4.3 Legal Demands for PHI: Subpoenas, Court Orders, Warrants, and Law Enforcement Inquiries

Key Takeaways

  • Under 45 CFR § 164.512(e), a court order signed by a judge or magistrate legally compels disclosure of only the specific PHI named in the order without patient authorization or notice, whereas an attorney-issued subpoena duces tecum is not a court order and cannot be honored without satisfactory assurances or patient authorization.
  • Satisfactory assurances under § 164.512(e)(1)(ii) require written documentation proving either: (1) good faith written notice to the individual with an opportunity to object (§ 164.512(e)(1)(iii)); or (2) that the parties secured or requested a Qualified Protective Order (QPO) under § 164.512(e)(1)(iv)-(v).
  • A Qualified Protective Order (QPO) must strictly prohibit the parties from using or disclosing the PHI for any purpose outside the specific litigation and mandate the return or destruction of all PHI and copies at the conclusion of the proceeding.
  • Under 45 CFR § 164.512(f)(2), law enforcement inquiries to locate or identify a suspect, fugitive, or witness permit disclosure of only eight specific demographic and physical identifiers, and strictly prohibit disclosing DNA data, dental records, or body fluid analysis.
  • Search warrants issued under the Fourth Amendment compel immediate compliance; HIM and privacy personnel must verify the warrant's validity and scope, shadow executing officers, log seized items, and never physically obstruct execution.
Last updated: September 2026

Legal Demands for PHI: Subpoenas, Court Orders, Warrants, and Law Enforcement Inquiries

AHIMA CHPS Blueprint Focus: Health information professionals frequently operate on the front lines of legal compulsion. When confronted by aggressive trial attorneys, subpoenas, grand jury demands, or law enforcement officers presenting badges, HIM and privacy leaders must enforce exact regulatory boundaries. On the CHPS exam, candidates are heavily tested on the crucial distinction between a judge-signed court order and an attorney-issued subpoena under 45 CFR § 164.512(e), the mandatory elements of a Qualified Protective Order, Fourth Amendment search warrant protocols, and the eight enumerated identifiers permitted under 45 CFR § 164.512(f)(2).


1. Statutory Framework: Judicial Compulsion vs. Law Enforcement

The HIPAA Privacy Rule establishes structured exceptions permitting covered entities to disclose PHI without patient authorization or opportunity to agree or object under two primary sections:

  • 45 CFR § 164.512(e): Disclosures for judicial and administrative proceedings.
  • 45 CFR § 164.512(f): Disclosures for law enforcement purposes.

Permissive vs. Mandatory Nature

Except when an order is signed by a judge with direct contempt powers, disclosures permitted under § 164.512 are generally permissive under federal law—meaning HIPAA authorizes the covered entity to release the data without violating federal privacy rules, but does not itself mandate production. Production obligations are created by underlying state or federal procedural law, court rules, or statutory reporting mandates.


2. Judicial and Administrative Proceedings (45 CFR § 164.512(e))

Every HIM department must distinguish between a direct judicial mandate and an attorney-issued discovery request.

                          [Incoming Legal Demand for Medical Records]
                                             |
                                             v
                              [Who Signed the Legal Document?]
                                 /                       \
                   [Judge, Magistrate, or ALJ]       [Attorney, Clerk, or Notary]
                               /                                   \
                  [COURT ORDER: § 164.512(e)(1)(i)]     [ATTORNEY SUBPOENA: § 164.512(e)(1)(ii)]
                               |                                   |
               [Disclose ONLY Specific Records]       [NEVER Disclose on Subpoena Alone!]
               [Named on Face of Order]                            |
               [No Patient Notice Required]           [Check for 1 of 3 Prerequisites:]
                                                      1. Valid Signed HIPAA Authorization
                                                      2. Written Notice Assurances (§ 164.512(e)(1)(iii))
                                                      3. Qualified Protective Order (§ 164.512(e)(1)(iv))

A. Court Orders (45 CFR § 164.512(e)(1)(i))

A court order is an official mandate issued by a judicial officer—such as a state or federal judge, magistrate, or administrative law judge (ALJ) presiding over an administrative tribunal.

  • Production Mandate: The covered entity must disclose only the PHI expressly authorized by the terms of the order.
  • Four Corners Rule: If a court order authorizes the disclosure of inpatient psychiatric records from March 2026, the facility violates HIPAA if it also releases outpatient notes from April 2026. Disclosing records outside the "four corners" of the judicial order is an impermissible disclosure.
  • No Assurances Needed: A judge-signed court order does not require patient authorization, written notice to the individual, or a qualified protective order. (Note: Heightened state laws and 42 CFR Part 2 may still require specialized judicial findings — a Part 2 record demands a Subpart E court order supported by a good-cause showing, which an ordinary civil court order does not satisfy. The 2024 Reproductive Privacy Rule attestation is not among these requirements: that rule was vacated nationwide in Purl v. HHS in June 2025.)

