8.3 Patient Records, Confidentiality & Permitted Health Information Disclosures

Key Takeaways

  • The HIPAA Privacy Rule (45 C.F.R. Part 164) protects all individually identifiable Protected Health Information (PHI) maintained or transmitted by covered entities, including community and institutional pharmacies.
  • Pharmacies must present a Notice of Privacy Practices (NPP) at the initial service encounter, post it conspicuously, and make a documented good-faith effort to obtain the patient's written acknowledgment of receipt.
  • Protected Health Information may be disclosed without specific patient authorization strictly for Treatment, Payment, and Health Care Operations (TPO), subject to the Minimum Necessary Standard (which does not apply to treatment communications between providers).
  • Patients hold enforceable federal rights under HIPAA to inspect and obtain copies of their pharmacy records within thirty (30) days, request confidential communications, request record amendments, and receive an accounting of non-TPO disclosures made during the prior six (6) years.
  • Under Code of Alabama 1975 § 34-23-33, prescription records are privileged and confidential; unauthorized disclosure constitutes professional misconduct subjecting licensees to suspension, revocation, or civil penalties, with disclosures permitted only under narrow statutory exceptions.
Last updated: September 2026

8.3 Patient Records, Confidentiality & Permitted Health Information Disclosures

[!NOTE] Dual Federal and State Privacy Protection: Pharmacy patient records in Alabama are shielded by two intersecting bodies of law: federal privacy standards established under the Health Insurance Portability and Accountability Act of 1996 (HIPAA, 45 C.F.R. Parts 160 and 164) and state statutory confidentiality protections under the Alabama Pharmacy Practice Act (Code of Alabama 1975 § 34-23-33). Pharmacists must maintain strict confidentiality regarding patient health data, balancing patient privacy against lawful state inspections, public health mandates, and valid judicial process.

A patient's prescription record contains sensitive information regarding medical diagnoses, financial standing, mental health conditions, and personal lifestyle. Unlawful disclosure destroys the fiduciary relationship between patient and pharmacist and exposes practitioners to administrative license revocation, substantial civil monetary fines, and criminal liability.


The HIPAA Privacy Rule in Pharmacy Practice

Enforced by the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR), the HIPAA Privacy Rule establishes national standards for the protection of individually identifiable health information.

Definition of Protected Health Information (PHI)

In pharmacy practice, Protected Health Information (PHI) encompasses any individually identifiable health information created, received, transmitted, or maintained by a covered entity (or business associate) in any medium (electronic, paper hardcopy, or verbal communication) that relates to:

  1. The individual's past, present, or future physical or mental health or condition;
  2. The provision of health care to the individual (including dispensing prescriptions and therapeutic counseling); or
  3. The past, present, or future payment for the provision of health care to the individual.

Identifiers that convert health data into PHI include patient names, residential addresses, dates of birth, telephone numbers, Social Security numbers, medical record numbers, prescription numbers, and health plan beneficiary identifiers.

+-----------------------------------------------------------------------------------------+
|                           HIPAA Covered Entity & Associate Architecture                 |
+-----------------------------------------------------------------------------------------+
| Covered Entity: Pharmacy, Pharmacists, Dispensing Facilities                            |
|      │                                                                                  |
|      ├──► Protected Health Information (PHI) Handled Directly                           |
|      │                                                                                  |
|      └──► Business Associate Agreement (BAA) ──► Business Associates:                   |
|                                                  • Pharmacy Software Vendors            |
|                                                  • Claims Switches & Clearinghouses     |
|                                                  • Data Backup / Cloud Hosts            |
|                                                  • Document Destruction Shredding Firms |
+-----------------------------------------------------------------------------------------+

Business Associates and Business Associate Agreements (BAAs)

A Business Associate (BA) is an external person or entity that performs functions or activities on behalf of a covered pharmacy involving the use or disclosure of PHI (e.g., pharmacy management software vendors, electronic prescription routing networks, claims switch clearinghouses, third-party billing services, cloud storage hosts, and secure document shredding companies). Under 45 C.F.R. § 164.502(e), a pharmacy must execute a written, legally binding Business Associate Agreement (BAA) before granting any third party access to PHI. The BAA binds the vendor to implement administrative, physical, and technical safeguards identical to HIPAA standards.


The Notice of Privacy Practices (NPP)

Under 45 C.F.R. § 164.520, every community and institutional pharmacy must develop and distribute a comprehensive Notice of Privacy Practices (NPP) detailing how patient PHI is used, disclosed, and protected.

