2.1 HIPAA Privacy Rule & the Public Health Reporting Exception

Key Takeaways

  • Under 45 CFR § 164.512(b), covered entities may disclose Protected Health Information (PHI) to public health authorities without patient consent or authorization.

  • The HIPAA Privacy Rule defines 18 specific identifiers that transform health data into identifiable PHI under 45 CFR § 164.514.

  • Disclosures required by law are exempt from the minimum necessary standard, and for other public health disclosures a covered entity may reasonably rely on the public health authority's request as the minimum necessary (45 CFR § 164.502(b) and § 164.514(d)(3)(iii)).

  • Disclosures to state central cancer registries do not require a Business Associate Agreement (BAA) because central registries function as sovereign public health authorities.

  • A Business Associate Agreement is legally mandated when engaging external contract abstractors, independent cancer registry software vendors, or cloud hosts.

Last updated: September 2026

2.1 HIPAA Privacy Rule & the Public Health Reporting Exception

Cancer registration relies on the systematic collection of detailed personal, demographic, clinical, and pathological information from individuals diagnosed with neoplastic disease. Because cancer data abstracting involves extensive review of inpatient admissions, outpatient oncology visits, surgical operative notes, pathology reports, and radiation summaries, Oncology Data Specialists (ODS) operate at the direct intersection of patient privacy rights and public health law. Navigating this environment requires mastering the Health Insurance Portability and Accountability Act of 1996 (HIPAA) Privacy Rule, codified in Title 45 of the Code of Federal Regulations (CFR), Parts 160 and 164.


The HIPAA Privacy Rule: Statutory Architecture

Enacted by Congress in 1996 and implemented through federal regulations issued by the Department of Health and Human Services (HHS), the HIPAA Privacy Rule establishes national standards to protect individuals' medical records and other personal health information. The rule applies to Covered Entities, which include:

  1. Healthcare Providers: Any provider of medical or health services (e.g., hospitals, academic medical centers, ambulatory surgery centers, pathology laboratories, radiation clinics, and individual physicians) who transmits health information electronically in connection with standard transactions.
  2. Health Plans: Health insurance companies, health maintenance organizations (HMOs), Medicare, Medicaid, and employer-sponsored group health plans.
  3. Healthcare Clearinghouses: Entities that process nonstandard health information received from another entity into standard electronic data formats, or vice versa.

In addition to covered entities, HIPAA regulations directly govern Business Associates—external individuals or entities that perform functions or activities on behalf of, or provide services to, a covered entity involving the use or disclosure of protected health information.


Protected Health Information (PHI) & The 18 HIPAA Identifiers

Protected Health Information (PHI) is defined under 45 CFR § 160.103 as individually identifiable health information held or transmitted by a covered entity or its business associate, in any form or media, whether electronic, paper, or oral. It relates to the past, present, or future physical or mental health or condition of an individual, the provision of healthcare to an individual, or the past, present, or future payment for the provision of healthcare.

Under 45 CFR § 164.514(b)(2), health information is rendered non-identifiable only when all 18 HIPAA Identifiers pertaining to the individual, their relatives, employers, or household members are removed, provided the covered entity has no actual knowledge that the remaining information could identify the individual:

Identifier NumberHIPAA Identifier CategoryCancer Registry Operational Context
1NamesPatient first, middle, last, maiden, and alias names recorded in registry abstracts
2Geographic Subdivisions Smaller Than a StateStreet address, city, county, precinct, ZIP code, and equivalent geocodes (census tract, block group)
3All Dates Directly Related to an IndividualDate of birth, date of initial diagnosis, date of first contact, admission/discharge dates, dates of surgery, radiation, systemic therapy, and date of last contact/death (and all ages over 89)
4Telephone NumbersPrimary residential, cellular, and emergency contact numbers used for active follow-up
5Fax NumbersProvider and facility facsimile transmission numbers
6Electronic Mail AddressesPatient personal and work email addresses
7Social Security Numbers (SSN)Patient SSN used for deterministic record linkage and National Death Index (NDI) matching
8Medical Record Numbers (MRN)Facility-assigned unique patient identifiers within hospital electronic health records (EHR)
9Health Plan Beneficiary NumbersMedicare, Medicaid, or private commercial payer insurance policy numbers
10Account NumbersHospital billing and patient financial services encounter numbers
11Certificate / License NumbersDriver's license numbers or professional license numbers
12Vehicle Identifiers and Serial NumbersAutomobile license plate numbers and vehicle identification numbers (VINs)
13Device Identifiers and Serial NumbersMedical device serial numbers (e.g., implanted port serial numbers, pacemaker IDs)
14Web Universal Resource Locators (URLs)Patient or personal website addresses
15Internet Protocol (IP) Address NumbersNetwork IP addresses captured during patient portal access
16Biometric IdentifiersFingerprints, voiceprints, or retinal scans
17Full-Face Photographic ImagesClinical photographs, identification badge photos, or comparable images
18Any Other Unique Identifying Number, Characteristic or CodeAny unique number, characteristic or code, such as a registry accession number; only a re-identification code assigned under 45 CFR § 164.514(c) (not derived from patient information) may remain

For geographic data, the rule permits using the first three digits of a ZIP code if the geographic unit formed by combining all ZIP codes with the same three initial digits contains more than 20,000 individuals; otherwise, the first three digits must be combined into 000.


