15.3 HIPAA and Privacy Intersections

Key Takeaways

  • HIPAA covered entities are health plans, health care clearinghouses, and health care providers who transmit health information electronically in connection with a standard HIPAA transaction
  • HIPAA permits uses and disclosures for treatment, payment, and health care operations without a HIPAA authorization; Part 2 still generally needs written consent before TPO sharing
  • Minimum necessary limits PHI to what is needed for the purpose; it does not apply to treatment disclosures to a health care provider, to the individual, or to uses under a valid authorization
  • Breach notice to individuals must go out without unreasonable delay and no later than 60 calendar days after discovery; breaches affecting 500 or more people are also reported to HHS, and to media if more than 500 residents of a state are involved
  • The 2024 Part 2 rule applies the HIPAA Breach Notification Rule to Part 2 records; when both laws apply, follow both, and Part 2 is generally the stricter consent rule for SUD records
Last updated: September 2026

Why HIPAA shows up on an ADC ethics item

Domain IV.E is Demonstrate compliance with confidentiality and privacy law. In U.S. practice, that means 42 CFR Part 2 (previous section) and the HIPAA Privacy Rule at 45 CFR Parts 160 and 164, Subparts A and E, plus the Breach Notification Rule at 45 CFR 164.400–414. Many ADC workplaces are both a Part 2 program and a HIPAA covered entity—for example a Medicare-participating opioid treatment program, a Medicaid-billing outpatient clinic, or a hospital SUD unit. When both apply, you follow both. Where they differ, the more protective SUD-record rule usually wins. Part 2 is generally stricter on consent.

HIPAA's goal is to protect protected health information (PHI) while still allowing care, payment, and operations to function. The HHS Office for Civil Rights (OCR) enforces HIPAA. After the 2024 Part 2 rule, OCR also uses HIPAA-style civil and criminal authorities for Part 2 violations, and Part 2 programs must use HIPAA-style breach notice.

Who is a covered entity

The Privacy Rule applies to covered entities:

  1. Health plans (health, dental, vision, and prescription insurers; HMOs; Medicare; Medicaid; many employer group plans), with listed exceptions such as workers' compensation carriers and certain small self-administered employer plans.
  2. Health care clearinghouses that convert nonstandard information to standard HIPAA transactions, and the reverse.
  3. Health care providers who transmit health information electronically in connection with a standard transaction for which HHS has adopted standards—claims, eligibility inquiries, referral authorizations, and similar Transactions Rule activity.

Using email does not, by itself, make a counselor a covered entity. The trigger is a standard electronic transaction, done directly or through a biller. A tiny cash-only practice that never bills electronically may fall outside HIPAA coverage and still be a Part 2 program if it is federally assisted, or the reverse. Do not assume the labels are identical.

A business associate is a person outside the workforce who performs functions involving PHI for a covered entity (billing, EHR hosting, utilization review, legal, accounting). Covered entities need a business associate agreement. Under the 2024 Part 2 definitions, a qualified service organization includes a person who meets the HIPAA business-associate definition for a Part 2 program that is also a covered entity, with respect to PHI that is also a Part 2 record.

PHI is individually identifiable health information held or transmitted by a covered entity or business associate in any form—electronic, paper, or oral—that relates to health status, health care, or payment and that identifies the person or could reasonably be used to identify the person. Employment records the entity keeps as employer, and specified FERPA education records, are not PHI. De-identified information that meets the Privacy Rule's statistician or safe-harbor method is not PHI.

TPO without a HIPAA authorization

A covered entity may use and disclose PHI for TPO without a HIPAA authorization:

  • Treatment: providing, coordinating, or managing care, including consultation and referral.
  • Payment: premiums, coverage determinations, billing, and reimbursement.
  • Health care operations: quality assessment, credentialing, audits, legal services, specified insurance functions, and general administration, including de-identification.

That is the central HIPAA/Part 2 contrast. HIPAA TPO does not require a HIPAA authorization. Part 2 still requires written consent before TPO sharing, but since the 2024 rule one consent can cover future TPO, and HIPAA covered entities and business associates that receive records under that consent may redisclose under HIPAA, except to use the records against the patient in legal proceedings.

HIPAA authorization is required for uses the Privacy Rule does not otherwise permit. Typical exam examples are marketing that does not fit a health-care-operations exception, selling PHI, and most employer or life-insurance disclosures. Psychotherapy notes (and, under Part 2, SUD counseling notes) need their own authorization or consent except for listed uses such as the originator's treatment use, specified training, or defense in a proceeding the patient brought.

Covered providers with a direct treatment relationship must give patients a Notice of Privacy Practices no later than the first service encounter, post it, and make a good-faith effort to obtain a written acknowledgement of receipt. The 2024 Part 2 rule brought Part 2 patient-notice content closer to that HIPAA notice. Individuals also have HIPAA rights to access PHI in the designated record set, request amendment, request restrictions, request confidential communications, and obtain an accounting of certain disclosures.

