and compliance is assessed against the regulation rather than any certification. Organizations should evaluate their disclosure practices directly against current HIPAA requirements and applicable state law.

Common misconceptions

Any disclosure of PHI for money is automatically prohibited.
A sale of PHI is generally permitted where the individual has provided a valid authorization that discloses the remuneration involved. In addition, several defined exceptions exist where a disclosure involving payment is not treated as a sale, such as certain research or public health disclosures subject to applicable fee limits. Practitioners should confirm the specific exceptions against the current regulation.
The sale-of-PHI rules only apply to covered entities.
The restrictions extend to business associates and their subcontractors through the obligations that flow down via business associate agreements. Entities handling PHI on behalf of a covered entity are generally bound by the same limitations.
Charging a fee to provide records or data always counts as a sale of PHI.
Certain permitted disclosures, such as providing an individual access to their own PHI or cost-based fees for research, are generally not treated as a sale. The distinction typically turns on whether the remuneration is in exchange for the PHI and whether a specific exception applies; verify the details against current guidance.

Best practices

Before any disclosure of PHI involving remuneration, determine whether the transaction meets the regulatory definition of a sale and whether any defined exception applies, verifying against the current CFR text.
Where a sale is involved, obtain a valid HIPAA authorization that clearly states the disclosure will result in remuneration to the covered entity or business associate.
Review and update business associate agreements to ensure the sale-of-PHI restrictions flow down to business associates and their subcontractors.
Maintain documentation supporting any claimed exception (for example, research cost-based fees or public health disclosures) so the basis for treating a disclosure as non-sale is defensible.
Train privacy and compliance staff to distinguish permitted disclosures involving fees from disclosures that trigger the sale-of-PHI authorization requirement.
Check whether state law or the HITECH Act imposes additional or more restrictive requirements beyond the HIPAA Privacy Rule, and confirm penalty and enforcement details with current HHS OCR guidance.