hipaa.systems
Rule overview · 45 CFR 164.500–164.534

HIPAA Privacy Rule

What the HIPAA Privacy Rule covers: when protected health information may be used and shared, patients' rights over their records, and the administrative duties of covered entities.

Checked 2026-10-06Requirements 8

HIPAA Privacy Rule at a glance

The HIPAA Privacy Rule (45 CFR Part 164, Subpart E) sets national standards for when covered entities and business associates may use and disclose protected health information, and gives patients rights over it. PHI may be used for treatment, payment and health care operations without permission; most other uses need the patient's authorization. Patients can access and get copies of their records within 30 days, request amendments, get an accounting of disclosures and receive a Notice of Privacy Practices.

Where45 CFR Part 164, Subpart E (164.500–164.534)
Applies toPHI in any form — electronic, paper, spoken
Without permissionTreatment, payment, health care operations, and listed public-interest purposes
Needs authorizationMost other uses, including most uses of psychotherapy notes and marketing
Patient accessWithin 30 days, with one 30-day extension
Key dutiesPrivacy official, training, safeguards, complaints process, sanctions, documentation

What it governs

The Privacy Rule answers three questions for covered entities and business associates:

  1. When may PHI be used or shared? Without permission for treatment, payment and health care operations (164.506) and for a defined list of public-interest purposes (164.512). With the patient’s written authorization for most other purposes (164.508). Always limited to the minimum necessary where that standard applies.
  2. What rights do patients have? To receive a Notice of Privacy Practices; to access and get copies of their records; to request amendments; to an accounting of certain disclosures; to request restrictions and confidential communications.
  3. What must the organization have in place? A privacy official, workforce training, reasonable safeguards, a complaints process, sanctions for staff who violate policies, mitigation of harmful disclosures, written policies and six-year documentation (164.530).

What it means when choosing tools

Tools that handle PHI must support these duties: a BAA with any vendor that is a business associate, the ability to find and export a patient’s records for access requests, and settings that limit who sees what.

Requirements explained

Frequently asked questions

What is the difference between the Privacy Rule and the Security Rule?

The Privacy Rule governs who may use and share PHI in any form and patients' rights. The Security Rule sets safeguards specifically for electronic PHI.

Does the Privacy Rule stop doctors from sharing information with each other?

No. Disclosures for treatment are permitted without the patient's authorization, including to other providers.

How long does a practice have to give patients their records?

No later than 30 days after the request, with one possible 30-day extension if the patient is told the reason in writing.