Treatment, Payment, and Health Care Operations
Treatment, Payment, and Health Care Operations (TPO) refers to three broad categories of core activities for which the HIPAA Privacy Rule generally permits a covered entity to use and disclose protected health information (PHI) without first obtaining a patient's separate authorization. Treatment covers the provision and coordination of care, payment covers obtaining reimbursement for services, and health care operations covers administrative and business functions that support the entity. These permissions are subject to the Privacy Rule's other conditions and limitations, and readers should verify specific requirements against the current regulation.
TPO is a defined framework under the HIPAA Privacy Rule under which a covered entity is generally permitted to use or disclose PHI for its own treatment, payment, and health care operations activities without individual authorization, subject to applicable Privacy Rule conditions. 'Treatment' encompasses the provision, coordination, or management of health care and related services, including consultation and referral among providers; the Privacy Rule permits disclosure of PHI for the treatment activities of a health care provider. 'Payment' encompasses the various activities of health care providers to obtain payment or be reimbursed for their services and of a health plan to obtain premiums or fulfill coverage responsibilities and provide benefits. 'Health care operations' encompasses defined administrative, financial, legal, and quality-improvement activities that support the entity's core functions. This TPO framework is specific to the Privacy Rule and does not by itself address Security Rule safeguard obligations for ePHI; note also that a covered entity's ability to disclose PHI for another entity's operations is more limited, and that the minimum necessary standard and other conditions generally apply. State law and other requirements may impose additional restrictions, so practitioners should confirm the precise scope against the current regulatory text.
Why it matters
The TPO framework is one of the most practically significant permissions in the HIPAA Privacy Rule because it allows the ordinary business of health care to function without requiring a signed authorization for every use or disclosure of PHI. Without this framework, a provider would arguably need separate patient authorization to consult a specialist, submit a claim to a health plan, or run internal quality-improvement reviews. By generally permitting these three broad categories of activity, the Privacy Rule reduces friction in routine care coordination, reimbursement, and administration while still keeping those uses within defined boundaries.
Who it's relevant to
Inside TPO
Common questions
Answers to the questions practitioners most commonly ask about TPO.