Skip to main content
Category: Uses and Disclosures

Treatment, Payment, and Health Care Operations

Also known as: TPO, TPO, Treatment, Payment, and Operations, TPO exception
Simply put

Treatment, Payment, and Health Care Operations (TPO) refers to three broad categories of core activities for which the HIPAA Privacy Rule generally permits a covered entity to use and disclose protected health information (PHI) without first obtaining a patient's separate authorization. Treatment covers the provision and coordination of care, payment covers obtaining reimbursement for services, and health care operations covers administrative and business functions that support the entity. These permissions are subject to the Privacy Rule's other conditions and limitations, and readers should verify specific requirements against the current regulation.

Formal definition

TPO is a defined framework under the HIPAA Privacy Rule under which a covered entity is generally permitted to use or disclose PHI for its own treatment, payment, and health care operations activities without individual authorization, subject to applicable Privacy Rule conditions. 'Treatment' encompasses the provision, coordination, or management of health care and related services, including consultation and referral among providers; the Privacy Rule permits disclosure of PHI for the treatment activities of a health care provider. 'Payment' encompasses the various activities of health care providers to obtain payment or be reimbursed for their services and of a health plan to obtain premiums or fulfill coverage responsibilities and provide benefits. 'Health care operations' encompasses defined administrative, financial, legal, and quality-improvement activities that support the entity's core functions. This TPO framework is specific to the Privacy Rule and does not by itself address Security Rule safeguard obligations for ePHI; note also that a covered entity's ability to disclose PHI for another entity's operations is more limited, and that the minimum necessary standard and other conditions generally apply. State law and other requirements may impose additional restrictions, so practitioners should confirm the precise scope against the current regulatory text.

Why it matters

The TPO framework is one of the most practically significant permissions in the HIPAA Privacy Rule because it allows the ordinary business of health care to function without requiring a signed authorization for every use or disclosure of PHI. Without this framework, a provider would arguably need separate patient authorization to consult a specialist, submit a claim to a health plan, or run internal quality-improvement reviews. By generally permitting these three broad categories of activity, the Privacy Rule reduces friction in routine care coordination, reimbursement, and administration while still keeping those uses within defined boundaries.

Who it's relevant to

Privacy Officers at Covered Entities
Privacy officers rely on the TPO framework to design policies governing routine uses and disclosures of PHI. They must be able to distinguish activities that fall within treatment, payment, or health care operations from those that require individual authorization, and to apply the minimum necessary standard where it applies. They should also confirm how the framework interacts with any stricter state-law requirements.
Health Care Providers and Care Coordination Staff
Clinicians and staff who consult, refer, and coordinate care depend on the treatment permission to share PHI among providers without first securing separate authorization. Understanding that the Privacy Rule generally permits disclosure for the treatment activities of a health care provider helps them support timely care while staying within permitted boundaries.
Billing, Payment, and Revenue Cycle Teams
Staff handling claims, reimbursement, and premium activities operate under the payment category, which covers provider activities to obtain payment and health plan activities to obtain premiums and provide benefits. These teams should understand that payment-related uses remain subject to applicable Privacy Rule conditions, including the minimum necessary standard in most cases.
Compliance and Legal Counsel
Compliance professionals and counsel assess whether specific uses or disclosures qualify under TPO or fall outside it, and they evaluate the more limited rules that apply to disclosures for another entity's health care operations. They should remember that TPO is a Privacy Rule concept that does not by itself address Security Rule safeguard obligations, and that HITECH or state law may impose additional requirements.

Inside TPO

Treatment
Under the HIPAA Privacy Rule, treatment generally refers to the provision, coordination, or management of health care and related services by one or more health care providers, including consultation between providers and referral of a patient from one provider to another. Covered entities may generally use and disclose PHI for treatment purposes without obtaining a separate patient authorization, subject to applicable minimum necessary and other requirements.
Payment
Payment generally encompasses activities undertaken by a health plan to obtain premiums or determine coverage, and by a provider or plan to obtain or provide reimbursement for the provision of health care. This typically includes activities such as eligibility determinations, billing, claims management, and utilization review. PHI may generally be used and disclosed for these purposes without separate authorization, subject to the Privacy Rule's conditions.
Health Care Operations
Health care operations generally refers to a defined set of administrative, financial, legal, and quality improvement activities of a covered entity that are necessary to run its business and support treatment and payment functions. Examples commonly cited include quality assessment, credentialing, and certain business management functions. The specific categories are enumerated in the Privacy Rule and should be confirmed against the current regulatory text.
Permitted use and disclosure without authorization
A central feature of TPO is that the Privacy Rule generally permits covered entities to use and disclose PHI for these three purposes without obtaining a separate patient authorization, distinguishing TPO from many other uses that do require authorization.
Minimum necessary standard
TPO uses and disclosures remain subject to the Privacy Rule's minimum necessary standard in most cases, with a notable general exception for disclosures to or requests by a health care provider for treatment purposes. Readers should verify the scope of exceptions against the current regulation.

Common questions

Answers to the questions practitioners most commonly ask about TPO.

