• Contact
  • 888-54-FIRST
  • Client Login
    • Client Portal
    • Online Store
Search
First Healthcare Compliance
  • Solutions
    • Compliance Management Software
    • Online Compliance Courses
    • Compliance Management Suite
  • Plans
  • Resources
    • Blog
    • Virtual Education Hub
    • 1st Talk Compliance Podcast
    • Connect Magazine
    • Compliance Posters
    • Healthcare Compliance Books
    • Newsletter Signup
  • News & Events
    • Press Releases
  • Our Team
  • Request Demo
  • Menu Menu
  • Shopping Cart Shopping Cart
    0Shopping Cart

Blog

HIPAA: Handling Patient Requests for Medical Record Restriction

HIPAA: Handling Patient Requests for Medical Record Restriction

June 21, 2018/in Blog, HIPAA

Healthcare compliance professionals frequently face confusing situations about sharing of protected health information (PHI).  The Health Insurance Portability and Accountability Act (HIPAA) supports the protection of privacy of medical records. However, even when a patient does not authorize sharing of his record there are permitted uses and disclosures such as for the purpose of treatment, payment or healthcare operations (TPO).

The U.S. Department of Health and Human Services (HHS) Office of the National Coordinator for Health IT (ONC) and the Office for Civil Rights (OCR) provide a series of topical fact sheets on HIPAA Permitted Uses and Disclosures with examples of when PHI can be exchanged under HIPAA without first requiring a specific authorization from the patient. Please note that state laws may also apply.

Permitted Uses and Disclosures for Health Care Operations

The ONC issued a useful fact sheet explaining Permitted Uses and Disclosures for Health Care Operations. For activities that fall within HIPAA’s definition of “health care operations,” an entity covered by HIPAA (Covered Entity), such as a physician or hospital, can disclose PHI to another Covered Entity (or a contractor working for that covered entity, i.e., Business Associate). A Covered Entity (CE) can disclose PHI (orally, on paper, by fax, or electronically) to another CE or that CE’s Business Associate for the following subset of health care operations activities without needing patient consent or authorization:

  • Conducting quality assessment and improvement activities
  • Developing clinical guidelines
  • Conducting patient safety activities as defined in applicable regulations
  • Conducting population-based activities relating to improving health or reducing health care cost
  • Developing protocols
  • Conducting case management and care coordination (including care planning)
  • Contacting health care providers and patients with information about treatment alternatives
  • Reviewing qualifications of health care professionals
  • Evaluating performance of health care providers and/or health plans
  • Conducting training programs or credentialing activities
  • Supporting fraud and abuse detection and compliance programs

45 CFR 164.501; 45 CFR 164.506(c)(4).

Case Management scenario from Permitted Uses and Disclosures for Health Care Operations fact sheet

Three conditions must be met when sharing PHI for the purposes stated above:

  1. Both CEs must have or have had a relationship with the patient (can be a past or present patient);
  2. The PHI requested must pertain to the relationship; and
  3. The discloser must disclose only the minimum information necessary for the health care operation at hand.

What is meant by the term ‘minimum necessary’?

Covered entities are required to have reasonable minimum necessary policies and procedures to limit how much PHI is used, disclosed, and requested for certain purposes. Minimum necessary policies and procedures must also reasonably limit who within the entity has access to PHI, and under what conditions, based on job responsibilities and the nature of the business.

For example, the minimum necessary standard requires that a CE limit who within the entity has access to PHI, based on who needs access to perform their job duties. If a hospital employee is allowed to have routine, unimpeded access to patients’ medical records, where such access is not necessary for the employee to do his job, the hospital is not applying the minimum necessary standard. Therefore, any incidental use or disclosure that results from this practice, such as another worker overhearing the hospital employee’s conversation about a patient’s condition, would be an unlawful use or disclosure under the HIPAA Privacy Rule.

