Skip to main content
Patient Protect circular logo mark in purple and white used for site navigationPatient Protect

Regulatory guide

The HIPAA Privacy Rule — What Independent Practices Need to Know

The Privacy Rule governs how your practice uses and discloses patient information — who can see it, when, and under what conditions. This guide covers the provisions that matter most for independent practices, in language practitioners can act on.

45 CFR Part 164, Subpart E · current as of September 2026

What is the HIPAA Privacy Rule?

The Privacy Rule (45 CFR Part 164, Subpart E) governs use and disclosureof protected health information — who may see it, for what purpose, and what a patient can require of you. The Security Rule is its counterpart for electronic safeguards. Most of what the Privacy Rule asks for is carried by documents and habits rather than by software.

What it requires
A Notice of Privacy Practices (§164.520), a designated Privacy Officer (§164.530(a)), minimum-necessary limits (§164.502(b)), patient access within 30 days (§164.524), and an accounting of certain disclosures (§164.528).
What it does not require
Patient authorization for treatment, payment or health care operations (§164.506) — a common and expensive misunderstanding. It also does not prescribe a specific form, vendor, or annual training course.
What a small practice should do
Name the Privacy Officer in writing, publish and post the Notice, decide how you will meet a records request inside 30 days, and train the workforce on minimum necessary. Those four carry most of the exposure.
Where the authority is
Every provision below is indexed by citation in the regulation map. The rule itself is 45 CFR Part 164 Subpart E on eCFR, and HHS OCR guidance for interpretation.

Overview

What the Privacy Rule covers.

The HIPAA Privacy Rule (45 CFR Part 164, Subpart E) establishes national standards for the protection of individually identifiable health information. Unlike the Security Rule — which focuses on electronic data — the Privacy Rule covers PHI in every form: electronic records, paper charts, and verbal communications.

For independent practices, the Privacy Rule governs everyday operations: how your front desk discusses patient information, how billing staff share data with insurers, how clinicians coordinate care with specialists, and how your practice responds when a patient asks to see their records.

The rule defines permitted uses and disclosures — situations where PHI can be shared without patient authorization (treatment, payment, healthcare operations, public health reporting) — and situations where written authorization is mandatory (marketing, psychotherapy notes, sale of information). It also establishes patient rights that your practice must support: access, amendment, accounting of disclosures, restrictions, and confidential communications.

Key provisions

The provisions that matter most for your practice.

Minimum Necessary Standard

§164.502(b)

Covered entities must limit the use, disclosure, and request of PHI to the minimum amount needed to accomplish the intended purpose. Staff should not access entire patient records when only a specific data point is needed. This standard applies to internal use, disclosures to third parties, and requests to other covered entities — with exceptions for treatment, patient requests, and legally required disclosures.

The minimum necessary standard in full

Patient Rights

§§164.524–528

Six distinct rights, not one. Access to the designated record set (§164.524). Amendment, which a practice may deny on stated grounds with a right of rebuttal (§164.526). An accounting of certain disclosures, which excludes treatment, payment and operations (§164.528). A request for restriction — which a practice may generally decline, except the mandatory one for a service paid in full out of pocket. Confidential communications by alternative means or at an alternative location, which a provider must accommodate if the request is reasonable (§164.522). And the right to complain without retaliation.

Answering an access request

Notice of Privacy Practices

§164.520

Every covered entity must provide patients with a clear, written notice explaining how their PHI may be used and disclosed, their rights, and the entity's legal obligations. The NPP must be provided at the first service encounter, posted in the facility, and available on the practice's website. A material change may not be implemented before the revised notice's effective date, and a provider then posts the revised notice and makes it available going forward — there is no general duty to mail it to every past patient. Health plans have their own distribution rules.

What the notice must say in 2026

Authorization Requirements

§164.508

Uses and disclosures not covered by TPO or other permitted purposes require a valid, written authorization from the patient. Authorizations must be specific — describing the information, who may disclose it, who may receive it, the purpose, and an expiration date. Psychotherapy notes and marketing uses require separate, specific authorizations.

Administrative Requirements

§164.530

The part practices skip. §164.530 requires a designated privacy official and a contact person for complaints, workforce training, appropriate safeguards, a complaint process, sanctions for workforce who breach policy, mitigation of known harm, no retaliation against anyone who complains, no requiring a patient to waive their rights as a condition of treatment, written policies and procedures, and six-year retention of the documentation the Rule requires.

Privacy vs. Security

How the Privacy Rule differs from the Security Rule.

These two rules are complementary — not interchangeable. Compliance with one does not satisfy the other. Most independent practices need to address both simultaneously.

