9.3 HIPAA Privacy, Security & Protected Health Information

Key Takeaways

  • Protected Health Information (PHI) includes all individually identifiable health data held or transmitted by a covered entity relating to physical/mental health, healthcare provision, or payment.
  • Covered entities may use and disclose PHI without patient authorization for Treatment, Payment, and Health Care Operations (TPO); all other non-exempt disclosures require signed written authorization.
  • Pharmacies must provide the Notice of Privacy Practices (NPP) on the first date of service, make a good faith effort to obtain written acknowledgment of receipt, and retain NPP records for six (6) years.
  • The Minimum Necessary standard requires limiting PHI uses and disclosures to the minimum required, but strictly does NOT apply to treatment disclosures between healthcare providers, patient requests, or required-by-law disclosures.
  • Under the Breach Notification Rule, covered entities must notify affected individuals within 60 days; breaches affecting 500+ individuals mandate immediate/60-day notification to HHS and prominent media outlets.
Last updated: August 2026

9.3 HIPAA Privacy, Security & Protected Health Information

The Health Insurance Portability and Accountability Act of 1996 (HIPAA), codified in 45 CFR Parts 160 and 164, established nationwide standards to protect sensitive patient health information from unauthorized disclosure. Enforced by the Department of Health and Human Services (HHS) Office for Civil Rights (OCR) and the Department of Justice (DOJ), HIPAA compliance is a cornerstone of professional pharmacy practice and a heavily tested domain on the MPJE.


1. Covered Entities, Business Associates & Protected Health Information (PHI)

To apply HIPAA regulations correctly, candidates must master the fundamental definitions governing regulatory scope:

┌─────────────────────────────────────────────────────────────────────────────┐
│                     HIPAA JURISDICTIONAL ARCHITECTURE                       │
├─────────────────────────────────────────────────────────────────────────────┤
│ COVERED ENTITIES (CE):                                                      │
│ • Pharmacies (retail, institutional, mail-order, compounding)               │
│ • Healthcare Providers (physicians, dentists, APRNs, PAs, hospitals)        │
│ • Health Plans (health insurance issuers, HMOs, Medicare/Medicaid programs) │
│ • Healthcare Clearinghouses (billing billing intermediaries, claim routers) │
│                                                                             │
│ BUSINESS ASSOCIATES (BA):                                                   │
│ • Third-party vendors performing services involving PHI on behalf of a CE   │
│ • Examples: Pharmacy software vendors, PBM claims processors, document      │
│   shredding services, cloud hosting platforms, collection agencies          │
│ • MUST execute a written Business Associate Agreement (BAA) binding the    │
│   BA to direct statutory HIPAA liability and security standards             │
│                                                                             │
│ PROTECTED HEALTH INFORMATION (PHI):                                         │
│ • Individually identifiable health information transmitted or maintained in │
│   any form (electronic, paper, or oral) created or received by a CE/BA     │
│ • Relates to past, present, or future physical/mental health condition,     │
│   the provision of healthcare, or the payment for healthcare services      │
└─────────────────────────────────────────────────────────────────────────────┘

The 18 HIPAA Identifiers

Health information is deemed "individually identifiable" if it contains any of the 18 statutory HIPAA identifiers, including: 1) Names; 2) Geographic subdivisions smaller than a state (street address, city, county, ZIP code); 3) All dates (DOB, admission, discharge, death, exact age if $\ge 90$); 4) Telephone numbers; 5) Fax numbers; 6) Email addresses; 7) Social Security numbers; 8) Medical record numbers (MRNs); 9) Health plan beneficiary numbers; 10) Account numbers; 11) Certificate/license numbers; 12) Vehicle identifiers and serial numbers (VINs, license plates); 13) Device identifiers and serial numbers; 14) Web URLs; 15) IP addresses; 16) Biometric identifiers (fingerprints, voiceprints); 17) Full-face photographic images; 18) Any other unique identifying number, characteristic, or code.

De-Identification Standards

Information is exempt from HIPAA restrictions only if it is de-identified via: (1) Safe Harbor Method (complete removal of all 18 identifiers with no actual knowledge of re-identification capability), or (2) Expert Statistical Determination (formal mathematical certification of very small risk of re-identification).

Loading diagram...
HIPAA PHI Disclosure & Authorization Decision Tree

2. Notice of Privacy Practices (NPP) & Good Faith Acknowledgment

Under 45 CFR § 164.520, covered pharmacies must develop and distribute a comprehensive Notice of Privacy Practices (NPP) detailing how PHI is used, disclosed, and protected, as well as outlining individual patient rights.

Core NPP Operational Requirements

  1. First Date of Service: The pharmacy must provide the NPP to the patient no later than the date of the first service delivery (in-person dispensing or electronic transmission).
  2. Good Faith Effort for Acknowledgment: The pharmacy must make a good faith effort to obtain a signed, written acknowledgment from the patient confirming receipt of the NPP.
  3. Patient Refusal to Sign: If the patient refuses or is unable to sign the acknowledgment (e.g., emergency situation, acute distress, active refusal), the pharmacy must document the good faith effort and the specific reason why acknowledgment was not obtained. A patient's refusal to sign the NPP acknowledgment does NOT prevent the pharmacy from dispensing prescriptions or providing care.
  4. Physical & Digital Posting: The pharmacy must prominently display the complete NPP in a clear and prominent location within the physical pharmacy where patients can readily read it, and post the NPP prominently on the pharmacy's public website.
  5. Record Retention: All written acknowledgments, documented good faith efforts, and copies of historical NPP revisions must be retained for six (6) years from the date created under 45 CFR § 164.530(j).