Minimum necessary standard is not required among physicians discussing a patient’s medical chart for treatment purposes and does not apply to disclosures, including oral disclosures, among health care providers for treatment purposes.

Permitted Uses and Disclosures for Treatment

The fact sheet titled ‘Permitted Uses and Disclosures: Exchange for Treatment’ explains how HIPAA supports sharing of PHI between and among health care providers in order to treat or coordinate care for their patients. CEs may disclose PHI (orally, on paper, by fax, or electronically) to another provider for the treatment activities of that provider, without needing patient consent or authorization. 45 CFR 164.506(c)(2).

Treatment is broadly defined to include:

  • the provision, coordination, or management of health care and related services by one or more providers, including the coordination or management of health care by a provider with a third party;
  • consultation between providers relating to a patient; or
  • the referral of a patient for care from one provider to another.

45 CFR 164.501.

The disclosing CE is responsible for the PHI until recipient CE has received the information. HIPAA requires disclosing the PHI to the receiving CE in a permitted and secure manner, which includes sending the PHI securely and taking reasonable steps to send it to the right address. The receiving CE is responsible for safeguarding the PHI and otherwise complying with HIPAA, including with respect to subsequent uses or disclosures or any breaches that occur.

Hospital and Treating Physician exchange information scenario from Permitted Uses and Disclosures for Treatment fact sheet

Common HIPAA Questions

Q. How should we ensure that we’re staying compliant with HIPAA Privacy and Security Rules when sharing PHI for purposes of treatment or operations?

Many issues are covered under HIPAA Privacy and Security.  Here are a few important reminders regarding permitted uses and disclosures:

  • HIPAA Security Rule compliance requires disclosure of electronic PHI by CEHRT.
  • Address permitted uses and disclosures in your Notice of Privacy Practices.
  • Follow minimum necessary policies and procedures and apply reasonable safeguards, as required by 45 CFR 164.502(a)(1)(iii).

Q. What are the reasonable safeguard requirements?

Reasonable safeguards vary from CE to CE depending on factors, such as the size of the CE and the nature of its business. In implementing reasonable safeguards, CEs should analyze their own needs and circumstances, such as the nature of the PHI it holds, and assess the potential risks to patients’ privacy. CEs should also take into account the potential effects on patient care and may consider other issues, such as the financial and administrative burden of implementing particular safeguards.

Consider the following examples of appropriate administrative, technical, and physical safeguards:

  • Sign in sheet information is limited to the patient’s name, time of arrival, and the patient’s doctor
  • Fax machine is in a secure location and the “fax disclaimer” is on all outgoing faxes
  • The Notice of Privacy Practices is on your web site and there is no way to access PHI on that site
  • All computer screens are turned away from the patient’s view
  • Screen savers are set to go on after a short period of inactivity
  • No employee leaves his or her computer unattended while PHI is visible on the screen
  • Passwords are assigned only to those who should have access to PHI on the computers
  • Limit the information disclosed over a facility’s public announcement system to the minimum necessary
  • Outgoing mail only shows the minimum necessary information
  • All correspondence containing PHI that is received or sent from the facility is marked confidential
  • Signs are posted to restrict patient access to particular areas and to remind employees about confidentiality
  • Talk quietly and do not use the full name of the patient if not necessary and always use minimum necessary when discussing in public areas
  • E-mail “disclaimer” is on all outgoing messages
  • Medical charts on exam room doors should be turned inward so they do not have any visible information
  • Medical records are set face down when not in use

To gain more HIPAA insight and practical tips consider The Fundamentals guidebook, The Fundamentals course, or helpful downloadable HIPAA posters.

