Skip to main content
Category: Uses and Disclosures

Uses and Disclosures

Also known as: Permitted Uses and Disclosures, Uses and Disclosures of PHI
Simply put

Under HIPAA, a "use" generally refers to how protected health information (PHI) is handled within an organization, while a "disclosure" refers to sharing that information with someone outside it. The HIPAA Privacy Rule sets rules for when these activities may happen, sometimes requiring the individual's written authorization and sometimes permitting the activity without it. Some minor, secondary disclosures that cannot reasonably be prevented, called incidental disclosures, may also be permitted when appropriate safeguards are in place.

Formal definition

Uses and disclosures are core regulatory concepts under the HIPAA Privacy Rule governing how covered entities (and, through business associate agreements, their business associates) may handle protected health information (PHI) in all forms, including oral, paper, and electronic. The Privacy Rule generally permits certain uses and disclosures without an individual's authorization or permission for a defined set of national priority purposes, as described in HHS guidance on the Privacy Rule, while other uses and disclosures require a valid authorization; readers should confirm the specific permitted categories and conditions against the current regulatory text. 45 CFR § 164.512 addresses uses and disclosures for which authorization or an opportunity to agree or object is not required, including, for example, uses and disclosures required by law, subject to the stated conditions. Incidental uses and disclosures, secondary disclosures that cannot reasonably be prevented, are limited in nature, and occur as a byproduct of an otherwise permitted use or disclosure, are generally not treated as violations when the covered entity has applied reasonable safeguards and the minimum necessary standard where applicable. This entry addresses the Privacy Rule's framework only and does not cover Security Rule technical requirements; note that the HITECH Act and state law may impose additional or more stringent requirements, and practitioners should verify all specific provisions against the current CFR text.

Why it matters

Uses and disclosures sit at the heart of the HIPAA Privacy Rule because they define the boundaries of what a covered entity, and through business associate agreements its business associates, may lawfully do with protected health information. Getting these boundaries wrong is one of the most common sources of privacy complaints and enforcement scrutiny: sharing PHI without a required authorization, or using it internally beyond a permitted purpose, can constitute a violation. Understanding when an activity is a permitted use, a permitted disclosure, or one that requires the individual's written authorization is therefore foundational to Privacy Rule compliance.

The framework also recognizes practical reality through the concept of incidental uses and disclosures. HHS guidance describes an incidental use or disclosure as a secondary one that cannot reasonably be prevented, is limited in nature, and occurs as a byproduct of an otherwise permitted use or disclosure. Because everyday healthcare operations inevitably produce such byproducts, overheard conversations, information visible on a sign-in sheet, the Privacy Rule generally does not treat these as violations when reasonable safeguards and the minimum necessary standard, where applicable, have been applied. This distinction helps organizations focus their compliance efforts on preventable disclosures rather than on eliminating every conceivable byproduct of care delivery.

Beyond the Privacy Rule itself, practitioners should be aware that the HITECH Act and state law may impose additional or more stringent requirements on uses and disclosures. This entry addresses only the Privacy Rule framework and does not cover Security Rule technical safeguards for electronic PHI. Because the specific permitted categories and their conditions are set out in the regulatory text and subject to interpretation through HHS guidance, readers should confirm any particular provision against the current CFR text rather than relying on a general summary.

Who it's relevant to

Privacy Officers
Privacy officers are responsible for establishing policies that distinguish permitted uses and disclosures from those requiring authorization, and for applying the minimum necessary standard where applicable. They also design the reasonable safeguards that keep incidental disclosures within permitted bounds.
Covered Entities
Covered entities must ensure their handling and sharing of PHI, whether oral, paper, or electronic, falls within the Privacy Rule's permitted categories or is supported by a valid authorization, and that any conditions attached to a given category, such as disclosures required by law, are met.
Business Associates
Business associates are bound to the Privacy Rule's use and disclosure limits through their business associate agreements. Their permitted activities generally flow from the terms of that agreement and the underlying regulatory requirements, so they should confirm what their contracts and the applicable rules allow.
Compliance and Legal Teams
Compliance and legal professionals evaluate whether a proposed use or disclosure is permitted, whether an authorization is required, and how state law or the HITECH Act may impose additional or more stringent requirements. They should verify specific provisions against the current CFR text.

Inside Uses and Disclosures

Use
Under the HIPAA Privacy Rule, a 'use' generally refers to the sharing, employment, application, utilization, examination, or analysis of protected health information (PHI) within the covered entity or business associate that maintains it. Use is internal movement or handling of PHI, as distinguished from disclosure.
Disclosure
A 'disclosure' generally refers to the release, transfer, provision of access to, or divulging of PHI outside the entity holding it. Disclosure involves PHI leaving the boundaries of the covered entity or business associate. This applies to PHI in all forms, oral, paper, and electronic, because it falls under the Privacy Rule rather than the Security Rule (which governs only ePHI).
Treatment, Payment, and Health Care Operations (TPO)
The Privacy Rule generally permits covered entities to use and disclose PHI for treatment, payment, and health care operations without individual authorization, subject to conditions in the applicable regulatory text. These are among the most common permitted uses and disclosures.
Permitted Uses and Disclosures
Categories the Privacy Rule generally permits without individual authorization, which typically include disclosures to the individual, TPO, uses and disclosures with opportunity to agree or object, incidental disclosures, certain public interest and benefit activities, and limited data set uses under specified conditions. Readers should verify the specific categories and conditions against the current regulation.
Uses and Disclosures Requiring Authorization
Certain uses and disclosures generally require a valid written authorization from the individual, such as many uses for marketing or the sale of PHI, and psychotherapy notes in most cases. The precise requirements should be confirmed against current Privacy Rule text.
Minimum Necessary Standard
For most uses and disclosures, covered entities and business associates are generally expected to limit PHI to the minimum necessary to accomplish the intended purpose. Certain categories, such as disclosures for treatment or to the individual, are typically excepted from this standard.
Flow-Through Obligations via Business Associate Agreements
Business associates and their subcontractors may use and disclose PHI only as permitted by their business associate agreement and by the Privacy Rule. Obligations attach through these defined contractual relationships rather than to any vendor that merely touches data.

