2.4 HIPAA & Patient Privacy
Key Takeaways
- HIPAA covered entities are health plans, health care clearinghouses, and health care providers who transmit health information electronically; business associates are vendors handling PHI on their behalf.
- The Privacy Rule's minimum necessary standard limits uses and disclosures to the least PHI needed, but does not restrict disclosures for treatment, payment, or health care operations.
- Most uses and disclosures of PHI for non-TPO purposes require a valid patient authorization; treatment, payment, and health care operations may proceed without one.
- Patients have a right to access, inspect, and obtain copies of their PHI, and to receive a Notice of Privacy Practices describing how the entity uses their information.
- When Pennsylvania law is stricter than HIPAA for mental health, HIV, or substance use records, the stricter state or 42 CFR Part 2 rule controls.
HIPAA & Patient Privacy in Pharmacy Practice
The Health Insurance Portability and Accountability Act of 1996 (HIPAA) established the first federal privacy floor for health information. For pharmacists, the HIPAA Privacy Rule (45 CFR Parts 160 and 164) governs how protected health information (PHI) is used, disclosed, and safeguarded. PHI is individually identifiable health information held or transmitted by a covered entity in any form—electronic, paper, or oral. On the PA MPJE, HIPAA is tested alongside Pennsylvania's stricter state overlays, so you must know both layers and apply the stricter- standard rule.
Covered Entities and Business Associates
HIPAA applies directly to three categories of covered entities:
- Health plans — insurers, HMOs, Medicare, Medicaid, pharmacy benefit managers acting as payers.
- Health care clearinghouses — entities that convert nonstandard health information into standard transactions (e.g., billing processors).
- Health care providers who transmit health information electronically in connection with covered transactions — community, hospital, and mail-order pharmacies almost always meet this test because they submit electronic pharmacy claims.
A business associate (BA) is a person or entity that creates, receives, maintains, or transmits PHI on behalf of a covered entity to perform a function or service—claims processing, transcription, pharmacy reminder services, data analysis. Covered entities must execute a business associate agreement (BAA) that binds the BA to safeguard PHI and report breaches. Pharmacists should recognize that a courier or software vendor that merely handles PHI incidentally is not a BA, but a refill-reminder vendor transmitting PHI is.
Minimum Necessary Standard
The minimum necessary standard requires covered entities to limit uses, disclosures, and requests for PHI to the least amount needed to accomplish the intended purpose. This standard applies to most internal uses and external disclosures, but has explicit exceptions:
- Disclosures to or requests by a health care provider for treatment purposes.
- Uses or disclosures made under a patient authorization.
- Disclosures to the individual patient (access requests).
- Disclosures required by law (e.g., to HHS, public health authorities, law enforcement under valid process).
[!IMPORTANT] A pharmacist pulling a patient's full medication history to fill a new prescription is a treatment use—the minimum necessary standard does not apply. The same pharmacist disclosing that history to a marketing firm would need a signed authorization and would be limited to the minimum necessary.
Authorization vs. Treatment, Payment, and Health Care Operations (TPO)
HIPAA permits uses and disclosures for treatment, payment, and health care operations (TPO) without patient authorization:
- Treatment — filling a prescription, consulting a prescriber, transferring records to another pharmacy.
- Payment — submitting a claim to insurance, verifying eligibility, obtaining prior authorization.
- Health care operations — quality assurance, training, audits, customer service.
Any use beyond TPO—marketing, sale of PHI, most research, disclosures to a third party for the third party's own purposes—requires a valid authorization that includes a description of the information, the recipient, the purpose, an expiration date or event, and the patient's signature. Authorizations are revocable.
Notice of Privacy Practices and Patient Right to Access
A covered entity must provide a Notice of Privacy Practices (NPP) that describes its uses and disclosures of PHI, patient rights (access, amendment, accounting of disclosures, restriction requests, confidential communications), and the entity's legal duties. Pharmacies must make the NPP available at the site of service and post it online.