B. Attorney-Issued Subpoenas Duces Tecum (45 CFR § 164.512(e)(1)(ii))

A subpoena duces tecum (meaning "bring with you under penalty") commands the custodian of records to produce documents at a deposition, hearing, or trial. In modern civil litigation, subpoenas are routinely signed by private attorneys, court clerks, or notaries public acting as officers of the court.

[!CAUTION] The Cardinal Rule of Subpoenas: An attorney-signed subpoena is NOT a court order. A covered entity that immediately produces PHI upon receiving an attorney's subpoena without satisfying federal prerequisites commits an egregious HIPAA violation. Under § 164.512(e)(1)(ii), the covered entity cannot disclose PHI unless it receives one of two forms of satisfactory assurances, or obtains a valid written HIPAA authorization signed by the patient.

The Two Satisfactory Assurance Pathways

Under 45 CFR § 164.512(e)(1)(ii), the party seeking discovery must provide the covered entity with a formal written statement and accompanying documentation proving one of the following:

Pathway 1: Satisfactory Assurances of Written Notice (45 CFR § 164.512(e)(1)(iii))

The requesting party must provide documentation demonstrating that:

  1. The party made a good faith effort to provide written notice to the individual;
  2. The notice included sufficient information about the litigation to permit the individual to raise an objection with the court;
  3. The deadline for raising objections has elapsed; and
  4. Either no objections were filed, or any objections filed by the individual were resolved by the court and the requested disclosure is consistent with that resolution.

Pathway 2: Satisfactory Assurances of a Qualified Protective Order (45 CFR § 164.512(e)(1)(iv))

The requesting party must provide documentation demonstrating that:

  1. The parties to the dispute have agreed to a Qualified Protective Order (QPO) and presented it to the court; or
  2. The party seeking discovery has formally applied to the court for a Qualified Protective Order.

Mandatory Terms of a Qualified Protective Order (45 CFR § 164.512(e)(1)(v))

To be valid under HIPAA, a Qualified Protective Order must be an order of the court or a formal stipulation between litigation parties that satisfies two mandatory criteria:

  1. Use Restriction: Strictly prohibits the parties from using or disclosing the protected health information for any purpose other than the specific litigation or proceeding for which it was requested; and
  2. Return or Destruction: Requires the return of the PHI to the covered entity or the complete destruction of the PHI (including all physical and electronic copies) at the conclusion of the litigation or proceeding.

3. Grand Jury Subpoenas and Law Enforcement Process

Grand Jury Subpoenas (45 CFR § 164.512(f)(1)(ii)(B))

A grand jury subpoena commands the production of records for a secret criminal investigatory grand jury. Because grand jury proceedings are governed by strict federal or state secrecy rules (e.g., Federal Rule of Criminal Procedure 6(e)):

  • The covered entity is not permitted to provide notice to the patient.
  • The satisfactory assurance requirements of § 164.512(e) do not apply to grand jury subpoenas.
  • The covered entity may disclose the requested records pursuant to § 164.512(f)(1)(ii)(B), provided the records are responsive and within the scope of the grand jury demand.
  • The disclosure must be logged in the facility's release tracking system to maintain compliance with the Accounting of Disclosures (§ 164.528).

Administrative Demands and Summonses (45 CFR § 164.512(f)(1)(ii)(C))

Law enforcement agencies (e.g., FBI, DEA, state police, OIG) frequently issue administrative subpoenas, civil investigative demands (CIDs), or summonses. A covered entity may disclose PHI only if the administrative request satisfies a three-part statutory test:

  1. The information sought is relevant and material to a legitimate law enforcement inquiry;
  2. The request is specific and limited in scope to the extent reasonably practicable in light of the purpose for which the information is sought; and
  3. De-identified information could not reasonably be used to satisfy the inquiry.

4. Search Warrants and Fourth Amendment Compulsion

A search warrant is an order issued by a judge or magistrate upon a finding of probable cause under the Fourth Amendment of the U.S. Constitution, authorizing law enforcement officers to enter a specific physical premises and seize specific property or electronic data.

Execution Realities vs. Routine ROI Workflows

Unlike subpoenas (which allow 15 to 30 days to respond), search warrants compel immediate execution. Officers executing a warrant have the legal authority to physically enter the facility, seize paper charts, confiscate workstations, or extract digital server images immediately.

