Skip to content
Lawwise

      Subjects

      This handbook

      Healthcare Regulation

      Using Health Information Without Written Authorization

      Most disclosures of patient information happen without a signed form, because the privacy rule permits a defined list of purposes outright. The list is closed, the permission is narrower than it sounds, and a separate standard limits how much information each permitted purpose may carry.

      Healthcare Regulation5 min readFederal and stateHealth information

      A row of pale manila folders standing upright in a metal drawer, one pulled forward slightly above the others.
      The question is rarely whether a record can move, but how much of it may travel and for what purpose. — W.carter, CC0, source.

      The rule in short

      A covered entity may use or disclose protected health information without authorization to the individual, for treatment, payment and health care operations, under an opportunity to agree or object, and for an enumerated set of public interest purposes. Everything outside that list requires a written authorization, and psychotherapy notes, marketing and any sale of information require one regardless. Permitted disclosures are separately limited to the minimum necessary to accomplish the purpose.

      The rule is not a general prohibition with exceptions. It is a closed permission. A covered entity may use or disclose protected health information only as the rule permits or requires, and everything outside the permitted list needs a written authorization signed by the individual. Getting this right means identifying which permission applies before the record moves, not after.

      Treatment, payment and operations are three permissions

      They are habitually spoken of as one phrase and defined separately. Treatment covers the provision, coordination or management of care, including consultation between providers and referral. Payment covers activities to obtain reimbursement: eligibility determination, billing, claims adjudication, collection, utilization review for coverage. Health care operations is the broadest and the most misread, covering quality assessment, credentialing, training, business planning, and certain fraud detection.

      The distinction has consequences. A disclosure to another covered entity for that entity's operations is permitted only where both have a relationship with the individual and the purpose falls within a defined subset of operations. A disclosure for treatment carries no such limit. When the wrong label is applied to a transfer, the transfer is unauthorized even though a correctly labeled version would have been permitted.

      How much may travel

      Permission to disclose is not permission to disclose everything. A covered entity must make reasonable efforts to limit the information to the minimum necessary to accomplish the purpose. That is implemented structurally rather than case by case: role-based access policies for internal uses, standard protocols for routine disclosures, and individual review for non-routine requests.

      The standard has defined exclusions and they are the ones that matter most in daily work. It does not apply to a disclosure to a provider for treatment, to a disclosure to the individual, to a disclosure made under the individual's authorization, to a disclosure to the federal agency for enforcement, to a disclosure required by law, or to a disclosure required for compliance with the rule itself.

      Required by law is narrower than lawful

      The permission for disclosures required by law reaches a mandate that compels the disclosure and is enforceable in court. A subpoena signed by an attorney is not that. A law enforcement request is not that. Those routes exist, but they sit in the public interest provisions and carry their own conditions, including satisfactory assurance of notice to the individual or a protective order. Treating any official-looking demand as a legal requirement is one of the most common privacy failures.

      The public interest purposes and their conditions

      A separate provision lists purposes for which authorization is not required and the opportunity to object need not be given. Among them are public health reporting, reports of abuse, neglect or domestic violence, health oversight activities, judicial and administrative proceedings, specified law enforcement purposes, decedent purposes, organ donation, research under approved conditions, averting a serious threat, specialized government functions and workers' compensation.

      Each carries its own conditions, and the conditions are the operative part. Research requires either an authorization, a waiver approved by a review board or privacy board, or a limited data set under a data use agreement. Law enforcement disclosures are permitted only for defined categories and are limited to specified data elements for identification requests. Reading the heading and skipping the conditions produces a disclosure that fails.

      RouteWhat it permitsIndividual's involvementMinimum necessary appliesCommon failure
      TreatmentDisclosure to any provider for careNone requiredNoLabeling a business transfer as treatment
      Payment and operationsReimbursement and defined internal activitiesNone requiredYesSending a full chart where a summary suffices
      Opportunity to objectDirectory listings and notice to family involved in careInformal agreement or chance to objectYesNo record that the opportunity was given
      Public interest purposesEnumerated purposes with conditionsSometimes notice, sometimes noneYesTreating a party subpoena as a legal requirement
      Written authorizationAnything not otherwise permittedSignature on a compliant formNoAn authorization without an expiration term
      Limited data setResearch, public health, operationsNone requiredNo, the set defines the limitUsing it without a data use agreement

      Categories that never move on a permission

      Three categories require authorization no matter how the purpose is characterized. Psychotherapy notes, meaning the separately maintained notes of a mental health professional documenting a counseling session, need authorization for almost every use including treatment by another provider. Marketing communications need authorization where remuneration is involved. Any sale of protected health information needs an authorization that states the sale.

      Substance use disorder records held by a federally assisted program sit under a separate federal regime with its own consent requirements, and the two frameworks do not perfectly align. Where a facility holds both kinds of record, the more restrictive rule governs the record it covers. The same principle governs state law: a state provision more protective of the individual is not displaced.