Patients have the right to access, inspect, and obtain a copy of their PHI in the designated record set (e.g., their medication profile, prescription records, billing records) in the form and format they request if practicable. Covered entities generally must act within 30 days of a written request (one 30-day extension for good cause). Pharmacists may not withhold records for nonpayment of dispensing fees—access is not conditioned on payment of debt.
Breaches and the Breach Notification Rule
A breach is an impermissible use or disclosure of unsecured PHI. The Breach Notification Rule requires covered entities to notify affected individuals within 60 days of discovery of a breach affecting 500 or more individuals, with concurrent notice to HHS and prominent media notice if the breach affects more than 500 residents of a state or jurisdiction. Breaches affecting fewer than 500 individuals require individual notice and an annual log submitted to HHS. The Security Rule (45 CFR Part 164, Subpart C) requires administrative, physical, and technical safeguards for electronic PHI (e-PHI).
Federal Floor vs. Pennsylvania-Stricter: A Side-by-Side Table
HIPAA sets a federal floor. Where Pennsylvania law is stricter, the state rule controls. The table below maps the most tested areas:
| Privacy Area | Federal HIPAA Standard | Pennsylvania-Stricter Overlay |
|---|---|---|
| Mental health records | Permits disclosure for TPO; state law may be stricter | PA mental health confidentiality (50 P.S. § 7111) restricts disclosure; often requires patient consent beyond HIPAA |
| HIV / AIDS records | Allows TPO use; recognizes state stricter rules | PA Confidentiality of HIV-Related Information Act (35 P.S. § 7601 et seq.) requires specific written consent for HIV-related info disclosure |
| Substance use disorder (SUD) treatment records | HIPAA covers most SUD records | 42 CFR Part 2 is stricter federal rule for federally assisted SUD programs; requires separate patient consent for disclosure, even for TPO |
| Minor's records | Defers to state consent law | PA allows minors to consent to certain services (e.g., SUD treatment, reproductive care); access follows the consenting party |
| Breach notification | 60 days to individuals; HHS notice | PA Breach of Personal Information Notification Act (73 P.S. § 2301 et seq.) may require notice for state-defined personal information breaches |
42 CFR Part 2 Trap
42 CFR Part 2 (Confidentiality of Substance Use Disorder Records) applies to federally assisted SUD treatment programs. It is stricter than HIPAA: a Part 2 program generally may not disclose patient identifying information for any purpose—including treatment, payment, or operations—without patient consent, except in narrowly defined medical emergencies or to qualified service organizations. A pharmacy operating as a Part 2 program (or receiving Part 2 records) must obtain a separate written consent that names the recipient and purpose, and the disclosure must be limited to what is necessary. When a Part 2 record is re-disclosed, the recipient must honor the same prohibition.
Exam Traps and Scenarios
- Insurance company requesting full medication history for a non-treatment audit — minimum necessary applies; the pharmacist should limit to records relevant to the audit.
- Family member asking about a patient's medications — unless the patient is incapacitated or has agreed, disclosure is not permitted under TPO; apply professional judgment and minimum necessary.
- Subpoena without court order — HIPAA permits disclosure under certain conditions; notice to the patient may be required; when in doubt, consult counsel.
- Patient requests their own records but owes a balance — access cannot be denied for nonpayment, though a reasonable cost-based fee for copies is allowed.
- Disclosing HIV status to another provider for continuity of care — PA's HIV Act permits disclosure for treatment on a need-to-know basis; document the purpose.
A community pharmacy transmits electronic prescription claims to a third-party payer. Under HIPAA, which of the following best describes the pharmacy's status?
Which disclosure by a pharmacist does NOT require a patient authorization under the HIPAA Privacy Rule?
A patient who is overdue on her pharmacy account requests a copy of her complete medication profile. Under HIPAA, how must the pharmacy respond?