18.1 Confidentiality and Privacy Laws
Key Takeaways
- Healthcare executives own the control environment for confidentiality: policies, training, access controls, release-of-information workflows, and breach response—not only clinical staff behavior.
- The federal Privacy Act of 1974 governs federal agency systems of records; FOIA is a disclosure statute with privacy exemptions that often conflict with patient and employee confidentiality expectations.
- Release of information (ROI) must rest on authorization, a legal exception, or a permitted disclosure—not informal courtesy, media pressure, or internal curiosity.
- HIPAA Privacy, Security, and Breach Notification Rules form the operational confidentiality baseline for covered entities and business associates in U.S. healthcare.
- Minimum necessary, role-based access, BAAs, and documented accounting of disclosures convert legal duties into daily management practice.
Confidentiality and Privacy Laws
Quick Answer: FACHE-level confidentiality competence is operational. Leaders must run a system that limits access to protected information, releases data only under lawful authority, contracts business associates correctly, and responds to breaches and FOIA/media requests without improvisation. Privacy Act, FOIA, HIPAA, and state medical privacy statutes all shape that system—executives need the management implications, not only statute titles.
The ACHE Laws and Regulations domain expects healthcare leaders to apply confidentiality and privacy requirements when designing policies, approving technology, supervising health information management (HIM), responding to subpoenas and media, and overseeing compliance programs. Exam and practice scenarios turn on who may see what, when disclosure is required vs. prohibited, and how leaders create reliable processes under time pressure.
Why Confidentiality Is an Executive Duty
Trust is a strategic asset. Patients share sensitive clinical, financial, and social information because they believe it will be used for care and operations—not gossip, marketing abuse, or casual internal browsing. Confidentiality failures drive OCR investigations, civil liability, criminal exposure in egregious cases, payer and accreditation scrutiny, workforce demoralization, and community reputation damage. Boards hold the CEO and senior team accountable for the privacy control environment: governance, risk assessment, training, access provisioning/deprovisioning, vendor oversight, and incident response.
Confidentiality is not only clinical chart access. It includes employee health and occupational records, credentialing files, quality and peer-review materials (subject to privilege rules), donor and foundation data, strategy documents, and research data. Different legal regimes may apply, but the executive principle is consistent: define the purpose, limit the audience, document the authority, and audit the practice.
Privacy Act of 1974 (Federal Agency Context)
The Privacy Act of 1974 governs how federal agencies collect, maintain, use, and disclose personally identifiable information in systems of records. Healthcare executives encounter it most clearly when leading federal facilities (e.g., VA, military treatment facilities, certain federal clinics), when partnering with federal agencies, or when handling data originating from federal systems under specific agreements.
Core Privacy Act management themes:
| Theme | Executive implication |
|---|---|
| System of records notice | Federal agencies must publish notices describing what is collected, how used, and routine uses |
| Individual access and amendment | Individuals generally may request access to their records and seek correction of inaccurate data |
| Conditions of disclosure | Disclosure without consent is limited to enumerated exceptions (e.g., certain routine uses, law enforcement, court orders) |
| Accountability | Improper maintenance or disclosure can create administrative and civil exposure |
For non-federal hospitals, the Privacy Act is not the day-to-day privacy statute—but executives in public–private partnerships, health information exchanges involving federal partners, or multi-mission systems must still know when federal privacy rules overlay HIPAA. Never assume “we are a private hospital, so Privacy Act never matters” if federal data or federal partners are in scope.
Freedom of Information Act (FOIA) and Transparency vs. Privacy
The Freedom of Information Act (FOIA) is a disclosure statute: it creates a right for the public to request records from federal agencies, subject to exemptions. State open-records / sunshine laws create analogous duties for many state and local public hospitals, health departments, and public university medical centers.
FOIA and open-records regimes force a recurring executive tension: transparency of public business versus privacy of patients, employees, and certain proprietary or security-sensitive materials. Common exemptions and withholding grounds (wording varies by statute) include personal privacy, medical files that would constitute a clearly unwarranted invasion of privacy, law enforcement records, deliberative process materials, and trade secrets/confidential commercial information.
Management implications for FACHE leaders:
- Route requests. FOIA and state public-records requests should go through designated counsel/records officers—not unit managers improvising email replies.
- Separate patient PHI from public records analysis. A request for “ED wait times by day” may be releasable in aggregate; a request for “names of patients who presented after the industrial accident” is not a casual release.