Trap: telling a client that HIPAA lets the clinic fax the entire SUD chart to anyone on a treatment team without asking, so Part 2 no longer matters. If you are a Part 2 program, obtain the Part 2 TPO consent, or another Part 2 permission, first.

Minimum necessary

Covered entities must make reasonable efforts to use, disclose, and request only the minimum necessary PHI to accomplish the purpose. Do not send the entire record for a payment audit if a date range and diagnosis codes would do, unless you can justify the whole record.

Minimum necessary does not apply to: (a) disclosure to or a request by a health care provider for treatment; (b) disclosure to the individual; (c) use or disclosure under a valid authorization; (d) disclosure to HHS for HIPAA enforcement; (e) use or disclosure required by law; or (f) uses required to comply with the HIPAA Transactions Rule.

Scenario: A health plan asks for "everything you have" to process one outpatient claim. Under HIPAA, payment is TPO, but minimum necessary still applies to that payment request. Send what the claim requires. Separately, if the chart is a Part 2 record, confirm you have a valid Part 2 TPO consent, or another Part 2 permission, before you disclose.

Workforce access should be role-based. The receptionist does not need overnight group-therapy process notes to check someone in. Reasonable safeguards (lowered voices, screen privacy, not posting census boards in public hallways) also limit incidental disclosures.

Breach notification basics

A breach is generally an impermissible acquisition, access, use, or disclosure of unsecured PHI that compromises privacy or security. The Privacy Rule presumes an impermissible use or disclosure is a breach unless the entity documents a low probability that the PHI was compromised, using at least four factors: nature and extent of the information; who received it; whether it was actually viewed; and how far the risk was mitigated.

Three narrow exceptions include certain good-faith unintentional access by a workforce member acting within authority, certain inadvertent disclosures between authorized persons in the same entity, and disclosures where the recipient could not reasonably have retained the information.

Notice to each affected individual must go out without unreasonable delay and in no case later than 60 calendar days after discovery (45 CFR 164.404). If 500 or more individuals are affected, notify the HHS Secretary on the same 60-day outer limit. If the breach involves more than 500 residents of a single state or jurisdiction, notify prominent media serving that state, also within 60 days. Breaches affecting fewer than 500 individuals are logged and reported to HHS no later than 60 days after the end of the calendar year. Business associates notify the covered entity within the same 60-day outer limit.

The 2024 Part 2 rule applies the HIPAA Breach Notification Rule to Part 2 records. Do not teach that Part 2 has no breach-notice duty. That was the pre-2024 picture; it is not current. Patients may also file a Part 2 complaint with the program and directly with the HHS Secretary.

When both laws apply

IssueHIPAA Privacy Rule42 CFR Part 2 (current)
Who is coveredHealth plans, clearinghouses, providers who do standard electronic transactionsFederally assisted SUD programs as defined in §§ 2.11–2.12
TPO sharingPermitted without authorizationWritten consent still required; a single consent may cover future TPO
Redisclosure after TPOOrdinary HIPAA permissionsCovered-entity and business-associate recipients may redisclose under HIPAA; still barred from using records against the patient in legal proceedings without consent or a Part 2 court order
SubpoenaSometimes enough with notice or a protective orderNot enough; need consent or a good-cause court order
Child-abuse reportPermitted/required-by-law pathwaysInitial state-law report permitted; the SUD file remains restricted for later proceedings
Breach notice60-day individual notice; 500+ to HHS and, if 500+ residents of a state, to mediaSame HIPAA breach rule now applies to Part 2 records
Counseling notesExtra authorization for psychotherapy notesSUD counseling notes need separate consent; cannot ride on TPO consent

Scenario: You work in a Medicaid-billing intensive outpatient program that advertises SUD treatment. You are a HIPAA covered provider and a Part 2 program. A primary-care physician requests last month's progress notes to manage the client's diabetes medications. HIPAA would allow a treatment disclosure without a HIPAA authorization, and minimum necessary would not block a treatment disclosure to a provider. Part 2 still requires a valid written consent—a TPO consent that names treating providers is designed for this—unless an exception such as a bona fide medical emergency applies.

Trap: picking the law that is easier that day. Exam keys follow the stricter applicable limit. Another trap: confusing informed consent to treatment (Domain IV.G, next chapter) with consent to disclose records. They are different documents. State laws that are more protective still apply; HIPAA does not wipe out a tighter state SUD-confidentiality statute.

Loading diagram...
When HIPAA and Part 2 both apply to an ADC workplace
Test Your Knowledge

Who is a HIPAA covered entity?

A
B
C
D
Test Your Knowledge

Which statement about HIPAA treatment, payment, and health care operations and the minimum-necessary standard is accurate?

A
B
C
D
Test Your Knowledge

A laptop with unsecured Part 2 and HIPAA records of 600 clients is stolen. Which statement is correct under current federal rules?

A
B
C
D