                              [SEARCH WARRANT PRESENTED AT FACILITY]
                                                |
                 +------------------------------+------------------------------+
                 |                                                             |
                 v                                                             v
    [MANDATORY HIM / PRIVACY ACTIONS]                             [EXPRESSLY PROHIBITED ACTIONS]
  - Inspect officer credentials & badges                        - NEVER physically block or obstruct officers
  - Inspect face of warrant (scope, date, judge)                - Do not alter, hide, or delete records
  - Shadow officers continuously                                - Do not argue legal merits on site
  - Log every file, drive, and chart seized                     - Do not consent to search outside named areas
  - Obtain signed copy of officer inventory receipt             - Do not provide unrequested records
  - Escalate immediately to General Counsel

HIM and Privacy Officer Operational Search Warrant Protocol

When law enforcement officers arrive with a search warrant, HIM and compliance leadership must follow a rigid protocol:

  1. Verify Credentials: Inspect the physical agency credentials and badges of the lead agent and executing officers.
  2. Examine the Face of the Warrant: Review the document to verify that: (a) it is signed and dated by a judicial officer; (b) the time limit for execution has not expired; (c) it correctly identifies the facility's name and physical address; and (d) it specifically describes the exact areas to be searched and the specific patient records or electronic devices to be seized.
  3. Non-Interference Rule: Never physically obstruct, delay, or argue with officers executing a valid search warrant. Obstructing a federal or state officer executing a search warrant is a severe criminal offense.
  4. Maintain Custodial Oversight: HIM or compliance staff should accompany the officers at all times, monitoring the extraction process.
  5. Exhaustive Logging and Inventory Receipt: Staff must maintain an exhaustive, real-time inventory of every paper chart, microfiche record, hard drive, USB media, or server imaged. Before the officers depart, staff must obtain a complete, signed copy of the officers' official inventory receipt (e.g., Form CRM-107 or state equivalent).
  6. Immediate Escalation: Immediately notify the facility's General Counsel, Chief Privacy Officer, and Risk Management leadership.

5. Law Enforcement Inquiries Under 45 CFR § 164.512(f)

HIM and emergency department personnel frequently receive verbal or written requests from police officers conducting active investigations. The Privacy Rule strictly controls disclosures based on the factual scenario:

A. Identifying or Locating a Suspect, Fugitive, Material Witness, or Missing Person

Under 45 CFR § 164.512(f)(2), if law enforcement requests PHI to help identify or locate a suspect, fugitive, material witness, or missing person, the covered entity may disclose ONLY the following eight enumerated data elements:

  1. Name and address;
  2. Date and place of birth;
  3. Social Security Number;
  4. ABO blood type and Rh factor;
  5. Type of injury;
  6. Date and time of treatment;
  7. Date and time of death (if applicable); and
  8. A description of distinguishing physical characteristics (e.g., height, weight, gender, hair and eye color, tattoos, surgical scars).

[!WARNING] The Four Prohibited Items under § 164.512(f)(2): A covered entity is strictly prohibited from disclosing the following data elements to law enforcement under the identification and location exception, absent a search warrant, court order, or written patient authorization:

  • DNA data or genetic information;
  • Dental records;
  • Body fluid or tissue analysis (e.g., Blood Alcohol Concentration / BAC results, toxicology drug screens, blood glucose levels, urinalysis);
  • Clinical progress notes or narrative psychiatric documentation.

B. Victims of a Crime (45 CFR § 164.512(f)(3))

A covered entity may disclose PHI about an individual who is suspected to be a victim of a crime if:

  1. The individual agrees to the disclosure; or
  2. The individual is incapacitated or unable to agree due to emergency circumstances, provided that:
    • Law enforcement represents that the information is needed to determine whether another person committed a crime, and cannot wait until the victim is able to agree;
    • Law enforcement represents that the records will not be used against the victim; and
    • The healthcare professional determines, in the exercise of professional judgment, that the disclosure is in the best interest of the individual.

C. Decedents (45 CFR § 164.512(f)(4))

A covered entity may disclose PHI to a law enforcement official about an individual who has died if the entity has a suspicion that the death resulted from criminal conduct.

D. Crime on Premises (45 CFR § 164.512(f)(5))

A covered entity may disclose PHI to law enforcement if the covered entity believes in good faith that the information constitutes evidence of criminal conduct that occurred on the premises of the covered entity.

