4.8 Privacy, Confidentiality & Pharmacy Policies and Procedures

Key Takeaways

  • Pharmacies are HIPAA covered entities and must also comply with California’s Confidentiality of Medical Information Act (CMIA, Civil Code § 56 et seq.) for individually identifiable medical information.
  • Confidentiality covers patient profiles, prescriptions, eMARs, counseling conversations, and electronic prescription transmissions (e.g., B&P § 4070(c); 16 CCR § 1717.4).
  • Pharmacies need a suitable area for confidential consultation (16 CCR §§ 1714, 1764) and workforce policies limiting access to the minimum necessary information.
  • Pharmacists participate in developing P&Ps, protocols, order sets, and therapeutic guidelines that operationalize clinical and legal standards.
  • The PIC is responsible for pharmacy compliance under B&P § 4113 and must keep P&Ps current, immediately retrievable, and aligned with Board self-assessment expectations.
Last updated: July 2026

4.8 Privacy, Confidentiality & Pharmacy Policies and Procedures

Outline items 3C3 and 3C4 pair two operational competencies that the Board inspects constantly: (1) keeping patient and prescription information confidential and controlled, and (2) building the written policies, procedures, protocols, order sets, and guidelines that make lawful practice reproducible. On the CPJE, expect scenarios that mix federal HIPAA language with California-specific confidentiality duties and PIC accountability.

Confidentiality of Patient and Prescription Information (3C3)

HIPAA baseline

Community and institutional pharmacies that transmit health information electronically in connection with standard transactions are covered entities under the Health Insurance Portability and Accountability Act (HIPAA) Privacy and Security Rules. Protected health information (PHI) includes prescription records, profiles, payment information tied to care, and counseling documentation. Core HIPAA duties for pharmacists include:

  • Using or disclosing PHI only for treatment, payment, and health-care operations—or pursuant to a valid authorization or another permitted pathway.
  • Applying the minimum necessary standard for non-treatment uses and disclosures.
  • Providing a Notice of Privacy Practices and honoring patient rights to access and amend records as required.
  • Implementing administrative, physical, and technical safeguards (role-based access, unique logins, automatic logoff, audit trails, workstation positioning).

HIPAA preempts contrary state law, but more stringent state confidentiality rules still apply. California’s CMIA is the classic example pharmacists must not ignore.

California Confidentiality of Medical Information Act (CMIA)

The Board’s Pharmacy Lawbook intentionally excerpts the Confidentiality of Medical Information Act (Civil Code § 56 et seq.) because pharmacies routinely hold “medical information.” Under CMIA, medical information means individually identifiable information—electronic or physical—regarding a patient’s medical history, mental or physical condition, or treatment, held by (among others) a provider of health care or pharmaceutical company. “Individually identifiable” includes name, address, email, telephone number, SSN, or other data that alone or combined can identify the person.

CMIA generally prohibits disclosure of medical information without a valid written authorization meeting statutory content requirements, subject to enumerated exceptions (for example, disclosures to other providers for diagnosis/treatment, certain public-health or compulsory legal processes, and other listed pathways). Unauthorized disclosure can create civil liability beyond HIPAA enforcement. For CPJE purposes: do not treat “HIPAA allows it” as automatically sufficient in California—check whether CMIA imposes a tighter rule or a required authorization format.

Board enforcement materials also pair privacy failures with pharmacy regulations—inspectors cite confidentiality problems under frameworks such as Civil Code § 56.10 together with operational security rules when records are mishandled or improperly disclosed.

Pharmacy-specific confidentiality controls

California practice standards expect concrete safeguards:

  • Confidential consultation space. Community pharmacy self-assessment tools require an area suitable for confidential patient consultation (16 CCR §§ 1714, 1764). Counseling about HIV therapy, naloxone, contraception, or psychiatric medication in a loud checkout line is both poor practice and a regulatory risk.
  • Electronic prescription security. The security and confidentiality of electronically transmitted prescriptions must be maintained (B&P § 4070(c); 16 CCR § 1717.4). Shared printers in public hallways, unlocked terminals, and unattended e-fax trays are classic failure modes.
  • Profiles, eMARs, and shared databases. If dispensing information is maintained in a shared common electronic file, policies must assure confidentiality of medical information—another recurring self-assessment theme. Access should be role-based; clerks processing insurance claims should not browse unrelated clinical notes.
  • Verbal disclosures. Confirm the patient’s identity before discussing therapy; use professional judgment with family members; prefer speaking to the patient unless an authorized personal representative is involved. Leaving detailed drug names on voicemail or shouting pickup names with drug therapy details undermines confidentiality.
  • Disposal and media controls. Shred hard-copy PHI; wipe or destroy electronic media; control remote work access for verification pharmacists.

