Skip to content
Interdisciplinary CurriculumCurriculum

Your learning stays with you.

Purchase Terms

© 2026 Commensurate Ventures. All rights reserved.

Interdisciplinary CurriculumCurriculum

HIPAA Compliance & Patient Data Security

1HIPAA Privacy Rule: Covered Entities, PHI, and Minimum Necessary2Permitted Uses and Disclosures: Treatment, Payment, Operations, and Authorizations3Security Rule: Administrative, Physical, and Technical Safeguards4Breach Notification: Definition, Risk Assessment, Timeline, and Penalties5Business Associate Agreements and Vendor Management6Patient Rights: Access, Amendment, Accounting, Restrictions, and Confidential Communications7HIPAA Enforcement: OCR Investigation Process, Civil Penalties, Criminal Penalties, and Case Studies8Emerging Issues: Telehealth Privacy, Cloud Services, Health Apps, Wearables, and AI

No recommended media for this unit

1
8 min readProfessional CE

HIPAA Privacy Rule: Covered Entities, PHI, and Minimum Necessary

Establishes the foundational framework of the HIPAA Privacy Rule, including covered entity definitions, PHI scope, and the minimum necessary principle.

Learning Objectives

  • 1Define covered entities, business associates, and protected health information under the Privacy Rule
  • 2Apply the minimum necessary standard to uses and disclosures of PHI
  • 3Distinguish between HIPAA-protected communications and non-protected health information

The Regulatory Foundation of Health Privacy

The Health Insurance Portability and Accountability Act of 1996 established a federal floor for the protection of individually identifiable health information. Before HIPAA, health privacy was governed by a patchwork of state laws, common law duties, and ethical obligations that varied widely in scope and enforceability. HIPAA's Privacy Rule, which became effective on April 14, 2003, created uniform standards for the use and disclosure of protected health information across all states.

Understanding who is bound by HIPAA — and what information receives protection — is the prerequisite for every other compliance obligation. The Department of Health and Human Services Office for Civil Rights (OCR), which enforces HIPAA, has repeatedly emphasized that the Privacy Rule's requirements cannot be properly implemented without a clear grasp of these threshold definitions. OCR enforcement actions show that covered entities frequently violate HIPAA not through willful misconduct but through misunderstanding the scope of their obligations.

Covered Entities: The Three Categories

The Privacy Rule applies to three categories of covered entities. Health plans include group health plans, health insurance issuers, HMOs, Medicare, Medicaid, and military and veterans' health programs. Healthcare clearinghouses process nonstandard health information received from another entity into a standard format. Healthcare providers who conduct certain financial and administrative transactions electronically — such as billing and eligibility inquiries — become covered entities for all PHI they maintain, not just the information involved in electronic transactions.

The covered entity determination is function-based, not label-based. A mental health practice that submits claims to insurers electronically is a covered entity even if it does not self-identify as such. An employer-sponsored health plan is a covered entity even though the employer itself is not. OCR's 2013 breach report analysis found that many small providers did not realize they were covered entities until they experienced a breach and faced OCR investigation.

Hybrid entities — organizations that perform both covered and non-covered functions — may designate health care components that are subject to HIPAA, while excluding functions like employee records or educational programs. The designation must be documented, and the hybrid entity must ensure that the designated health care components comply fully with the Privacy Rule.

Protected Health Information: The 18 Identifiers

Protected health information is individually identifiable health information transmitted or maintained in any form or medium by a covered entity or its business associate. The information must relate to the individual's past, present, or future physical or mental health or condition, the provision of healthcare to the individual, or payment for that care. It must also identify the individual or provide a reasonable basis to believe it could be used to identify the individual.

The Privacy Rule specifies 18 identifiers that, when present with health information, make that information protected. These include names, geographic subdivisions smaller than a state, dates directly related to an individual (birth, admission, discharge, death), telephone and fax numbers, email addresses, Social Security numbers, medical record numbers, health plan beneficiary numbers, account numbers, certificate or license numbers, vehicle identifiers and serial numbers, device identifiers and serial numbers, web URLs, IP addresses, biometric identifiers, full-face photographs, and any other unique identifying number or code.

The 18-identifier framework creates a safe harbor for de-identification under 45 CFR § 164.514(b)(2). If all 18 identifiers are removed and the covered entity has no actual knowledge that the remaining information could be used alone or in combination with other information to identify the individual, the information is no longer PHI and is not subject to the Privacy Rule. An alternative statistical method under § 164.514(b)(1) allows de-identification if a person with appropriate statistical and scientific knowledge determines that the risk of re-identification is very small.

The Minimum Necessary Standard

The Privacy Rule requires covered entities to make reasonable efforts to limit the use, disclosure, and requests for PHI to the minimum necessary to accomplish the intended purpose. This standard does not apply to disclosures to the individual who is the subject of the information, disclosures pursuant to the individual's authorization, disclosures to the Department of Health and Human Services for enforcement purposes, uses or disclosures required by law, and uses or disclosures required for compliance with HIPAA.

