7.2 Confidentiality, Privacy, and HIPAA Rules
Key Takeaways
- Confidentiality is not absolute and can be breached for child/elder abuse reporting, imminent risk of harm to self/others, or under a court order.
- HIPAA allows disclosure of PHI without client consent for Treatment, Payment, and Operations (TPO), but social workers must adhere to the minimum-necessary disclosure standard.
- A valid release of information (ROI) must be voluntary, informed, and specify the authorized parties, the exact information shared, the purpose, and an expiration date.
- Federal regulation 42 CFR Part 2 enforces stricter confidentiality rules for substance use disorder records than standard HIPAA TPO guidelines.
- Electronic privacy requires robust access controls, encryption, physical safeguards, and signed Business Associate Agreements (BAAs) with technology vendors.
In clinical social work, confidentiality and privacy are the foundations of therapeutic trust. The NASW Code of Ethics (Standard 1.07) and federal regulations, specifically the Health Insurance Portability and Accountability Act (HIPAA), dictate strict standards for the protection of client information. Social workers must understand both the ethical principles and legal requirements governing how client records are maintained, when disclosures are permitted, and the specific limits imposed on privacy in professional practice.
The Limits of Confidentiality
Confidentiality is never absolute. Social workers have a duty to inform clients of the limits of confidentiality during the initial intake and ongoing throughout treatment. Disclosures without client consent are legally and ethically permissible—and often mandated—in specific circumstances:
- Abuse and Neglect: Mandated reporting laws require social workers to report suspected child abuse or neglect, as well as elder or vulnerable adult abuse, to protective services.
- Harm to Self: If a client presents an imminent risk of suicide, the social worker must take protective actions, such as disclosing information to emergency services.
- Harm to Others: Under the duty to warn and protect, social workers must take reasonable steps to protect a third party threatened with imminent, serious physical violence by a client.
- Court Orders: A subpoena signed by a judge requires compliance, though the social worker must first attempt to limit the disclosure or advocate for protective measures.
HIPAA Privacy Rule and TPO
HIPAA establishes national standards for protecting individuals' medical records and other personal health information (PHI). A core concept within the HIPAA Privacy Rule is the allowance of disclosure for Treatment, Payment, and Health Care Operations (TPO) without explicit client authorization:
- Treatment: Sharing PHI among healthcare providers actively treating the client (e.g., consulting with the client's psychiatrist).
- Payment: Disclosing PHI to obtain reimbursement from insurance companies.
- Operations: Using PHI for quality improvement or case management coordination within the agency.
Although TPO allows these disclosures, social workers must adhere to the minimum-necessary disclosure standard. This standard requires that when using or disclosing PHI, the social worker must make reasonable efforts to limit the information to only what is directly necessary to accomplish the intended purpose. For example, when billing an insurance company, the social worker should submit the diagnostic code and session date, rather than detailed progress notes. When consulting with colleagues under treatment exceptions, only relevant details should be shared.
Release of Information (ROI)
For disclosures outside of TPO and statutory mandates, social workers must obtain a valid, written release of information (ROI). An ROI must be specific, voluntary, and informed, containing:
- The specific name of the client.
- The name of the organization authorized to disclose the information.
- The name of the recipient authorized to receive the information.
- A description of the specific information to be shared (e.g., 'evaluation reports only').
- The purpose of the disclosure and an expiration date.
- A statement informing the client of their right to revoke the authorization in writing.
- The signature of the client or legally authorized surrogate, and the date.
Under HIPAA, clients also possess a legal right to access their own clinical records, except in rare cases where the social worker determines that access would cause severe psychological or physical harm to the client. Social workers must document their rationale if they restrict client access.
Special care must be taken with substance use disorder patient records. Under federal regulation 42 CFR Part 2, records maintained in connection with federally assisted substance use disorder programs are subject to stricter confidentiality rules than standard medical records, requiring written consent even for disclosures that would normally be permitted under TPO.
Technology and Electronic Records Privacy
The integration of digital technology in social work introduces privacy vulnerabilities. Social workers must secure electronic health records (EHR) and digital communications:
- Access Controls: Utilize unique user IDs, complex passwords, and multi-factor authentication.
- Encryption: Ensure all transmitted data (e.g., email, telehealth sessions) are encrypted. Unencrypted email should not be used without explicit client consent.
- Physical Safeguards: Secure screens from public view and lock electronic equipment.
- Business Associate Agreements (BAAs): When using third-party vendors (e.g., telehealth platforms), social workers must ensure they sign a BAA, which legally binds them to HIPAA compliance.
Additionally, in the event of a data breach, social workers must follow the HIPAA Breach Notification Rule, which requires notifying affected clients, the Department of Health and Human Services (HHS), and in large-scale breaches, the media.
Clinical Scenario: Managing Subpoenas
A social worker receives a subpoena from a client’s husband’s attorney demanding the client’s entire file for a custody dispute. The husband's attorney claims the records prove the client is emotionally unstable. The client contacts the social worker, refusing to allow her private notes to be shared.
In this scenario, the social worker must not release the records. A subpoena from an attorney is not a court order signed by a judge. The social worker must contact the client to discuss the subpoena. If the client refuses to sign an ROI, the social worker must assert privilege and notify the attorney in writing that the records cannot be released without client authorization or a court order. If the attorney persists, the social worker should file a motion to quash the subpoena. The social worker must protect client privacy, releasing records only when a judge signs an order commanding the release.
A clinical social worker receives a subpoena from a client’s employer’s attorney demanding the client's complete psychotherapy records for an active lawsuit. The client does not want the records released. What is the most appropriate FIRST action for the social worker?
A social worker at a community clinic wants to consult with the client’s primary care physician to coordinate treatment. Under HIPAA rules, what is required before the social worker can share personal health information (PHI) with the physician?
A social worker is selecting a cloud-based video conferencing platform to conduct telehealth sessions with clients. To ensure compliance with HIPAA regulations, what must the social worker do?