hipaa.systems
Privacy Rule · 45 CFR 164.502(b), 164.514(d)

Minimum necessary

What the HIPAA minimum necessary standard requires, when it does not apply, and how small practices put it into practice with role-based access and standard disclosure limits.

Checked 2026-10-06Sources 2

Minimum necessary at a glance

The HIPAA minimum necessary rule requires covered entities and business associates to make reasonable efforts to limit protected health information to the minimum necessary for the purpose of a use, disclosure or request (45 CFR 164.502(b)). It does not apply to disclosures to providers for treatment, disclosures to the patient, uses under the patient's authorization, or disclosures required by law. In practice it means role-based access for staff and standard limits for routine disclosures.

Rule45 CFR 164.502(b) and 164.514(d)
Applies toUses, disclosures and requests of PHI
Does not apply toTreatment disclosures, the patient, authorized disclosures, disclosures to HHS, disclosures required by law
Staff accessIdentify who needs which PHI and limit access accordingly
Routine disclosuresStandard protocols; non-routine requests reviewed case by case

The rule

When using or disclosing PHI, or requesting it from another covered entity or business associate, you must make reasonable efforts to limit PHI to the minimum necessary to accomplish the purpose (164.502(b)(1)).

When it does not apply

Under 164.502(b)(2), the standard does not apply to:

  • disclosures to, or requests by, a health care provider for treatment;
  • uses or disclosures to the patient;
  • uses or disclosures under the patient’s authorization;
  • disclosures to HHS for compliance investigations;
  • uses or disclosures required by law;
  • uses or disclosures required to comply with the HIPAA rules.

How to put it into practice

Requirement (164.514(d)) What a small practice does
Identify who needs access to which PHI List roles — front desk, clinicians, billing — and the PHI each needs
Limit access accordingly Set permissions in the EHR, email and file storage by role — see Access control
Standard limits for routine disclosures Templates for common requests (insurers, other providers for non-treatment purposes) that include only what’s needed
Case-by-case review for other disclosures A short checklist before sending anything unusual
Reasonable reliance on certain requests Requests from other covered entities, public officials or your own professionals can be treated as the minimum necessary when reasonable

In tools

The standard is why role-based permissions matter when choosing software: an EHR or storage tool where everyone sees everything makes minimum necessary hard to meet.

Frequently asked questions

Does minimum necessary apply when sending records to another doctor?

No. Disclosures to a health care provider for treatment are excluded from the minimum necessary requirement.

Does minimum necessary mean staff can only see some records?

It requires identifying which staff need access to which categories of PHI for their jobs and making reasonable efforts to limit access accordingly — for example, front desk staff may not need clinical notes.

Does minimum necessary apply to business associates?

Yes. Business associates must limit PHI to the minimum necessary when they use, disclose or request it.