The Public Health Reporting Exception: 45 CFR § 164.512(b)

A common misunderstanding among healthcare staff and newly credentialed registrars is the belief that patient authorization or written consent is required before cancer data can be collected, abstracted, or transmitted to state authorities. Under federal law, this assumption is completely incorrect.

Congress and HHS recognized that requiring individual patient consent for public health tracking would paralyze epidemiology, obscure disease clusters, and prevent accurate population-level cancer surveillance. Consequently, 45 CFR § 164.512(b) establishes an explicit Public Health Exception to the Privacy Rule.

Core Provisions of 45 CFR § 164.512(b)

Under this statutory provision, covered entities are legally permitted to disclose PHI WITHOUT individual patient authorization, consent, or opportunity to agree or object, to:

"A public health authority that is authorized by law to collect or receive such information for the purpose of preventing or controlling disease, injury, or disability, including, but not limited to, the reporting of disease, injury, vital events such as birth or death, and the conduct of public health surveillance, public health investigations, and public health interventions..."

Legal Classification of State Central Cancer Registries

A Public Health Authority is defined under 45 CFR § 164.501 as an agency or authority of the United States, a State, a territory, a political subdivision of a State or territory, or an Indian tribe, or a person or entity acting under a grant of authority from or contract with such public agency, that is responsible for public health matters as part of its official mandate.

State central cancer registries established pursuant to state reporting statutes qualify unequivocally as public health authorities. Therefore, when a hospital cancer registry, pathology laboratory, or independent abstractor transmits cancer abstracts containing complete patient identifiers (names, SSNs, street addresses, dates of diagnosis) to the state central cancer registry, the transmission is fully authorized under federal law.


The Minimum Necessary Standard & Mandatory Disclosures: 45 CFR § 164.502(b)

The general standard under the HIPAA Privacy Rule is the Minimum Necessary Standard (45 CFR § 164.502(b)). This standard requires that when covered entities use or disclose PHI, or request PHI from another covered entity, they must make reasonable efforts to limit the information to the minimum amount necessary to accomplish the intended purpose.

The Critical Public Health Carve-Out

Many hospital privacy officers mistakenly attempt to redact or withhold names, full street addresses, or Social Security numbers from state cancer registry submissions, citing the Minimum Necessary Standard. However, federal regulations contain two critical exceptions that supersede this restriction:

  1. Disclosures Required by Law (45 CFR § 164.512(a)): The minimum necessary standard does not apply to disclosures required by state or federal statute.
  2. Disclosures to Public Health Authorities (45 CFR § 164.512(b)): Under 45 CFR § 164.514(d)(3)(iii)(A), a covered entity may reasonably rely on the representations of the public health authority regarding what information constitutes the minimum necessary for the public health purpose.

Because state cancer reporting statutes and administrative codes mandate the submission of the standardized North American Association of Central Cancer Registries (NAACCR) data item set—which explicitly requires patient names, Social Security numbers, dates, geocodes, and detailed diagnostic text—the covered entity is legally protected in disclosing the entire mandated data set without redaction.


Business Associate Agreements (BAAs) in Cancer Registry Operations

A Business Associate Agreement (BAA) is a binding legal contract required under 45 CFR § 164.502(e) and § 164.504(e) between a covered entity and a business associate. The BAA establishes the permitted and required uses and disclosures of PHI, requires the business associate to implement administrative, physical, and technical safeguards, mandates prompt breach reporting, and extends HIPAA statutory liability directly to the contractor.

Understanding when a BAA is legally required—and when it is legally prohibited or unnecessary—is a frequent test area on the ODS examination.

Operating Entity / RelationshipBAA Required?Legal Rationale & Statutory Basis
State Central Cancer RegistryNOState central registries are sovereign public health authorities exercising statutory oversight under 45 CFR § 164.512(b). They are not performing a service on behalf of the hospital; therefore, requiring a BAA is inappropriate and legally invalid.
Contract Abstracting CompanyYESAn outsourced abstracting firm or independent credentialed contractor hired by a hospital to abstract cases performs a registry function on behalf of the covered entity under 45 CFR § 160.103. A formal BAA is mandatory prior to granting system access.
Commercial Registry Software Vendor (Cloud / EHR Host)YESSoftware providers hosting electronic cancer registry databases or cloud servers store, maintain, and transmit ePHI on behalf of the facility. A BAA is federally mandated.
Offsite Data Storage & Document Shredding ServicesYESVendors providing physical archive storage, microfiche conversion, digital scanning, or secure destruction of paper oncology records handle PHI on behalf of the covered entity.
Treating Physicians & Consulting OncologistsNODisclosures between healthcare providers for the purpose of patient treatment (45 CFR § 164.506) do not require a BAA.
Commission on Cancer (CoC) / National Cancer Database (NCDB)YESNCDB submissions are quality-assessment disclosures made under the American College of Surgeons Business Associate/Data Use Agreement that STORE references for accredited programs; the agreement defines how the ACS may use the data.