Minimum necessary applies to both routine and non-routine disclosures. For routine disclosures, covered entities must implement policies and procedures that limit access to PHI based on job role or function. Role-based access controls are the standard implementation mechanism: front desk staff receive access to demographic and scheduling information but not clinical notes; billing staff receive access to diagnostic codes and procedure information but not full treatment records; physicians receive access to the full medical record for patients under their care.

For non-routine disclosures — such as responses to subpoenas or requests from other providers — the covered entity must review each request individually and disclose only the information reasonably necessary to satisfy the request. OCR's 2016 guidance clarified that covered entities may rely on the requestor's representation that the information requested is the minimum necessary, but this reliance must be reasonable given the circumstances. A request for an entire medical record to verify a single diagnosis would not satisfy the minimum necessary standard without additional justification.

Business Associates and the Extended Privacy Rule

The HITECH Act amendments of 2009, which became effective in 2013, extended most Privacy Rule obligations directly to business associates. A business associate is a person or entity that performs functions or activities on behalf of, or provides services to, a covered entity that involve the use or disclosure of PHI. Common business associate relationships include claims processing, data analysis, utilization review, billing services, practice management, legal services, accounting services, consulting services, and cloud storage providers.

The relationship is functional, not contractual — although a business associate agreement (BAA) is required before PHI may be disclosed to a business associate. If an entity meets the functional definition of a business associate, it is subject to the Privacy Rule whether or not a BAA has been executed. Failure to have a BAA in place before disclosing PHI is itself a violation by the covered entity, but it does not exempt the business associate from compliance.

Subcontractors that create, receive, maintain, or transmit PHI on behalf of a business associate are themselves business associates and must comply with HIPAA. The chain of accountability extends through all tiers: if a covered entity engages a medical billing company, and that billing company uses a cloud hosting provider, both the billing company and the hosting provider are business associates. The covered entity's BAA is with the billing company, and the billing company must have a BAA with the hosting provider.

Personal Representatives and Family Member Access

The Privacy Rule permits covered entities to treat a personal representative the same as the individual for purposes of access to PHI. Personal representatives include parents or guardians of unemancipated minors, court-appointed guardians of adults, healthcare agents under a power of attorney, executors of estates, and others authorized by state law to act on behalf of a deceased individual.

The Privacy Rule creates exceptions where treating a person as a personal representative would not be in the best interest of the individual. If a provider reasonably believes that an adult or emancipated minor has been or may be subjected to domestic violence, abuse, or neglect by the purported personal representative, or that treating the person as the personal representative could endanger the individual, the provider may decline to recognize the personal representative's authority.

For unemancipated minors, state law controls the parent's access to the minor's PHI. If state law requires, permits, or prohibits parental access, HIPAA follows that determination. When state law is silent or unclear, HIPAA permits the covered entity to exercise professional judgment to grant or deny parental access based on the best interest of the minor. This framework is particularly relevant in reproductive health, mental health, and substance abuse treatment contexts, where adolescents may have privacy rights independent of their parents under state law.

The Intersection of HIPAA and State Privacy Laws

HIPAA establishes a federal floor, not a ceiling. State laws that provide greater privacy protections are not preempted by HIPAA. If state law prohibits a disclosure that HIPAA permits, the covered entity must comply with the more restrictive state law. If state law requires a disclosure that HIPAA permits but does not require, the covered entity must comply with state law.

The most common state law variations involve mental health records, substance abuse treatment records (which are also subject to 42 CFR Part 2 at the federal level), HIV status, genetic information, and reproductive health records. Many states impose stricter standards for the release of psychotherapy notes, require separate patient consent for HIV test results, or prohibit certain uses of genetic information. Covered entities operating in multiple states must map the privacy requirements in each jurisdiction and apply the most protective standard.

OCR does not issue advisory opinions on whether a particular state law is more stringent than HIPAA. Covered entities bear the compliance risk if they incorrectly conclude that HIPAA preempts a more protective state law. Legal counsel familiar with state health privacy statutes is often necessary to navigate these overlapping frameworks, particularly in areas where state law imposes criminal penalties for unauthorized disclosure.

Next
Permitted Uses and Disclosures: Treatment, Payment, Operations, and Authorizations

Discussion

From the video libraryBrowse all →
The Tyranny of Merit: Can We Find the Common Good?
1h 8m
The Tyranny of Merit: Can We Find the Common Good?Geneva Graduate Instituteshares: Authority, Disclosure, Representation
How to get dark money out of politics
57m
How to get dark money out of politicsOn with Kara Swishershares: Disclosure, Risk
How the Supreme Court is Dividing America
50m
How the Supreme Court is Dividing AmericaThe 92nd Street Y, New Yorkshares: Disclosure, Authority