7.4 Patient Confidentiality & Pharmacy Records
Key Takeaways
- Patient medication profiles must remain retrievable for five years from the most recent entry under 8 NYCRR Part 63 — the same retention period underlying counseling documentation.
- Entering a patient's data into a shared prescription database requires the patient's documented express written consent; if the patient refuses, the originating pharmacy must place a firewall around that patient's data.
- Public Health Law §18's patient record access procedure applies to DOH-licensed facilities (hospitals, home care, hospices, HMOs); community pharmacies are NYSED-licensed under Education Law Article 137, so a patient's right to access pharmacy records runs through HIPAA's right of access instead.
- New York's shared-database consent requirement is stricter than HIPAA's baseline treatment-sharing allowance; where NY law is stricter, the New York standard governs pharmacy practice.
- This section builds on, but does not repeat, the federal HIPAA chapter — it focuses on NY-specific recordkeeping, consent, and access rules layered on top of HIPAA.
Scope of This Section
The federal HIPAA chapter of this study guide covers the baseline federal privacy framework — the Privacy Rule, covered entities, minimum necessary, and permitted disclosures. This section does not repeat that material. Instead, it focuses on what makes New York pharmacy confidentiality distinct: Part 63 recordkeeping obligations, shared-database consent rules, and the jurisdictional trap around who can access a patient's pharmacy record.
Record Retention Under Part 63
New York pharmacy regulation (8 NYCRR Part 63, under Education Law Article 137) requires that a patient's medication profile be maintained in a retrievable form for five years following the date of the most recent entry. This single retention period governs the same record used for counseling documentation (see §7.1) and underlies the pharmacy's ability to answer a Board of Pharmacy inspection request, respond to a malpractice inquiry, or reconstruct a medication history years after the original dispensing.
- The clock resets with each new entry — a profile is not aged out five years from its creation, but five years from its most recent update.
- Retention obligations survive even if the patient stops using that pharmacy or the prescription is never refilled again.
- Failure to produce a retrievable record within the five-year window is a Part 63 violation independent of any privacy breach.
Shared Database Consent and the Firewall Requirement
New York pharmacies increasingly participate in shared prescription/medical information databases — health information exchanges that let multiple pharmacies or providers view a patient's medication history. New York imposes a consent-based structure that is stricter than the federal HIPAA floor:
- A pharmacist must obtain the patient's documented express written consent before that patient's information is entered into, or accessed through, a shared database.
- A patient may refuse to have information entered into the shared database.
- If the patient refuses, the originating pharmacy (the one that first filled the prescription) must place a firewall around that patient's data — a technical/administrative barrier that prevents other locations or participants in the shared system from accessing that specific patient's information without proper authorization.
This is a meaningfully higher bar than HIPAA's baseline, which generally permits sharing for treatment purposes without patient authorization. Where New York law is more protective than HIPAA, the more protective state standard controls for the New York-licensed pharmacist — HIPAA sets a privacy floor, not a ceiling, and states are free to require more.
Patient Access to Their Own Pharmacy Records — the Jurisdictional Trap
The MPJE likes to test a subtle jurisdictional distinction: Public Health Law (PHL) §18, New York's general Access to Patient Information statute, gives patients a right to inspect and copy their records — but §18 applies to records maintained by health care facilities licensed by the Department of Health (DOH), such as hospitals, home care agencies, hospices, and HMOs.
Community pharmacies are not DOH-licensed facilities. They are licensed and regulated by the New York State Education Department (NYSED) under Education Law Article 137 and Part 63 — the same framework that governs counseling and record retention. PHL §18's specific 10-day inspection/copying procedure, written for DOH-licensed facilities, does not neatly extend to a community pharmacy's dispensing records.
That does not leave patients without a right of access. A New York pharmacist must still honor:
- The patient's HIPAA right of access (45 CFR §164.524) to their own protected health information as a HIPAA covered entity, which is the operative access mechanism for most community pharmacies.
- The general professional obligation under Part 63 to maintain accurate, retrievable records and provide the patient (or authorized representative) their own medication history on a reasonable request.
For MPJE purposes: if a question asks which statute gives a patient the right to inspect their hospital chart, PHL §18 is correct. If the question is about a patient's right to their community pharmacy dispensing/medication profile record, the operative right of access runs through HIPAA, not PHL §18, because the pharmacy is an NYSED-licensed, not DOH-licensed, entity.
How NY Confidentiality Rules and HIPAA Interact
| Question | Governing framework |
|---|---|
| Baseline privacy/security requirements for a pharmacy as a covered entity | Federal HIPAA Privacy and Security Rules |
| Consent before entering a patient's data into a shared database | New York-specific — express written consent plus firewall on refusal |
| How long the patient medication profile must be retrievable | 8 NYCRR Part 63 — five years from the most recent entry |
| Right to inspect/copy a hospital or DOH-licensed facility's record | PHL §18 |
| Right to inspect/copy a community pharmacy's own dispensing record | HIPAA right of access (45 CFR §164.524), operating alongside Part 63 recordkeeping duties |
The exam-writer's shorthand: HIPAA is the floor everywhere; New York adds a taller wall in specific places — shared-database consent and the five-year Part 63 retention period being the two most testable examples. When NY law is silent or matches HIPAA, HIPAA principles apply by default; when NY law is stricter, as with shared-database consent, the New York rule governs pharmacy practice.
Scenario Walkthrough
A patient transferring care asks her new pharmacy to pull her medication history from a regional health information exchange. The new pharmacy cannot simply query the shared database — it must first confirm the patient (or the originating pharmacy on the patient's behalf) provided express written consent to share that data; absent consent, a firewall should be blocking exactly this kind of cross-pharmacy access. Separately, if the same patient calls her pharmacy asking for a copy of everything she has ever filled there, the pharmacist should treat this as a HIPAA right-of-access request layered on the pharmacy's Part 63 duty to keep a retrievable five-year record — not as a PHL §18 request, since a retail pharmacy is not a DOH-licensed facility.
A New York community pharmacy is asked by the Board of Pharmacy to produce a patient's medication profile entry made 4 years and 9 months ago. Under Part 63, is the pharmacy required to produce it?
A patient tells her pharmacist she does not want her prescription history shared through a regional health information exchange. What must the originating pharmacy do?
A patient asks her retail pharmacy to let her inspect and copy her dispensing records, citing her rights under Public Health Law §18. Which statement is most accurate?
Where New York's shared-database consent rule is stricter than HIPAA's general treatment-sharing allowance, which standard governs a New York pharmacist's conduct?