Minimum necessary
What the HIPAA minimum necessary standard requires, when it does not apply, and how small practices put it into practice with role-based access and standard disclosure limits.
Minimum necessary at a glance
The HIPAA minimum necessary rule requires covered entities and business associates to make reasonable efforts to limit protected health information to the minimum necessary for the purpose of a use, disclosure or request (45 CFR 164.502(b)). It does not apply to disclosures to providers for treatment, disclosures to the patient, uses under the patient's authorization, or disclosures required by law. In practice it means role-based access for staff and standard limits for routine disclosures.
| Rule | 45 CFR 164.502(b) and 164.514(d) |
|---|---|
| Applies to | Uses, disclosures and requests of PHI |
| Does not apply to | Treatment disclosures, the patient, authorized disclosures, disclosures to HHS, disclosures required by law |
| Staff access | Identify who needs which PHI and limit access accordingly |
| Routine disclosures | Standard protocols; non-routine requests reviewed case by case |
The rule
When using or disclosing PHI, or requesting it from another covered entity or business associate, you must make reasonable efforts to limit PHI to the minimum necessary to accomplish the purpose (164.502(b)(1)).
When it does not apply
Under 164.502(b)(2), the standard does not apply to:
- disclosures to, or requests by, a health care provider for treatment;
- uses or disclosures to the patient;
- uses or disclosures under the patient’s authorization;
- disclosures to HHS for compliance investigations;
- uses or disclosures required by law;
- uses or disclosures required to comply with the HIPAA rules.
How to put it into practice
| Requirement (164.514(d)) | What a small practice does |
|---|---|
| Identify who needs access to which PHI | List roles — front desk, clinicians, billing — and the PHI each needs |
| Limit access accordingly | Set permissions in the EHR, email and file storage by role — see Access control |
| Standard limits for routine disclosures | Templates for common requests (insurers, other providers for non-treatment purposes) that include only what’s needed |
| Case-by-case review for other disclosures | A short checklist before sending anything unusual |
| Reasonable reliance on certain requests | Requests from other covered entities, public officials or your own professionals can be treated as the minimum necessary when reasonable |
In tools
The standard is why role-based permissions matter when choosing software: an EHR or storage tool where everyone sees everything makes minimum necessary hard to meet.
Related requirements
Frequently asked questions
Does minimum necessary apply when sending records to another doctor?
No. Disclosures to a health care provider for treatment are excluded from the minimum necessary requirement.
Does minimum necessary mean staff can only see some records?
It requires identifying which staff need access to which categories of PHI for their jobs and making reasonable efforts to limit access accordingly — for example, front desk staff may not need clinical notes.
Does minimum necessary apply to business associates?
Yes. Business associates must limit PHI to the minimum necessary when they use, disclose or request it.