      When the recipient is a vendor rather than a provider

      A disclosure to a service provider that performs a function on the entity's behalf is not a permitted purpose in its own right. It is permitted because the vendor is a business associate and a written agreement is in place. The distinction is set out in the treatment of business associate agreements and downstream liability, and the agreement is the permission, not a formality that follows it.

      Where a disclosure turns out to have been unpermitted, the analysis shifts immediately to whether it must be reported, which runs through the framework for when exposure of health information must be reported. Access controls and disclosure logs are also examined during inspections, so the record-handling policies reviewed in the facility survey and deficiency process and the multi-state questions raised by remote practice across state lines both feed back into the same documentation.

      Points to carry away

      • The permitted purposes are a closed list; anything outside it requires a written authorization.
      • Treatment, payment and health care operations are three separately defined permissions, not one.
      • The minimum necessary standard limits the volume of a disclosure that is otherwise permitted.
      • Minimum necessary does not apply to a disclosure to a provider for treatment or to the individual.
      • Psychotherapy notes, marketing and any sale of information require authorization in every case.
      • A more protective state law is not displaced by the federal rule.

      Questions readers ask

      Can a patient stop a disclosure that the rule permits?

      Only in a narrow case. An individual may request a restriction on uses for treatment, payment or operations, and the covered entity is generally free to decline. One restriction must be honored: where the individual pays for an item or service in full out of pocket and asks that it not be disclosed to a health plan for payment or operations, the entity must comply. Requests for confidential communications by an alternative address or method must also be accommodated when reasonable.

      Does a signed authorization last indefinitely once given?

      No. A valid authorization must identify the information, the person disclosing, the recipient, the purpose, and an expiration date or event, and it must state that the individual may revoke it in writing. An authorization without an expiration term is defective, and a disclosure made in reliance on a defective authorization is not a permitted disclosure. Revocation operates going forward; it does not undo a disclosure already made in reliance on the authorization before the revocation arrived.

      Are de-identified records still covered by the rule?

      No. Information that has been de-identified is no longer protected health information and may be used or disclosed freely. There are two accepted routes. One removes eighteen categories of identifier and requires no actual knowledge that the remainder could identify anyone. The other rests on a qualified person applying statistical principles and documenting that the risk of identification is very small. A limited data set is a third, distinct category: still regulated, usable for research, public health and operations under a data use agreement.

      Sources

      1. eCFR — 45 CFR 164.502, Uses and Disclosures of Protected Health Information: General RulesThe permitted and required disclosures and the minimum necessary obligation.
      2. eCFR — 45 CFR 164.506, Uses and Disclosures to Carry Out Treatment, Payment, or Health Care OperationsThe scope of the three core permissions and the consent that is not required.
      3. eCFR — 45 CFR 164.512, Uses and Disclosures for Which Authorization Is Not RequiredThe enumerated public interest purposes and the conditions attached to each.
      4. eCFR — 45 CFR 164.514, Other Requirements Relating to Uses and DisclosuresDe-identification, the limited data set, and how minimum necessary is implemented.
      5. eCFR — 45 CFR Part 164 Subpart E, Privacy of Individually Identifiable Health InformationThe privacy rule in full, including authorization content and individual rights.
      6. eCFR — 45 CFR Part 160, General Administrative RequirementsDefinitions, the preemption analysis for state law, and civil money penalty tiers.

      Lawwise is a publication, not a law firm. This article states general rules and cites its sources; it is not advice about any particular case, and the law differs by state and changes over time.

      More in Healthcare Regulation

      Healthcare Regulation

      The Self-Referral Prohibition and the Exceptions to It

      Where a physician or an immediate family member holds an ownership interest in or a compensation arrangement with an entity, the physician may not refer designated health services to that entity for federal payment and the entity may not present a claim for them, unless the arrangement satisfies an exception in full. Liability does not depend on intent. Amounts collected on prohibited referrals must be refunded, and knowing violations carry additional penalties.

      5 min readFederal and state

      Healthcare Regulation

      Provider Enrollment, Revalidation and Revocation

      Enrollment establishes the effective date from which claims may be paid, and certain practitioner types may bill retrospectively for up to thirty days before it. Enrollment must be revalidated every five years, or every three for equipment suppliers, and a revalidation request must be answered within sixty calendar days. Revocation carries a reenrollment bar of one to ten years, extended to twenty for a second revocation, and it takes effect thirty days after the notice is mailed.

      5 min readFederal and state

      Healthcare Regulation

      Overpayments: The Identification Date and the Sixty-Day Clock

      A person who receives an overpayment must report and return it by the later of sixty days after the overpayment was identified or the date any corresponding cost report is due. An overpayment is identified when it is knowingly received or retained, using the knowledge standard of the false claims statute. The deadline can be suspended during a timely good-faith investigation of related overpayments, and by a self-disclosure or an extended repayment request. The lookback period runs six years.

      5 min readFederal and state