Common questions

Answers to the questions practitioners most commonly ask about Uses and Disclosures.

Does the HIPAA Privacy Rule require a covered entity to obtain patient authorization for every use and disclosure of PHI?
No. This is a common misconception. The Privacy Rule generally permits certain uses and disclosures without individual authorization, most notably for treatment, payment, and health care operations (often abbreviated TPO), as well as certain other permitted or required disclosures defined in the rule. Written patient authorization is generally required for uses and disclosures that fall outside these permitted categories, such as many marketing activities or the sale of PHI. Because the specific conditions and exceptions are detailed, readers should verify the applicable requirements against the current regulatory text.
Do the rules governing uses and disclosures apply only to electronic PHI?
No. The uses and disclosures provisions arise under the HIPAA Privacy Rule, which covers protected health information in all forms, including oral, paper, and electronic. This differs from the HIPAA Security Rule, which applies only to electronic PHI (ePHI). Confusing the two can lead to gaps, because a use or disclosure of information communicated verbally or on paper is still governed by the Privacy Rule even though it is outside the Security Rule's scope.
How does the minimum necessary standard apply to uses and disclosures?
The minimum necessary standard generally requires that, when using or disclosing PHI or requesting it from others, a covered entity limit the information to the minimum reasonably necessary to accomplish the intended purpose. There are recognized exceptions, such as disclosures to or requests by a health care provider for treatment. The standard typically supports role-based access and workforce policies. Because the exceptions and their conditions are specific, confirm how they apply to a given scenario against the current regulatory text.
How should uses and disclosures involving a business associate be handled?
A covered entity may generally disclose PHI to a business associate, and permit the business associate to use or disclose PHI on its behalf, when a business associate agreement is in place. That agreement defines and limits the permitted uses and disclosures. The business associate's obligations, and any flow-down to subcontractors, attach through these defined relationships rather than automatically to every vendor that touches data. The agreement should reflect the specific purposes for which the information may be used or disclosed.
What documentation and tracking should support uses and disclosures in practice?
In most cases, organizations maintain policies and procedures describing permitted uses and disclosures, retain any required patient authorizations, and keep records that support an individual's right to an accounting of certain disclosures. Because the categories of disclosures that must be tracked and the retention expectations are defined by the rule, and because state law or the HITECH Act may impose additional requirements, readers should verify current obligations against the applicable regulatory text.
Does achieving HITRUST CSF certification establish that an organization's uses and disclosures comply with HIPAA?
No. HITRUST is a private organization and the HITRUST CSF is a certifiable control framework; certification is not a legal requirement and does not by itself establish HIPAA compliance. While the CSF may include controls that map to privacy practices, compliance with the Privacy Rule's uses and disclosures provisions is enforced by HHS OCR and must be assessed against the regulation itself. Organizations should treat certification as a supporting control activity rather than as proof of compliance.

Common misconceptions

'Use' and 'disclosure' mean the same thing.
They have distinct regulatory meanings under the Privacy Rule. A use generally involves handling PHI internally within the entity that holds it, while a disclosure generally involves releasing PHI to a party outside that entity. This distinction differs from common usage and affects which requirements apply.
Covered entities always need patient authorization before using or disclosing PHI.
The Privacy Rule generally permits a range of uses and disclosures without individual authorization, including for treatment, payment, and health care operations and certain public interest activities, subject to conditions. Authorization is generally required only for specific categories, and the exact rules should be verified against current regulatory text.
The rules on uses and disclosures apply only to electronic records.
Uses and disclosures are governed by the HIPAA Privacy Rule, which covers PHI in all forms, including oral and paper. The electronic-only scope belongs to the Security Rule, which addresses safeguards for ePHI rather than the permissibility of uses and disclosures.

Best practices

Classify each planned handling of PHI as a use or a disclosure, since the distinction affects which permissions, conditions, and safeguards apply.
Map your routine uses and disclosures against the permitted categories in the current Privacy Rule, and confirm which ones require individual authorization before proceeding.
Apply the minimum necessary standard to uses and disclosures that require it, while recognizing the exceptions (such as treatment-related disclosures) defined in the regulation.
Ensure business associate agreements specifically define the permitted uses and disclosures for each vendor and subcontractor, since these obligations attach through the contractual relationship.
Verify authorization requirements for sensitive categories such as marketing, sale of PHI, and psychotherapy notes against the current regulatory text before acting.
Check whether state law or the HITECH Act imposes additional restrictions on uses and disclosures beyond the baseline HIPAA Privacy Rule requirements, and document your basis for each permitted use or disclosure.