3. Permitted vs. Mandatory Disclosures & The TPO Framework

HIPAA categorizes disclosures into three distinct regulatory tiers: Permitted without authorization, Mandatory, and Prohibited without authorization.

Permitted Disclosures: Treatment, Payment & Operations (TPO)

Under 45 CFR § 164.506, a covered entity may use or disclose PHI without patient consent or authorization for:

  • Treatment: The provision, coordination, or management of healthcare services. Examples include: a pharmacist consulting with a prescriber about dosage adjustments, discussing drug interactions with another treating specialist, sharing records with a hospital upon transfer, or calling a patient regarding refills.
  • Payment: Activities undertaken to obtain reimbursement for healthcare services. Examples include: submitting electronic claims to PBMs or commercial insurance plans, adjudicating billing disputes, verifying insurance eligibility, and transmitting accounts to collection agencies.
  • Health Care Operations (HCO): Administrative, financial, legal, and quality improvement activities necessary to run a covered entity. Examples include: conducting internal quality assurance and medication error audits, training pharmacy students/interns, undergoing Board of Pharmacy or accreditation inspections, and legal defense consultations.

Mandatory Disclosures (Must Disclose)

A covered pharmacy is legally required to disclose PHI in only two specific circumstances:

  1. To the Individual Patient: When an individual (or their personal representative) requests access to inspect or obtain a copy of their own PHI.
  2. To the Secretary of HHS / OCR: When requested during a compliance review, complaint investigation, or enforcement action.

Disclosures Requiring Explicit Written Authorization

Specific uses of PHI require a signed, formal HIPAA Authorization containing an expiration date and explicit purpose. Crucially, authorizations are required for:

  • Marketing Communications: Using PHI to encourage the purchase or use of a third-party commercial product or service (except face-to-face communications or refill reminders where remuneration received is reasonably related to the pharmacy's cost).
  • Sale of PHI: Any disclosure where the covered entity receives direct or indirect financial remuneration in exchange for PHI.
  • Employment Determinations & Pre-employment Screenings.

4. The Minimum Necessary Standard & Key Statutory Exemptions

Under 45 CFR § 164.502(b), covered entities and business associates must make reasonable efforts to use, disclose, or request only the minimum amount of Protected Health Information necessary to accomplish the intended clinical or administrative purpose.

┌─────────────────────────────────────────────────────────────────────────────┐
│               MINIMUM NECESSARY: THE FIVE STATUTORY EXEMPTIONS              │
├─────────────────────────────────────────────────────────────────────────────┤
│ The Minimum Necessary rule applies to Payment, Healthcare Operations, and   │
│ third-party non-treatment disclosures. However, it STRICTLY DOES NOT APPLY  │
│ to the following five situations:                                           │
│                                                                             │
│ 1. Treatment Disclosures: Disclosures to or requests by healthcare         │
│    providers for treatment purposes (e.g., sending full clinical profile).  │
│                                                                             │
│ 2. Patient Requests: Disclosures made directly to the individual patient    │
│    requesting their own medical records.                                    │
│                                                                             │
│ 3. Explicit Authorizations: Disclosures made pursuant to a signed patient   │
│    HIPAA authorization.                                                     │
│                                                                             │
│ 4. Required by Law: Disclosures mandated by statute (e.g., KASPER reporting,│
│    mandatory child/elder abuse reports, DEA compliance audits).             │
│                                                                             │
│ 5. HHS Compliance Investigations: Disclosures to HHS/OCR investigators.     │
└─────────────────────────────────────────────────────────────────────────────┘

Incidental Disclosures & Reasonable Safeguards

  • HIPAA recognizes that accidental overhearing or viewing of PHI may occur in busy healthcare environments.
  • An incidental disclosure (e.g., a customer in line overhearing a pharmacist speak quietly at the counseling window) is not a HIPAA violation, provided the pharmacy implemented reasonable physical, technical, and administrative safeguards (e.g., speaking in lowered voices, maintaining privacy lines away from the counter, positioning computer screens away from customer view, and locking physical records).

