3.1 HIPAA & Patient Privacy

Key Takeaways

  • A pharmacy that submits electronic prescription claims to a payer is a HIPAA covered entity because it is a health care provider that transmits health information in connection with a covered transaction.
  • The HIPAA minimum necessary standard does not apply to treatment disclosures between providers, patient-authorized disclosures, disclosures to the patient, or disclosures required by law.
  • Covered entities must notify affected individuals within 60 days of discovering a breach, notify HHS within 60 days if 500 or more individuals are affected, and notify media if a breach affects more than 500 residents of a state.
  • Patients have a right to access and copy their PHI generally within 30 days of a written request (one 30-day extension allowed), and access cannot be conditioned on payment of an outstanding balance.
  • New York's Mental Hygiene Law Section 33.13 imposes confidentiality protections on mental health clinical records that can be stricter than HIPAA's TPO disclosure permissions.
Last updated: July 2026

HIPAA & Patient Privacy in Pharmacy Practice

The Health Insurance Portability and Accountability Act of 1996 (HIPAA) created the first federal privacy floor for health information. The HIPAA Privacy Rule (45 CFR Parts 160 and 164) governs how protected health information (PHI) — individually identifiable health information held or transmitted in any form (electronic, paper, or oral) — may be used and disclosed by pharmacies and other covered health care entities. Because pharmacy licensing exams test federal law as a baseline before layering on state-specific rules, you must know HIPAA's core mechanics cold before adding New York-specific overlays in later chapters.

Covered Entities and Business Associates

HIPAA applies directly to three categories of covered entities:

  • Health plans — insurers, HMOs, Medicare, Medicaid, and pharmacy benefit managers acting as payers.
  • Health care clearinghouses — entities that convert nonstandard health data into standard transactions.
  • Health care providers who transmit health information electronically in connection with a covered transaction. A retail, hospital, or mail-order pharmacy that submits electronic claims to a third-party payer meets this test and is almost always a covered entity.

A business associate (BA) creates, receives, maintains, or transmits PHI on behalf of a covered entity to perform a function such as claims processing, data analytics, or refill-reminder services. Covered entities must execute a business associate agreement (BAA) obligating the BA to safeguard PHI and report breaches. A courier who only incidentally handles PHI is not a BA; a software vendor that processes patient refill data on the pharmacy's behalf is.

The Minimum Necessary Standard

The minimum necessary standard requires a covered entity to make reasonable efforts to limit uses, disclosures, and requests for PHI to the least amount needed to accomplish the intended purpose. Under HHS guidance, this standard has explicit carve-outs:

SituationMinimum Necessary Applies?
Disclosure to or request by a health care provider for treatmentNo — exempt
Use or disclosure authorized by the patientNo — exempt
Disclosure to the patient about their own recordNo — exempt
Disclosure required by law (e.g., to HHS for a compliance investigation)No — exempt
Internal use for billing, quality assurance, or general operationsYes — must apply minimum necessary
Request from a health plan auditor for records unrelated to a specific claimYes — must apply minimum necessary

[!IMPORTANT] A pharmacist reviewing a patient's complete medication history to check for interactions before dispensing is a treatment use — minimum necessary does not limit it. The same pharmacist pulling records for an insurer's non-claim-specific audit must apply minimum necessary and disclose only what the audit requires.

Treatment, Payment, and Health Care Operations (TPO)

Under 45 CFR 164.506, HIPAA permits a covered entity to use and disclose PHI for treatment, payment, and health care operations (TPO) without a signed patient authorization:

  • Treatment — providing, coordinating, or managing care; consulting another provider; transferring a prescription to another pharmacy.
  • Payment — determining eligibility, adjudicating claims, billing and collections, utilization review, and disclosures to consumer reporting agencies limited to specified identifying and payment information.
  • Health care operations — quality assessment, competence review, training, accreditation, underwriting-related activities, and fraud and abuse detection.

Any use beyond TPO — marketing, sale of PHI, most research — requires a valid authorization naming the information, the recipient, the purpose, and an expiration date or event, signed by the patient. Authorizations are revocable at any time.

Notice of Privacy Practices and the Right of Access

Covered entities must provide a Notice of Privacy Practices (NPP) describing how PHI is used and disclosed and summarizing patient rights: access, amendment, an accounting of disclosures, and requests to restrict or use confidential communications. Patients have the right to access, inspect, and obtain a copy of PHI in the designated record set — including the pharmacy's medication profile — generally within 30 days of a written request, with one permissible 30-day extension for good cause. A covered entity may charge a reasonable, cost-based copying fee but cannot condition access on payment of an outstanding balance.

The Security Rule and Breach Notification

The Security Rule (45 CFR Part 164, Subpart C) requires administrative, physical, and technical safeguards for electronic PHI (e-PHI) — access controls, audit logs, encryption, and workforce training. The Breach Notification Rule (45 CFR §§ 164.400–414) defines a breach as an impermissible use or disclosure of unsecured PHI that compromises its security or privacy, subject to three narrow exceptions (good-faith unintentional workforce access, inadvertent disclosure between authorized persons at the same entity, and disclosures where the recipient could not reasonably have retained the information).

Following a breach, covered entities must notify:

  • Affected individuals — without unreasonable delay, no later than 60 days after discovery.
  • HHS (the Secretary) — within 60 days if the breach affects 500 or more individuals; breaches under 500 may be logged and reported annually, no later than 60 days after the end of the calendar year.
  • Prominent media outlets — if the breach affects more than 500 residents of a state or jurisdiction.

A business associate that experiences a breach must notify the covered entity without unreasonable delay and no later than 60 days after discovery.

New York Overlay: Mental Hygiene Law

HIPAA sets a federal floor; states may impose stricter protections. New York's Mental Hygiene Law Section 33.13 makes clinical records concerning mental health treatment confidential and generally restricts disclosure beyond what HIPAA alone would permit for TPO. Where a pharmacy handles records tied to a mental health facility or program subject to Section 33.13, the pharmacist must apply the stricter New York standard, not just the HIPAA floor — a recurring MPJE theme covered fully alongside New York's other confidentiality statutes in a later chapter.

Exam Traps

  • A subpoena alone (without a court order) does not automatically authorize disclosure — additional safeguards or patient notice may be required.
  • A family member asking about a patient's prescriptions is not a treatment disclosure unless the patient has consented or is incapacitated.
  • Access requests cannot be denied for an unpaid balance, though a reasonable copying fee is allowed.
  • A request that looks routine on its face still requires verifying the requester's authority before disclosure.
Test Your Knowledge

A mail-order pharmacy licensed in New York submits electronic prescription claims to insurers for reimbursement. Under HIPAA, what is the pharmacy's status?

A
B
C
D
Test Your Knowledge

A health plan requests a patient's complete ten-year medication history to investigate a single disputed claim for one prescription. Under the HIPAA minimum necessary standard, how should the pharmacy respond?

A
B
C
D
Test Your Knowledge

A pharmacy chain discovers a breach of unsecured PHI affecting 750 patients, all residents of New York State. Which notification obligations are triggered?

A
B
C
D
Test Your Knowledge

A New York pharmacy fills prescriptions tied to a hospital-based mental health clinic subject to Mental Hygiene Law Section 33.13. An outside party requests the patient's dispensing records, citing HIPAA's health care operations exception. What should the pharmacist do?

A
B
C
D