HIPAA Privacy Rule
What the HIPAA Privacy Rule covers: when protected health information may be used and shared, patients' rights over their records, and the administrative duties of covered entities.
HIPAA Privacy Rule at a glance
The HIPAA Privacy Rule (45 CFR Part 164, Subpart E) sets national standards for when covered entities and business associates may use and disclose protected health information, and gives patients rights over it. PHI may be used for treatment, payment and health care operations without permission; most other uses need the patient's authorization. Patients can access and get copies of their records within 30 days, request amendments, get an accounting of disclosures and receive a Notice of Privacy Practices.
| Where | 45 CFR Part 164, Subpart E (164.500–164.534) |
|---|---|
| Applies to | PHI in any form — electronic, paper, spoken |
| Without permission | Treatment, payment, health care operations, and listed public-interest purposes |
| Needs authorization | Most other uses, including most uses of psychotherapy notes and marketing |
| Patient access | Within 30 days, with one 30-day extension |
| Key duties | Privacy official, training, safeguards, complaints process, sanctions, documentation |
What it governs
The Privacy Rule answers three questions for covered entities and business associates:
- When may PHI be used or shared? Without permission for treatment, payment and health care operations (164.506) and for a defined list of public-interest purposes (164.512). With the patient’s written authorization for most other purposes (164.508). Always limited to the minimum necessary where that standard applies.
- What rights do patients have? To receive a Notice of Privacy Practices; to access and get copies of their records; to request amendments; to an accounting of certain disclosures; to request restrictions and confidential communications.
- What must the organization have in place? A privacy official, workforce training, reasonable safeguards, a complaints process, sanctions for staff who violate policies, mitigation of harmful disclosures, written policies and six-year documentation (164.530).
What it means when choosing tools
Tools that handle PHI must support these duties: a BAA with any vendor that is a business associate, the ability to find and export a patient’s records for access requests, and settings that limit who sees what.
Requirements explained
- Business associate agreements (BAAs) →§ 164.502(e)A vendor that creates, receives, maintains or transmits PHI on your behalf is generally a business associate, and you need a signed BAA with it before it touches patient data. No BAA means you should not put PHI in that tool.
- De-identification →§ 164.514(a)How HIPAA de-identification works — the Safe Harbor list of 18 identifiers and Expert Determination — and what it means for analytics, AI and research use of health data.
- Emailing patients →§ 164.522(b)HIPAA allows providers to email patients, with reasonable safeguards. Patients may also ask to receive information by email; if they prefer unencrypted email after being warned of the risk, a provider may honor that.
- HIPAA authorization →§ 164.508When you need a patient's written authorization to use or share their health information, what the form must contain to be valid, and how patients can revoke it.
- Minimum necessary →§ 164.502(b)What the HIPAA minimum necessary standard requires, when it does not apply, and how small practices put it into practice with role-based access and standard disclosure limits.
- Notice of Privacy Practices →§ 164.520What the Notice of Privacy Practices must say, when and how a practice must provide it, where it must be posted, and what changed in 2026.
- Psychotherapy notes →§ 164.501What counts as psychotherapy notes under HIPAA, how they differ from progress notes, and the extra protection they get — for therapists choosing how to keep their notes.
- Right of access →§ 164.524Patients' right to see and get copies of their health records: deadlines, formats, fees, third-party requests, and what a small practice needs in place.
Frequently asked questions
What is the difference between the Privacy Rule and the Security Rule?
The Privacy Rule governs who may use and share PHI in any form and patients' rights. The Security Rule sets safeguards specifically for electronic PHI.
Does the Privacy Rule stop doctors from sharing information with each other?
No. Disclosures for treatment are permitted without the patient's authorization, including to other providers.
How long does a practice have to give patients their records?
No later than 30 days after the request, with one possible 30-day extension if the patient is told the reason in writing.