Mandatory Distribution & Good-Faith Acknowledgment

  • First Service Delivery: The pharmacy must present the NPP to the patient no later than the date of the first service delivery (i.e., when the patient first drops off or picks up a prescription).
  • Good-Faith Effort for Written Acknowledgment: The pharmacy must make a documented good-faith effort to obtain the patient's written acknowledgment of receipt of the NPP. This is typically accomplished via a physical signature log or digital capture terminal.
  • Patient Refusal or Emergency Situations: If the patient refuses to sign the acknowledgment, or if an emergency situation prevents immediate signature, the pharmacist must document the good-faith effort and the specific reason why acknowledgment was not obtained (e.g., "Patient refused to sign signature terminal," "Patient in acute respiratory distress"). Crucially, a patient's refusal to sign the acknowledgment does not permit the pharmacy to withhold or refuse prescription dispensing.
  • Prominent Display: The NPP must be posted conspicuously in the pharmacy's physical waiting area where patients can readily observe it, and must be permanently available on the pharmacy's public website.

Treatment, Payment, and Health Care Operations (TPO) & The Minimum Necessary Standard

HIPAA permits covered entities to use and disclose PHI without specific patient authorization for three core purposes: Treatment, Payment, and Health Care Operations (TPO).

+-----------------------------------------------------------------------------------------+
|                        The TPO Non-Authorization Framework                              |
+-----------------------------------------------------------------------------------------+
| 1. Treatment: Dispensing medications, conducting prospective DUR, consulting with       |
|    prescribing physicians, providing patient counseling, coordinating hospital discharge|
+-----------------------------------------------------------------------------------------+
| 2. Payment: Submitting insurance claims to pharmacy benefit managers (PBMs), billing    |
|    Alabama Medicaid / Medicare Part D, resolving copay disputes, adjudicating claims    |
+-----------------------------------------------------------------------------------------+
| 3. Health Care Operations: Internal quality audits, peer review, pharmacist training,   |
|    software maintenance, fraud and abuse audits, defending malpractice claims          |
+-----------------------------------------------------------------------------------------+

The Minimum Necessary Standard (45 C.F.R. § 164.502(b))

When using, disclosing, or requesting PHI, a covered entity must make reasonable efforts to limit the information to the minimum necessary to accomplish the intended administrative or clinical purpose.

[!CRITICAL] The Treatment Exception to Minimum Necessary: Under 45 C.F.R. § 164.502(b)(2)(i), the Minimum Necessary Standard DOES NOT APPLY to disclosures to, or requests by, a healthcare provider for treatment purposes. When a pharmacist communicates with a prescribing physician, nurse practitioner, or specialist regarding a patient's clinical care, the pharmacist is legally authorized to share complete diagnostic histories, full active medication profiles, and clinical notes without truncating the data.

Additional Exceptions to the Minimum Necessary Standard

The Minimum Necessary rule also does not apply to:

  1. Disclosures made directly to the individual patient;
  2. Disclosures made pursuant to an explicit, signed HIPAA patient authorization;
  3. Disclosures required by federal or state law (e.g., mandatory disease reporting);
  4. Disclosures required for compliance investigations conducted by the HHS Office for Civil Rights.

Incidental Disclosures and Reasonable Safeguards

HIPAA recognizes that incidental communications (such as a customer briefly overhearing a pharmacist speak a medication name at the counter) may occur during ordinary retail operations. Such incidental disclosures do not constitute violations provided the pharmacy implements reasonable safeguards:

  • Maintaining semi-private counseling areas with acoustic buffers;
  • Lowering speaking voices during consultation and telephone discussions;
  • Positioning computer monitors away from public line-of-sight or applying privacy screen filters;
  • Placing physical barrier tape establishing a 6-foot customer waiting queue.

Enforceable Patient Rights Under HIPAA

HIPAA empowers patients with substantial legal rights regarding their healthcare data:

1. Right of Access, Inspection & Copies (45 C.F.R. § 164.524)

Patients have an enforceable right to inspect and obtain copies of their prescription dispensing records in the format requested (paper or electronic), if readily producible:

  • Statutory Timeline: The pharmacy must act upon the request within thirty (30) calendar days of receipt.
  • Allowable Extension: If records are stored offsite or cannot be produced within 30 days, the pharmacy is permitted a single thirty (30) day extension (total 60 days), provided it sends the patient a written statement before the initial 30 days expire detailing the reasons for the delay and the date of anticipated delivery.
  • Allowable Fees: The pharmacy may charge a reasonable, cost-based fee limited to the cost of supplies (paper, USB drives) and postage. Pharmacies cannot charge retrieval fees, administrative search fees, or fees for merely viewing records.

2. Right to Request Confidential Communications

Patients may request to receive pharmacy communications by alternative means or at alternative locations (e.g., calling a personal mobile phone rather than a shared home landline, or sending statements to a designated P.O. Box). The pharmacy must accommodate reasonable requests and cannot require the patient to explain the reason for the request.

3. Right to Request Record Amendments

Patients may request amendments to their prescription records if they believe information is incorrect or incomplete. The pharmacy must respond within sixty (60) calendar days (with one 30-day extension permitted). The pharmacy may deny the amendment if the record was not created by the pharmacy or is determined to be accurate.

4. Right to an Accounting of Disclosures (45 C.F.R. § 164.528)

Patients have the right to receive a formal accounting of non-routine disclosures of their PHI made by the pharmacy during the six (6) years preceding the request date.