Availability and control of records matter as much as secrecy. Profiles and prescription records must remain accessible for care and Board inspection while protected from unauthorized viewing—continuity and confidentiality are dual duties, not opposites.

Developing Policies, Procedures, Protocols & Guidelines (3C4)

Written documents translate statutes and clinical standards into daily behavior. Pharmacists—not only corporate lawyers—must participate in developing and revising:

  • Policies and procedures (P&Ps): operational “how we comply” documents (security, QA under 16 CCR § 1711, temporary pharmacist absence, controlled-substance reconciliation, emergency preparedness, immunization furnishing, sterile compounding, ADDS, etc.).
  • Protocols / standardized procedures: enable pharmacist-initiated therapies (e.g., hormonal contraception, smoking cessation, travel medications, CLIA-waived tests) under California authority and Board-approved statewide protocols where applicable.
  • Order sets: inpatient or clinic electronic order groups that embed evidence-based doses, monitoring, and stop dates—reducing free-text error.
  • Therapeutic guidelines: local adaptations of national guidelines (anticoagulation clinics, antimicrobial stewardship pathways, opioid stewardship).

Effective P&Ps are specific enough to train staff and inspect against, yet updated when law or technology changes. Vague statements such as “follow all laws” fail both surveys and real emergencies.

PIC responsibility for P&P currency

Under B&P § 4113, every pharmacy must designate a pharmacist-in-charge who is responsible for the pharmacy’s compliance with state and federal pharmacy laws. California regulations (including 16 CCR § 1709.1) reinforce that the owner must vest the PIC with adequate authority. Practically, that means the PIC must be able to approve, implement, and enforce P&Ps—even when corporate templates arrive from out of state.

Currency expectations include:

  • Aligning P&Ps with the latest Pharmacy Lawbook, Board subscriber alerts, and self-assessment form revisions.
  • Ensuring required P&Ps exist for high-risk operations (sterile compounding, ADDS, meal-break staffing, QA, inventory reconciliation).
  • Keeping P&Ps immediately retrievable on-site for inspectors and staff (many regulations, including QA under § 1711, explicitly require this).
  • Training staff on revisions and documenting competency where required.
  • Reviewing incidents and near-misses to amend P&Ps—closing the loop with the QA program.

When ownership or PIC changes, incoming PICs should treat a P&P gap analysis as an early priority; Board PIC training materials emphasize accountability for systems, not merely personal dispensing accuracy.

Integrating Privacy Into P&Ps

Privacy is not a separate binder nobody opens. Strong pharmacies weave confidentiality into operational procedures:

WorkflowPrivacy / P&P control
Pickup & counselingVerify identity; use consultation area; minimize PHI on bags/receipts
Technician data entryRole-based EHR/pharmacy-system access; no shared passwords
Transfers & shared databasesDisclose only necessary Rx information to authorized pharmacies/providers
Telepharmacy / remote verificationEncrypted connections; private verification workspace; audit logs
Marketing / refill outreachHonor opt-outs; avoid revealing drug names to third parties
Breach responseInvestigate, mitigate, notify as required by HIPAA/CMIA timelines

Exam Traps

  • Assuming California pharmacies follow only HIPAA and ignoring CMIA authorization rules.
  • Treating the PIC as a figurehead who cannot change corporate P&Ps that violate California law.
  • Confusing lawful treatment disclosures among care-team members with hallway gossip or social-media posts about patients.
  • Having beautiful P&Ps that staff cannot retrieve or that predate major statutory changes (e.g., medication-error reporting, emergency furnishing, staffing autonomy).

Confidentiality protects patients’ dignity and legal rights; current P&Ps protect patients’ safety. The CPJE expects pharmacists to own both.

Test Your Knowledge

Which California law, excerpted in the Board’s Pharmacy Lawbook, specifically restricts disclosure of individually identifiable medical information held by health-care providers and pharmaceutical companies?

A
B
C
D
Test Your Knowledge

A community pharmacy’s only counseling space is the open cash-register lane where other patients can easily overhear therapy details. Which regulatory expectation is most directly implicated?

A
B
C
D
Test Your Knowledge

Who is primarily responsible for ensuring a California pharmacy’s policies and procedures remain compliant with state and federal pharmacy law?

A
B
C
D
Test Your Knowledge

Which activity best illustrates outline competency 3C4 in pharmacy operations?

A
B
C
D