Does TPO give covered entities blanket permission to use or disclose PHI for any purpose?
No. TPO is a specific set of defined categories, treatment, payment, and health care operations, under the HIPAA Privacy Rule that generally permits certain uses and disclosures of PHI without individual authorization. It is not a blanket permission for all purposes. Uses and disclosures falling outside the defined TPO categories, such as most marketing or the sale of PHI, typically require a valid authorization. Additionally, even within TPO, the minimum necessary standard generally applies to many payment and health care operations activities, and other Privacy Rule requirements still govern the use. Readers should confirm scope against the current regulatory text.
Do I always need patient authorization to share PHI for treatment or payment?
Generally, no. One core function of the TPO framework is that a covered entity may typically use and disclose PHI for its own treatment, payment, and health care operations without obtaining individual authorization, and may disclose PHI for the treatment or payment activities of another covered entity in many cases. Authorization requirements usually attach to uses and disclosures that fall outside TPO. That said, some circumstances, such as certain psychotherapy notes or categories protected under other laws, may impose stricter requirements, and state law or other frameworks may add obligations. Verify against current guidance for specific scenarios.
How does the minimum necessary standard apply to TPO uses and disclosures?
The minimum necessary standard generally requires that a covered entity limit PHI to the amount reasonably needed for the intended purpose. A key nuance is that, as of the applicable regulatory text, minimum necessary typically does not apply to disclosures to or requests by a health care provider for treatment. It does generally apply to payment and health care operations activities. Covered entities usually implement this through role-based access policies and defined data-use limits. Because the treatment carve-out and its boundaries can be nuanced in practice, confirm application against the current Privacy Rule.
How should TPO be described in the Notice of Privacy Practices?
A covered entity's Notice of Privacy Practices generally must describe how it may use and disclose PHI for treatment, payment, and health care operations, typically with examples so individuals understand the types of activities involved. The notice is a Privacy Rule requirement and does not by itself function as an authorization. Practical implementation usually involves giving clear, illustrative examples for each of the three TPO categories rather than exhaustive lists. Confirm current content and distribution requirements against the applicable regulatory text, and note that state law may impose additional notice obligations.
How do business associate agreements factor into TPO activities?
When a covered entity engages a vendor to perform functions that involve PHI in support of payment or health care operations, that vendor generally meets the definition of a business associate, and a business associate agreement is typically required. TPO does not eliminate the need for a BAA; rather, the agreement is the mechanism through which certain HIPAA obligations flow to the business associate for those activities. The business associate is generally permitted to use PHI only as the agreement and the Privacy Rule allow. Assess each vendor relationship against the definitions in the current regulation to determine whether a BAA applies.
How can we operationally distinguish health care operations from other uses that require authorization?
Health care operations is a defined category covering activities such as quality assessment, certain business management, and administrative functions, and it is generally broader and more prone to misclassification than treatment or payment. Practically, organizations often maintain internal criteria mapping activities to the regulatory definition and flag borderline uses, particularly those touching marketing or the sale of PHI, for authorization review. Because the boundary between permitted operations and authorization-requiring uses can be fact-specific, involve privacy officers or counsel for uncertain cases and verify categorization against the current Privacy Rule definition of health care operations.

Common misconceptions

Because TPO is permitted without patient authorization, no privacy limits apply to how PHI is used for these purposes.
TPO uses and disclosures are permitted without a separate authorization, but they generally remain subject to other Privacy Rule requirements, including the minimum necessary standard in most cases (with limited exceptions such as treatment-related provider disclosures) and other applicable conditions. Permission is not the same as an absence of limits.
The health care operations category is broad enough to cover essentially any business activity a covered entity wants to conduct with PHI.
Health care operations is a defined and enumerated set of activities under the Privacy Rule, not an open-ended catch-all. Activities falling outside those defined categories may require patient authorization or another permitted basis, and practitioners should confirm the specific categories against the current regulatory text.
TPO permissions cover PHI in electronic form only and are a Security Rule concept.
TPO is a Privacy Rule concept and applies to PHI in all forms, including oral, paper, and electronic. The Security Rule, which governs only ePHI, addresses safeguards rather than the permitted purposes for use and disclosure.

Best practices

Confirm the current enumerated definitions of treatment, payment, and health care operations against the applicable Privacy Rule text before relying on TPO as a basis for a use or disclosure, since the specific categories are defined by regulation.
Apply the minimum necessary standard to payment and health care operations uses and disclosures, and document your reasoning for the treatment-related situations where the general minimum necessary exception applies.
Distinguish clearly between activities that qualify as TPO and those that fall outside it and require patient authorization or another permitted basis, and train staff on where that line falls.
Remember that TPO applies to PHI in all forms, so extend privacy considerations to oral and paper PHI, not just electronic records governed by the Security Rule.
Check whether state law or the HITECH Act imposes additional restrictions on TPO uses and disclosures beyond the federal HIPAA baseline, particularly for sensitive categories of information.
Maintain internal policies and documentation describing how your organization defines and handles TPO uses and disclosures, and review them periodically against current regulatory guidance.