  • Disclosures Excluded from Accounting: The pharmacy is not required to account for disclosures made for Treatment, Payment, or Health Care Operations (TPO), disclosures made directly to the patient, disclosures authorized by the patient in writing, or incidental disclosures.
  • Disclosures Included in Accounting: Disclosures pursuant to court subpoenas, mandatory public health reports, and regulatory audits must be tracked and reported.

Alabama Statutory Confidentiality & Permissible Disclosures

In addition to federal HIPAA standards, Alabama state law strictly enforces prescription confidentiality:

Alabama Pharmacy Practice Act: Ala. Code § 34-23-33

Under Code of Alabama 1975 § 34-23-33(a)(8), the Alabama State Board of Pharmacy possesses statutory authority to suspend, revoke, or refuse to renew any pharmacist license or pharmacy permit for:

Grounds for License RevocationWillfully betraying a professional secret or confidential patient record\text{Grounds for License Revocation} \longleftarrow \text{Willfully betraying a professional secret or confidential patient record}

Releasing prescription data to unauthorized individuals—such as estranged spouses, employers, curious acquaintances, or private investigators—constitutes an immediate violation of Alabama law and professional misconduct.

Permissible Disclosures Without Patient Authorization Under Alabama Law

Disclosing prescription data without patient consent is lawful in Alabama under five specific statutory exceptions:

  1. Alabama Board of Pharmacy Investigators & State Drug Inspectors: Authorized ALBOP personnel have an absolute statutory right to inspect, audit, and copy all pharmacy prescription records, inventory logs, and dispensing profiles during official regulatory inspections without a warrant or patient consent.
  2. Law Enforcement with Valid Judicial Process: A police officer or detective merely presenting a badge and requesting customer records must be refused. Disclosures to law enforcement require a valid search warrant issued by a judicial magistrate, a grand jury subpoena, or an explicit court order signed by a judge.
  3. Alabama Department of Public Health (ADPH): Mandatory statutory reporting of reportable infectious diseases, tuberculosis cases, or public health emergencies under Title 22 of the Alabama Code.
  4. Mandatory Abuse Reporting: Suspected child abuse, elder abuse, or vulnerable adult abuse must be immediately reported to the Alabama Department of Human Resources (DHR) or local law enforcement pursuant to mandatory state reporting statutes.
  5. Alabama Prescription Drug Monitoring Program (PDMP): Automated statutory daily reporting of all dispensed Schedules II, III, IV, and V controlled substances to the ADPH PDMP pursuant to Ala. Code § 20-2-210.

Comprehensive Health Information Disclosure Authorization Matrix

Recipient / Request ScenarioPatient Authorization Required?Legal Authority / Governing StatuteMinimum Necessary Standard Applies?
Treating Physician / PrescriberNOTreatment (45 C.F.R. § 164.506)NO (Exempt under § 164.502(b))
PBM / Insurance Claims SwitchNOPayment (45 C.F.R. § 164.506)YES
Patient Inspecting RecordsNOPatient Access (45 C.F.R. § 164.524)NO
ALBOP Board InspectorNOAla. Code § 34-23-8; ALBOP OversightNO (Full statutory access)
Police Detective with Search WarrantNO45 C.F.R. § 164.512(f); Judicial ProcessYES (Limited to warrant terms)
Police Officer without WarrantSTRICTLY PROHIBITEDAla. Code § 34-23-33; HIPAA ViolationN/A (Disclosure unlawful)
Patient's Employer / HR DeptYES (Signed Authorization)45 C.F.R. § 164.508YES (Restricted to scope)
ADPH Communicable Disease ReportNOAla. Code Title 22; Required by LawYES (Statutory report elements)
Test Your Knowledge

A uniformed municipal police detective enters a community pharmacy in Tuscaloosa without a search warrant, court order, or grand jury subpoena. The detective states that he is investigating an alleged burglary ring and demands to inspect the full prescription profile and dispensing history of a specific customer suspected of fencing stolen goods. Under the HIPAA Privacy Rule and Alabama confidentiality laws (Ala. Code § 34-23-33), how should the supervising pharmacist respond?

A
B
C
D
Test Your Knowledge

An established patient at an independent pharmacy in Decatur requests a complete physical copy of her pharmacy dispensing records for the past three years. The pharmacy accepts the written request on October 1st. Under 45 C.F.R. § 164.524 of the HIPAA Privacy Rule, what is the statutory deadline for the pharmacy to provide the requested records, and under what conditions may an extension be granted?

A
B
C
D
Test Your Knowledge

A community pharmacist in Mobile is conducting a prospective drug utilization review (DUR) and identifies a potentially lethal drug-drug interaction between a newly prescribed antibiotic (clarithromycin) and the patient's existing maintenance statin (simvastatin). The pharmacist contacts the prescribing physician's clinic and discloses the patient's full active medication list and recent dispensing dates to coordinate an alternative therapy. Does this disclosure violate the HIPAA 'Minimum Necessary' standard?

A
B
C
D