E. Mandatory Reporting: Child Abuse vs. Adult / Elder Abuse

  • Child Abuse or Neglect (45 CFR § 164.512(b)(1)(ii)): The Privacy Rule explicitly defers to state mandatory reporting statutes. Covered entities are legally permitted—and under state law universally mandated—to report known or suspected child abuse or neglect to public child protection or law enforcement authorities. Patient or parental consent is never required.
  • Adult, Elder, or Domestic Abuse (45 CFR § 164.512(c)): Disclosures regarding adult or elder abuse require that: (1) the individual agrees; or (2) the disclosure is authorized by statute and the clinician believes it is necessary to prevent serious harm; AND the covered entity must promptly inform the individual that a report has been or will be made, unless the clinician believes informing the individual would place them at serious risk of harm.

Comparison of Legal Demands and Production Mandates

Legal InstrumentIssuing AuthorityStatutory BasisPre-Production Legal MandatesScope of Permissible Production
Court OrderState or Federal Judge, Magistrate, or ALJ45 CFR § 164.512(e)(1)(i)None; signed judicial mandate compels productionStrictly limited to the specific PHI named in the order
Attorney SubpoenaPrivate Attorney, Court Clerk, or Notary45 CFR § 164.512(e)(1)(ii)Written notice to patient with objection window, OR Qualified Protective OrderResponsive records within the litigation scope (subject to redactions)
Grand Jury SubpoenaGrand Jury / Federal or State Prosecutor45 CFR § 164.512(f)(1)(ii)(B)None; secret proceeding; notice to patient strictly barredResponsive records; minimum necessary applies; log for accounting
Search WarrantJudicial Officer upon Probable CauseFourth Amendment, § 164.512(f)(1)Immediate execution; inspect warrant face and shadow officersHardware, servers, and charts strictly specified in the warrant
Police Inquiries (§ 164.512(f)(2))Investigating Police Detective / Officer45 CFR § 164.512(f)(2)Verification of official identity and suspect/fugitive statusStrictly limited to the 8 enumerated identifiers; no DNA, dental, or fluids

Exam Tips and Candidate Traps

[!IMPORTANT] The BAC Blood Alcohol Trap: A frequent CHPS scenario involves a police officer entering the Emergency Department following a motor vehicle collision and verbally demanding the trauma patient's Blood Alcohol Concentration (BAC) lab results under § 164.512(f)(2). Do not release the BAC. Section 164.512(f)(2) permits releasing ABO blood type, but explicitly prohibits disclosing body fluid analysis, blood alcohol results, or toxicology screens without a search warrant, court order, or written patient authorization.

[!TIP] Notice Requirements for Grand Jury Subpoenas: If a question asks whether an HIM Director must notify a patient that their records were subpoenaed by a federal grand jury, the answer is NO. Under federal law and § 164.512(f)(1)(ii)(B), grand jury proceedings are secret; notifying the target could constitute criminal obstruction of justice.

[!WARNING] Subpoena Alone Is Never Enough: Whenever an exam vignette describes an attorney serving a subpoena duces tecum signed only by the attorney or a court clerk, immediately look for either: (1) a signed HIPAA authorization; (2) written notice assurances; or (3) a Qualified Protective Order. If none of these exist, releasing records is an actionable HIPAA violation.

Loading diagram...
Legal Demands & Law Enforcement Inquiry Triage Architecture
Test Your Knowledge

A hospital Health Information Management (HIM) department receives a formal subpoena duces tecum signed by a plaintiff's personal injury attorney commanding the immediate production of an emergency department patient's complete medical chart and diagnostic imaging reports. The subpoena is not accompanied by a patient-signed authorization, a court order signed by a judge, or any supporting affidavits. How must the HIM professional proceed under 45 CFR § 164.512(e)?

A
B
C
D
Test Your Knowledge

Two municipal police detectives enter an urban hospital emergency department investigating a serious hit-and-run pedestrian accident. The detectives state they are actively searching for the suspect driver and have reason to believe the suspect was treated at the facility. Citing 45 CFR § 164.512(f)(2), the detectives verbally demand the suspect's name, home address, date of birth, nature of visible injuries, and the numerical results of their clinical Blood Alcohol Concentration (BAC) toxicology screen. What information is the hospital legally permitted to disclose?

A
B
C
D
Test Your Knowledge

Federal law enforcement agents arrive at a medical center's information technology data center presenting a search warrant signed by a United States Magistrate Judge commanding the immediate seizure and electronic copying of a billing database server used in an ongoing healthcare fraud investigation. How should the facility's on-duty Privacy Officer and IT leadership respond?

A
B
C
D