Tags: HIPAA, PHI
Share this
  • Share on Facebook
  • Share on X
  • Share on LinkedIn
  • Share on Reddit
  • Share by Mail
https://1sthcc.com/wp-content/uploads/2018/06/FeaturedImage_HIPAA_-blog_weekof_2018-06-17.jpg 500 800 Catherine Short https://1sthcc.com/wp-content/uploads/2022/10/1sthcc-logo-1024x378.jpg Catherine Short2018-06-21 12:00:402025-04-15 12:53:55HIPAA: Handling Patient Requests for Medical Record Restriction
You might also like
HIPAA Hot Topics
Recent Developments in Health Info Privacy Recent Developments in Health Information Privacy: HIPAA Right of Access, NPRM, & Information Blocking: Audio Version of the Webinar
How to Handle Document Retention & Destruction
Infographic: 6 Areas of Potential Liability for Healthcare Providers 6 Areas of Potential Liability for Healthcare Providers
Document Retention and Destruction Document Retention & Destruction: Audio Version of Webinar
Combatting Ransomware in Healthcare

Subscribe to Weekly eNewsletter

Get the latest healthcare compliance updates straight to your inbox.

Subscribe to Newsletter

Recent Posts

  • OSHA Recordkeeping in Healthcare: Answers to Frequently Asked Questions
  • Naughty or Nice? The Rules of Giving and Receiving in Healthcare
  • fraud waste abuse healthcare compliance
    FWA in Healthcare: How to Respond Appropriately to Detected Offenses
  • Infographic: 6 Areas of Potential Liability for Healthcare Providers
    6 Areas of Potential Liability for Healthcare Providers
  • 5 Benefits of Automating Incident Reporting in Healthcare
  • Compliance Primer Series: Fraud, Waste and Abuse

 

First Healthcare Compliance is a division of Panacea Healthcare Solutions. Learn more

Subscribe

Get the latest healthcare compliance updates straight to your inbox.

Subscribe to Newsletter

Connect

Get started: Request Demo

Call: 1-888-54-FIRST

E-mail: Contact us

  • Link to Instagram
  • Link to Youtube
  • Link to Facebook
  • Link to LinkedIn
  • Link to X
© Copyright 2026 Panacea Healthcare Solutions, LLC | Disclaimer | Privacy Policy and Copyright Notice
Scroll to top Scroll to top Scroll to top

We and our third-party partners use cookies to improve and personalize your experience on the site and with our services in addition to delivering and reporting on ads. Please visit our Privacy Statement for more information. By continuing to browse the site, you are agreeing to our use of cookies. Read Privacy Statement.

OKDismiss

Cookie and Privacy Settings



How we use cookies

We may request cookies to be set on your device. We use cookies to let us know when you visit our websites, how you interact with us, to enrich your user experience, and to customize your relationship with our website.

Click on the different category headings to find out more. You can also change some of your preferences. Note that blocking some types of cookies may impact your experience on our websites and the services we are able to offer.

Essential Website Cookies

These cookies are strictly necessary to provide you with services available through our website and to use some of its features.

Because these cookies are strictly necessary to deliver the website, refusing them will have impact how our site functions. You always can block or delete cookies by changing your browser settings and force blocking all cookies on this website. But this will always prompt you to accept/refuse cookies when revisiting our site.

We fully respect if you want to refuse cookies but to avoid asking you again and again kindly allow us to store a cookie for that. You are free to opt out any time or opt in for other cookies to get a better experience. If you refuse cookies we will remove all set cookies in our domain.

We provide you with a list of stored cookies on your computer in our domain so you can check what we stored. Due to security reasons we are not able to show or modify cookies from other domains. You can check these in your browser security settings.

Other external services

We also use different external services like Google Webfonts, Google Maps, and external Video providers. Since these providers may collect personal data like your IP address we allow you to block them here. Please be aware that this might heavily reduce the functionality and appearance of our site. Changes will take effect once you reload the page.

Google Webfont Settings:

Google Map Settings:

Google reCaptcha Settings:

Vimeo and Youtube video embeds:

Privacy Policy

You can read about our cookies and privacy settings in detail on our Privacy Policy Page.

Privacy Policy and Copyright Notice
Accept settingsHide notification only