Realistic Practice Scenarios & Exam Pitfalls

Scenario 1: The Patient Consent Refusal

A 58-year-old patient diagnosed with invasive ductal carcinoma of the breast signs a hospital admission document explicitly stating: "I revoke all permissions for my medical records, cancer diagnosis, or treatment records to be shared with any state, government, or external registry database." The hospital compliance officer directs the cancer registry supervisor to withhold the patient's abstract from the state central registry.

Legal Resolution: The compliance officer's instruction violates state mandatory reporting laws. Under 45 CFR § 164.512(b) and state public health statutes, cancer reporting is a non-consensual mandatory duty. An individual patient cannot "opt out" of statutory disease surveillance. The cancer registrar must complete the abstract and transmit the case to the state central registry. The facility faces statutory fines if it complies with the patient's request to withhold the report.

Scenario 2: The BAA Demand to the State Registry

A hospital legal counsel informs the cancer registry department that until the State Department of Health Central Cancer Registry executes the hospital's standardized 15-page Business Associate Agreement, no further electronic monthly batches of cancer abstracts may be uploaded.

Legal Resolution: Hospital legal counsel is incorrect. State central registries operate under sovereign public health authority. They do not work on behalf of the hospital and cannot sign a BAA. Demanding a BAA before releasing mandatory public health data obstructs statutory compliance and risks state regulatory penalties for failure to report within the mandated timeframe.

Exam Pitfall Checklist

  • Do NOT assume HIPAA restricts state cancer reporting: HIPAA was deliberately structured to facilitate, preserve, and protect public health reporting.
  • Do NOT confuse research with public health surveillance: Research involving PHI generally requires either patient authorization or a formal waiver of authorization from an Institutional Review Board (IRB) or Privacy Board under 45 CFR § 164.512(i). Mandatory state cancer registry reporting is public health surveillance under § 164.512(b), requiring neither IRB approval nor patient consent.
  • Do NOT apply Minimum Necessary to state data items: If the state cancer registry manual or NAACCR standard specifies an item (e.g., text justification, full birth dates, street addresses), the facility cannot withhold it under the guise of minimum necessary.
Loading diagram...
HIPAA PHI Disclosure Decision Pathway for Cancer Registry Operations
Test Your Knowledge

A newly admitted oncology patient presents an executed legal document to the hospital registration desk stating that they explicitly refuse permission for their clinical data to be disclosed to any government agency or public health registry. Under the HIPAA Privacy Rule (45 CFR § 164.512(b)), how must the hospital cancer registry handle this case?

A

The registry must abstract and report the cancer case to the state central cancer registry as mandated by law, because public health reporting does not require patient consent or authorization.

B

The registry must honor the patient's written refusal and place the record into a permanent non-reportable suspense queue.

C

The registry must redact all 18 HIPAA direct identifiers before transmitting the case data to the state central cancer registry.

D

The registry must submit a formal exemption petition to the state public health officer requesting permission to withhold the case.

Test Your Knowledge

A 400-bed hospital cancer registry experiences an unexpected staff shortage and contracts with an independent outsourced cancer abstracting company to process a 6-month backlog of analytic cases. Which administrative and legal instrument is strictly required under HIPAA before providing the contractor remote access to the electronic health record?

A

A formal public health delegation order signed by the state central registry director

B

An executed Business Associate Agreement (BAA) binding the contractor to HIPAA privacy and security safeguards

C

A Certificate of Confidentiality issued by the National Institutes of Health

D

An Institutional Review Board (IRB) expedited human subjects research protocol approval

Test Your Knowledge

A hospital compliance officer orders the cancer registry supervisor to delete patient names, street addresses, and Social Security numbers from all export files transmitted to the state central cancer registry, arguing that the HIPAA Minimum Necessary Standard (45 CFR § 164.502(b)) strictly prohibits disclosing identifying information. Why is the compliance officer's position legally flawed?

A

The Minimum Necessary Standard applies exclusively to billing transactions and does not apply to clinical medical records.

B

Covered entities are exempt from all HIPAA provisions if they maintain Commission on Cancer (CoC) accreditation.

C

State central cancer registries operate under federal law enforcement authority, which automatically suspends the Code of Federal Regulations.

D

Mandated public health disclosures under 45 CFR § 164.512(b) are exempt from the covered entity's minimum necessary determination, allowing full reliance on the public health authority's mandated data requirements.

Sections you finish are checked off in the contents.