5. Individual Patient Rights under HIPAA

HIPAA grants patients several enforceable legal rights regarding their health information:

  1. Right to Inspect and Copy PHI (45 CFR § 164.524): Patients have the right to inspect and obtain a paper or electronic copy of their PHI. The pharmacy must respond within thirty (30) calendar days. A single 30-day extension is permitted if the pharmacy provides a written explanation to the patient. The pharmacy may charge a reasonable, cost-based fee covering labor, supplies, and postage.
  2. Right to Request Amendments (45 CFR § 164.526): Patients may request corrections to inaccurate records. The pharmacy must act within sixty (60) days. The pharmacy may deny the request if the record is accurate, complete, or not created by the pharmacy.
  3. Right to an Accounting of Disclosures (45 CFR § 164.528): Patients may request a log of non-routine disclosures made during the six (6) years prior to the request. Disclosures for TPO (Treatment, Payment, Operations), disclosures to the patient, and disclosures pursuant to written authorizations are exempt from the accounting log.
  4. Right to Request Restrictions & Confidential Communications (45 CFR § 164.522): Patients may request confidential communications (e.g., call cell phone only). While pharmacies generally need not agree to disclosure restrictions, a pharmacy MUST agree to restrict disclosure to a health plan if the disclosure is for payment or operations, and the patient has paid out-of-pocket in full (cash) for the healthcare item or service.

6. HIPAA Breach Notification Rule & Penalty Framework

A breach is defined under 45 CFR § 164.402 as the unauthorized acquisition, access, use, or disclosure of unencrypted PHI that compromises the security or privacy of the data. An impermissible disclosure is legally presumed to be a breach unless the covered entity demonstrates through a formal 4-factor risk assessment that there is a low probability the data was compromised:

  1. The nature and extent of the PHI involved (types of identifiers, clinical sensitivity);
  2. The unauthorized person who used the PHI or to whom the disclosure was made;
  3. Whether the PHI was actually acquired or viewed; and
  4. The extent to which the risk has been mitigated.

Comprehensive Breach Notification Timelines & Civil / Criminal Penalty Tiers

Compliance / Breach ParameterStatutory Requirement & TimelineGoverning Regulation / Enforcement Agency
Individual Patient NotificationMust notify affected individuals in writing by first-class mail (or secure email if consented) without unreasonable delay and within 60 calendar days of discovery.45 CFR § 164.404 / HHS OCR
Breaches Affecting $\ge 500$ IndividualsMust notify the Secretary of HHS without unreasonable delay (within 60 days of discovery) AND notify prominent media outlets (TV/newspapers) in the state/jurisdiction within 60 days.45 CFR §§ 164.406, 164.408 / HHS OCR
Breaches Affecting $< 500$ IndividualsMust log all minor breaches and submit an electronic report to the Secretary of HHS annually, within 60 calendar days after the end of the calendar year (by March 1).45 CFR § 164.408(c) / HHS OCR
Civil Penalty Tier 1 (No Knowledge)Did not know and with reasonable diligence would not have known. Penalty: $100 to $50,000+ per violation (statutory annual caps apply).45 CFR Part 160 / HHS OCR
Civil Penalty Tier 2 (Reasonable Cause)Knew or through reasonable diligence would have known, but not willful neglect. Penalty: $1,000 to $50,000+ per violation.45 CFR Part 160 / HHS OCR
Civil Penalty Tier 3 (Willful Neglect - Corrected)Conscious, intentional failure or reckless indifference, corrected within 30 calendar days of discovery. Penalty: $10,000 to $50,000+ per violation.45 CFR Part 160 / HHS OCR
Civil Penalty Tier 4 (Willful Neglect - Uncorrected)Conscious, intentional failure or reckless indifference, NOT corrected within 30 days. Penalty: $50,000+ per violation up to annual statutory maximum (~$2,000,000+).45 CFR Part 160 / HHS OCR
Criminal Penalty Tier 1 (Knowing Disclosure)Knowingly obtaining or disclosing identifiable health info without authorization. Penalty: Up to $50,000 fine and up to 1 year imprisonment.42 U.S.C. § 1320d-6 / U.S. Dept. of Justice (DOJ)
Criminal Penalty Tier 2 (False Pretenses)Obtaining PHI under false pretenses (e.g., impersonating a physician or patient). Penalty: Up to $100,000 fine and up to 5 years imprisonment.42 U.S.C. § 1320d-6 / U.S. Dept. of Justice (DOJ)
Criminal Penalty Tier 3 (Commercial Gain / Malice)Obtaining or disclosing PHI for commercial advantage, personal financial gain, or malicious harm. Penalty: Up to $250,000 fine and up to 10 years imprisonment.42 U.S.C. § 1320d-6 / U.S. Dept. of Justice (DOJ)
Test Your Knowledge

A community pharmacy in Richmond suffers a ransomware cyberattack that exposes the unencrypted electronic prescription and medical records of 1,200 patients. Following discovery of the security incident, what are the pharmacy's mandatory legal obligations under the HIPAA Breach Notification Rule (45 CFR Parts 160 and 164)?

A
B
C
D
Test Your Knowledge

A patient presents a prescription for a 30-day supply of an expensive specialty medication at an independent pharmacy in Covington. The patient insists on paying cash (100% out-of-pocket) and signs a written request instructing the pharmacy NOT to bill their commercial health insurance or submit any claims data to their health plan. Under HIPAA Privacy regulations (45 CFR § 164.522), how must the pharmacy respond?

A
B
C
D
Test Your Knowledge

Under the HIPAA Privacy Rule (45 CFR § 164.502(b)), in which of the following scenarios does the 'Minimum Necessary' standard NOT apply?

A
B
C
D