What it protects

Privacy Rule

All PHI — electronic, paper, and oral

Security Rule

Only ePHI — electronic protected health information

Core focus

Privacy Rule

How PHI is used and disclosed — who can see it and under what circumstances

Security Rule

How ePHI is safeguarded — technical, physical, and administrative controls

Patient rights

Privacy Rule

Access, amendment, accounting of disclosures, restrictions, confidential communications

Security Rule

No direct patient-facing rights — focuses on organizational safeguards

Key requirement

Privacy Rule

Notice of Privacy Practices, minimum necessary standard, authorization requirements

Security Rule

Security Risk Assessment, access controls, encryption, audit logging

Enforcement focus

Privacy Rule

Unauthorized disclosures, failure to provide access, missing NPPs

Security Rule

Missing SRAs, unencrypted ePHI, no access controls, no audit trails

Who must comply

Privacy Rule

Covered entities. Business associates are directly liable for a defined subset — impermissible uses and disclosures, the individual's right of access to records they hold, minimum necessary, BAA terms, and disclosures to HHS

Security Rule

Both covered entities and business associates — fully and directly

For your practice

What this means for your practice.

Train every workforce member on permitted disclosures

Front desk staff, billing teams, and clinical staff all handle PHI differently. Each role needs training on what they can share, with whom, and under what circumstances. The most common Privacy Rule violations come from well-meaning employees who disclose too much information in response to phone calls, family inquiries, or insurance requests.

Post your Notice of Privacy Practices — and make it real

The NPP is not a formality. §164.520(b) requires it to describe the categories of uses and disclosures you actually make, the patient's rights, your duties, and how to complain — not an inventory of every tool or vendor you use. A generic template that does not match how your practice actually handles information is a compliance gap; a notice that omits a whole category of disclosure is a bigger one.

Implement the minimum necessary standard in daily operations

Configure your EHR so each role sees only the data they need. Front desk staff don't need clinical notes. Billing staff don't need psychotherapy records. Minimum necessary reaches use and disclosure, not only Security Rule access control, and role-based access is the usual way a practice implements it — but §164.514(d) asks you to identify who needs what and make reasonable efforts, not to adopt one prescribed architecture.

Know when you need an authorization — and when you don't

Treatment, payment and health care operations do not require authorization. Public health reporting, law enforcement requests and certain regulatory disclosures have their own conditions. Marketing, research, psychotherapy notes and sale of PHI generally do require a valid written authorization — but each has alternative pathways worth knowing: research can proceed on an IRB or Privacy Board waiver, on preparatory-to-research representations, on decedent research, on a limited data set under a data use agreement, or on de-identified data; marketing excludes treatment communications and face-to-face contact; psychotherapy notes and sale of PHI each carry their own statutory exceptions.

Respond to patient access requests without unreasonable delay, and within 30 days

Thirty calendar days is the outer limit, not the target, and you get one written 30-day extension if you need it. Patients have the right to their records in the form and format they request where that is readily producible, including electronic copies. Denials are limited and must be justified. Right of access has been a sustained OCR enforcement priority. You may charge a reasonable, cost-based fee — but never for search and retrieval.

Privacy Rule compliance starts with visibility

Know where your practice stands — before OCR asks.

Patient Protect works across both the Privacy Rule and the Security Rule in a single platform — risk assessments, policy generation, workforce training, and the documentation those obligations produce. Responding to a patient’s request is your practice’s to do; what the platform holds is the record that you did it. No spreadsheets. No consultant required.

14-day free trial · No charge until trial ends

FAQ

Questions about the Privacy Rule.

What is the difference between the Privacy Rule and the Security Rule?

The Privacy Rule governs how PHI in any form — electronic, paper, or oral — is used and disclosed. It defines patient rights and sets standards for who can access information and under what circumstances. The Security Rule focuses specifically on ePHI and requires technical, physical, and administrative safeguards to protect it. Both rules apply to all covered entities, and compliance with one does not satisfy the other.

Does the Privacy Rule apply to small practices?

Yes. There is no size-based exemption, and the standards apply to a solo practitioner as they do to a hospital system. What scales is implementation: the Rule asks what is reasonable and appropriate for an entity of your size and complexity, and some organizational provisions — hybrid entity, affiliated covered entity, organized health care arrangement — apply only to entities structured that way. In practice the obligations a small practice will actually meet are the ordinary ones: a Notice of Privacy Practices, the minimum necessary standard, answering access requests, and documented policies and procedures.

Can I share patient information with a referring physician without authorization?

Yes. Disclosures for treatment purposes — including referrals, consultations, and care coordination — are permitted without patient authorization, and minimum necessary does not apply to them at all (§164.502(b)(2)(i)). Sending the receiving clinician what they actually need is still the right thing to do, but that is clinical judgement and sensible data minimization rather than a minimum-necessary obligation. Minimum necessary does apply to your payment and operations disclosures, and to what your own workforce can reach.

What are the penalties for Privacy Rule violations?

OCR enforces Privacy Rule violations on the same penalty scale as all HIPAA violations: $145 to $73,011 per violation at Tier 1 (unknowing) up to $73,011 to $2,190,294 per violation at Tier 4 (willful neglect, uncorrected), with a $2,190,294 annual cap for identical violations of the same provision (2025 inflation-adjusted per 45 CFR §102.3). The most common Privacy Rule enforcement actions involve failure to provide patient access to records, unauthorized disclosures, and missing or inadequate Notices of Privacy Practices.