- Train communications and board staff. Media and political pressure do not create legal authority to release protected health information (PHI).
- Document the decision path. Redaction, partial release, and denial rationales should be consistent and defensible.
Public hospital executives often face higher volume and political visibility of records requests. Private nonprofits may still face subpoenas, discovery, accreditation surveys, and voluntary transparency initiatives—none of which replace lawful release procedures.
HIPAA as the Operational Confidentiality Baseline
For most U.S. hospitals, physician groups, health plans, and their vendors, the Health Insurance Portability and Accountability Act (HIPAA) Privacy, Security, and Breach Notification Rules (as amended, including HITECH-related provisions) form the operational privacy baseline. Covered entities and business associates must protect PHI, provide patients rights (access, amendments, restrictions in defined circumstances, accounting of certain disclosures, notice of privacy practices), implement administrative/physical/technical safeguards, and notify affected parties after breaches of unsecured PHI.
Executive-critical HIPAA operating principles:
- Minimum necessary. Workforce access and routine disclosures should be limited to what is needed for the purpose (with treatment-related nuances).
- Role-based access and workforce sanctions. Curiosity viewing, celebrity chart snooping, and sharing passwords are cultural and legal failures.
- Business associate agreements (BAAs). Cloud EHR hosts, billing companies, transcription, shredding, and many analytics vendors need appropriate agreements and oversight—not only a signature on day one.
- Patient rights operations. Delayed access to records is a frequent complaint and enforcement theme; HIM capacity and portals are leadership issues.
- Breach risk assessment and notification. Executives must support honest investigation, not minimization culture that hides incidents.
HIPAA does not preempt all stronger state privacy laws. Behavioral health, HIV, genetic, and substance-use confidentiality rules may impose stricter consent and redisclosure requirements. Multi-state systems need jurisdiction-aware policies.
Release of Information (ROI): Lawful Authority First
Release of information is where policy meets the front desk, HIM department, call center, and sometimes the CEO’s office. Lawful bases typically include:
- Valid patient authorization meeting content requirements (who, what, purpose, expiration, right to revoke, etc.).
- Treatment, payment, and healthcare operations (TPO) under HIPAA for many routine uses/disclosures without authorization.
- Required by law (certain public health reports, court orders, mandated reporting).
- Public interest and other permitted disclosures under HIPAA (narrowly applied—verify, do not stretch).
- Special category rules (psychotherapy notes, Part 2 substance use records, minors’ rights varying by state).
Executive failure modes include verbal “just fax it to the family,” marketing lists built from clinical systems without authorization analysis, research data sharing without IRB/privacy board processes, and releasing more than the request or legal process requires. Subpoenas are not all equal—some require patient authorization or a qualified protective order; counsel and HIM protocols must distinguish valid legal process from incomplete demands.
Building the Privacy Control Environment
High-performing organizations treat confidentiality as a management system:
- Governance: Privacy officer, security officer, compliance committee visibility, board risk reporting.
- Policy and procedure: ROI, minimum necessary, media, law enforcement, deceased patients, minors, workforce access, remote work.
- Training and culture: Role-specific training, sanctions that are real, leadership modeling (no executive exceptions for celebrity charts).
- Technology controls: Unique IDs, audit logs, automatic logoff, encryption standards, deprovisioning on termination.
- Vendor and affiliate management: BAAs, due diligence, right to audit, breach notification clauses.
- Monitoring: Access audits (especially VIPs and coworkers), ROI turnaround metrics, complaint trends, incident root cause.
- Incident response: Playbooks for misplaced devices, misdirected faxes/emails, ransomware, insider threats, and public-records collisions with PHI.
Executive Decision Lens
When a confidentiality issue escalates, FACHE leaders should ask: What is the legal authority to use or disclose? What is the minimum necessary? Who owns the process (HIM, compliance, counsel, security)? What patient rights or FOIA duties apply? What documentation will we defend later? Privacy is not the enemy of care coordination or transparency—uncontrolled disclosure is. Competent executives design systems that share the right information with the right people for the right reason, every time.
A public university medical center receives a state open-records request seeking the names and diagnoses of patients treated after a campus industrial accident. Which executive-aligned response is most appropriate?
Which statement best describes the Privacy Act of 1974 for healthcare executives?
A billing vendor will process claims using hospital PHI. What is the most essential confidentiality control the executive team must ensure before go-live?