HIPAA doesn’t mean you can never share PHI — there are clear rules about when it is permitted or even required.
Permitted Disclosures (No Patient Authorization Required):
-
To the individual – Always permitted.
-
For treatment, payment, and healthcare operations (TPO)
-
Sharing info with specialists
-
Billing insurance
-
Quality improvement reviews
-
-
Incidental disclosures – Accidental but unavoidable (e.g., someone overhears a name in the waiting room) — as long as safeguards are in place.
-
When required by law – Court orders, law enforcement
-
To prevent or lessen a serious threat – If PHI may prevent harm to someone
-
For public health purposes – Disease reporting, FDA tracking
Required Disclosures:
-
To the individual (if they request it)
-
To HHS when requested for a compliance investigation or review
When in Doubt, Leave it Out
If you’re ever unsure whether it’s appropriate to share PHI, always ask your compliance officer or supervisor before doing so.