Skip to main content
Patient Protect circular logo mark in purple and white used for site navigationPatient Protect

Minimum necessary is a standard about effort, not a setting in your software.

Section 164.502(b) asks a covered entity to make reasonable efforts to limit protected health information to the minimum needed for the purpose. It binds your internal uses, your disclosures and your requests — and it has six exceptions, the first of which is treatment.

45 CFR §164.502(b), §164.514(d) · current as of September 2026

Three surfaces, one standard.

The reasonable-efforts standard is deliberately not a formula. What is reasonable turns on your size, your complexity and what the information is for — which is why §164.514(d) asks you to write the answer down rather than derive it each time.

Internal uses

Identify the persons or classes of persons in your workforce who need access to carry out their duties, the categories of PHI each needs, and any conditions appropriate to that access. This is a policy exercise about job function, not a software configuration exercise.

Disclosures you make

For disclosures that recur, set a protocol and apply it — you are not required to reason from first principles every time. For anything nonroutine, review the request individually against criteria you have written down.

Requests you make

The standard runs in both directions. When you ask another entity for PHI, you must limit the request to what is reasonably necessary for the purpose, and the same routine-versus-nonroutine split applies.

The six exceptions.

Where an exception applies, the standard does not. Summaries that list three of these and then say it applies “everywhere else” are the reason practices limit referrals they were never required to limit.

Treatment

Disclosures to, or requests by, a health care provider for treatment. This is the one practices get wrong most often — a referral is not limited by this standard.

To the individual

Disclosures to the individual who is the subject of the information, including a right-of-access request under §164.524.

Under an authorization

Uses and disclosures made pursuant to a valid authorization. The authorization defines the scope; the standard does not narrow it further.

To the Secretary

Disclosures to HHS when required for an enforcement investigation, review or compliance action.

Required by law

Uses and disclosures required by law, where the law itself sets the scope.

Required for compliance

Uses and disclosures required for compliance with the HIPAA Administrative Simplification rules.

Common questions.

Does the Privacy Rule require role-based access control?

It requires policies and procedures identifying who needs access to what, and conditions appropriate to that access. Role-based policy is a sound and common way to satisfy that, and it is what we would recommend — but the Rule does not prescribe a particular software architecture, a role model, or a number of roles. A practice on paper charts satisfies this standard the same way a practice on an enterprise EHR does: by writing down who may see what, and meaning it.

Is this the same as Security Rule access control?

No, and treating them as one thing produces bad policy. §164.502(b) is a Privacy Rule limit on how much information moves, for any purpose, in any medium — spoken, faxed, printed, electronic. §164.312(a) is a Security Rule technical safeguard requiring technical policies and procedures for electronic systems holding ePHI. They overlap in practice and they are not interchangeable in analysis. Minimum necessary can be breached by a conversation.

When can we release an entire medical record?

Where the whole record is reasonably necessary for the purpose — but the Rule asks you to have specifically justified that in your policies and procedures rather than treating it as the default. A blanket practice of sending complete charts is the pattern the standard exists to interrupt.

Can we rely on what the requester tells us?

In defined situations, yes. Reasonable reliance is permitted when a public official states the information requested is the minimum necessary for a permitted purpose, when another covered entity asks, when a professional who is workforce or a business associate states it is the minimum necessary for their stated purpose, or for documented research requests. Reliance is permitted, not required, and it must actually be reasonable in the circumstances.

How much of this has to be written down?

The identification of persons or classes, categories of PHI and access conditions belongs in your policies and procedures, and §164.530(j) requires that documentation to be retained six years. Nonroutine criteria belong there too. What does not belong there is a per-request memo for routine disclosures — that is what the protocol is for.

Deciding who may see what is your policy. Holding the record of it is ours.

Patient Protect enforces role boundaries server-side inside Patient Protect, carries an ePHI Restricted flag per workforce member, and keeps the policies and training records that show what you decided. It does not set minimum-necessary policy for your EHR or your other systems, and it does not make the judgement call for you.

Get your Patient Protect Score — free