2.6 HIPAA, Patient Confidentiality & Privacy Duties

Key Takeaways

  • HIPAA protects PHI; pharmacies are covered entities and must apply minimum necessary safeguards.
  • Permitted disclosures include treatment, payment, operations, and lawful health-oversight requests such as GDNA inspections.
  • Curiosity queries of PDMP or profiles are impermissible and discipline-worthy.
  • Security Rule expectations include unique logins, role-based access, and protection of ePHI workstations.
Last updated: July 2026

HIPAA, Patient Confidentiality & Pharmacy Privacy Duties

Competency Area 2 explicitly tests regulations that protect patient and health-record confidentiality. On the Georgia MPJE, that means combining the federal Health Insurance Portability and Accountability Act (HIPAA) Privacy and Security Rules with Georgia expectations that pharmacists safeguard prescription records, PDMP data, and counseling conversations. Privacy questions are rarely labeled “HIPAA”—they appear as realistic counter scenarios.

Why Confidentiality Is an MPJE Topic

Pharmacy practice constantly exposes protected health information (PHI): patient identifiers plus health data such as drug names, directions, payment information, and PDMP histories. Improper disclosure can trigger federal civil penalties, Board discipline, employer sanctions, and—when PDMP data is misused—additional state consequences. The exam expects you to know who may receive information, what constitutes the minimum necessary disclosure, and when disclosure is required or permitted without patient authorization.

Core HIPAA Concepts for Pharmacists

Covered entities and business associates

Pharmacies that transmit health information electronically in connection with standard transactions are HIPAA covered entities. Vendors that create, receive, maintain, or transmit PHI for the pharmacy (software vendors, shredding companies, cloud hosts) are typically business associates and need business associate agreements before PHI is shared for those services.

PHI and the minimum necessary standard

PHI includes any individually identifiable health information. When using or disclosing PHI for treatment, payment, or healthcare operations, apply the minimum necessary standard for payment/operations uses (treatment disclosures among providers are more flexible, but still professional). Do not announce a patient’s HIV regimen across a crowded waiting area or leave labeled vials on an open counter visible to other customers.

Notice of Privacy Practices

Pharmacies must make a Notice of Privacy Practices available and make a good-faith effort to obtain written acknowledgment of receipt when required. Staff should know where the notice is posted and how to provide a copy.

Patient rights

Patients generally have rights to access their records, request amendments, request restrictions, request confidential communications, and receive an accounting of certain disclosures. A parent requesting a minor’s sensitive therapy records may raise state-law nuance—when unsure, escalate to the pharmacist-in-charge rather than guessing at the counter.

Permitted Disclosures Without Authorization (High-Yield)

HIPAA permits disclosures without authorization in defined situations. MPJE favorites include:

SituationTypical pharmacy action
TreatmentSpeak with the prescriber or another pharmacist about the patient’s therapy
PaymentSubmit claims to the patient’s insurer
Healthcare operationsQuality review, accreditation, training under safeguards
Public health / reports required by lawCertain adverse event or communicable disease reports when legally required
Law enforcement / Board / GDNAProvide records in response to lawful process, Board investigation, or GDNA inspection authority
PDMP program operationReport and access PDMP data only as authorized for clinical/legal purposes—not curiosity

Disclosures for marketing or sale of PHI generally require authorization. Posting a patient’s medication list on social media is never “operations.”

Georgia-Specific Confidentiality Overlaps

  • Prescription records maintained under O.C.G.A. Title 26 and Board rules are confidential professional records. Limit access to authorized personnel.
  • PDMP data is tightly controlled. Delegates may query only under supervisor rules; using PDMP to check on a neighbor, celebrity, or coworker without a treatment relationship is a classic violation scenario.
  • Counseling privacy: Offer counseling in a manner that reduces eavesdropping—move to a quieter area when discussing mental-health, HIV, or controlled-substance therapies.
  • Employer vs patient: An employer calling for an employee’s drug list usually needs patient authorization unless another legal pathway applies.

Security Rule Essentials (Practical)

The Security Rule focuses on electronic PHI (ePHI). Pharmacies should implement administrative, physical, and technical safeguards: unique logins, automatic logoff, role-based access, encrypted transmission where required, workstation positioning, and secure destruction of hard-copy PHI. Shared “tech1” passwords and unlocked terminals in the drive-thru are exam red flags.

Breach Response Mindset

If PHI is improperly accessed or disclosed (fax to wrong number, lost flash drive, misdirected bag), the pharmacy must assess whether a breach notification duty exists under the Breach Notification Rule and organizational policy. Do not hide the incident; document, mitigate, and escalate. Georgia Board discipline can follow careless privacy practices even when a federal fine is not assessed.

Exam Scenarios to Drill

  1. A patient’s spouse demands the full medication profile without the patient’s agreement and without legal authority → generally refuse or limit to what law allows; seek patient authorization.
  2. GDNA agents conducting an inspection request CS records → lawful oversight disclosure, not a HIPAA violation when properly scoped.
  3. A technician looks up a classmate’s isotretinoin history out of curiosity → impermissible access; report and discipline.
  4. A pharmacist discusses a therapy change with the prescribing APRN → treatment disclosure, permitted.

Confidentiality is not optional customer service—it is a tested legal duty. Combine HIPAA’s framework with Georgia PDMP and recordkeeping rules, and default to minimum necessary, role-based access, and documented lawful purpose whenever information leaves the pharmacy’s control.

Test Your Knowledge

Which scenario is most clearly an impermissible use of Georgia PDMP or pharmacy record access?

A
B
C
D
Test Your Knowledge

Under HIPAA’s minimum necessary concept, which practice is most appropriate at a busy retail counter?

A
B
C
D
Test Your Knowledge

A software vendor that hosts the pharmacy’s electronic prescription records is best categorized as which HIPAA role?

A
B
C
D
Test Your Knowledge

Which disclosure is generally permitted without patient authorization?

A
B
C
D