4.8 Patient Confidentiality & Pharmacy Records
Key Takeaways
- HIPAA applies to pharmacies as covered entities; the minimum-necessary standard governs all uses and disclosures of protected health information (PHI).
- Pennsylvania law is stricter than HIPAA on certain categories (mental health, HIV/AIDS, substance use), and the stricter rule controls.
- 42 CFR Part 2 imposes separate, heightened consent requirements for substance use disorder treatment records.
- Patients have the right to access their pharmacy records under HIPAA and PA Board rules; pharmacies must provide copies within a required timeframe.
- Pharmacy records must be retained for at least 2 years from the date of the last entry; controlled-substance records follow the 2-year DEA retention rule.
Why Confidentiality and Records Are Tested
Pharmacy practice sits at the intersection of state pharmacy law, federal HIPAA, and federal substance-use confidentiality rules. The MPJE tests whether you can recognize which law controls when they overlap. The general rule: when state law is stricter than HIPAA, state law governs; when HIPAA is stricter, HIPAA governs. Pennsylvania is stricter on mental health, HIV/AIDS, and substance use records.
HIPAA in the Pharmacy
Under the Health Insurance Portability and Accountability Act of 1996 (HIPAA) and the HIPAA Privacy Rule (45 CFR Parts 160 and 164), a pharmacy is a covered entity because it transmits health information electronically in connection with covered transactions (claims, eligibility, prior authorization). The pharmacy's obligations include:
- Notice of Privacy Practices (NPP): provide to every patient on first encounter; post in a prominent location; retain for at least 6 years from the last effective date.
- Minimum necessary standard: when using or disclosing PHI for treatment, payment, or health-care operations (TPO), limit the disclosure to the minimum amount necessary. Treatment disclosures (e.g., to a prescriber) are exempt from minimum-necessary.
- Authorization: a signed, HIPAA-compliant authorization is required for disclosures not permitted under TPO (e.g., marketing, most disclosures to employers, disclosures to family not involved in care).
- Business associate agreements (BAAs): required with vendors that create, receive, maintain, or transmit PHI on the pharmacy's behalf (e.g., software vendors, billing services, courier services handling PHI).
- Patient rights: access, amendment, accounting of disclosures, restriction requests, confidential communications.
Pennsylvania Confidentiality Rules
PA law supplements HIPAA in three sensitive categories where state law is stricter:
- Mental health records (50 P.S. § 7111 et seq.) — release requires specific written consent identifying the recipient and purpose; broad "release all records" authorizations are insufficient.
- HIV/AIDS-related information (35 P.S. § 7605 et seq.) — requires a specific authorization; general medical authorization is not enough.
- Drug and alcohol treatment records — governed by both PA confidentiality law and the federal 42 CFR Part 2 (see below).
A pharmacy that releases HIV or mental-health information under a generic HIPAA authorization without the disease-specific consent violates both HIPAA and PA law.
42 CFR Part 2 — Substance Use Disorder Records
42 CFR Part 2 (Confidentiality of Substance Use Disorder Patient Records) applies to any federally assisted program that holds itself out as providing substance use disorder (SUD) diagnosis, treatment, or referral. Key features tested on the MPJE:
- Written, specific consent required for any disclosure, even for TPO purposes, with limited exceptions (medical emergency, internal program operations, audits/evaluations, research, court order).
- Prohibition on re-disclosure: a recipient of Part 2 records may not re-disclose without a new consent, unless an exception applies.
- Medical emergency exception permits disclosure without consent to treat a life-threatening emergency; the program must document the disclosure.
- Law enforcement disclosures require a court order; a subpoena alone is not sufficient.
A pharmacy that fills a buprenorphine or methadone prescription from an OTP (opioid treatment program) may be subject to Part 2 for those records. Part 2 was narrowed in 2024 (Final Rule effective February 12, 2024) but the core consent requirement remains.
Patient Access to Records — 49 Pa. Code § 27.18
Under HIPAA (45 CFR 164.524) and PA Board rules (49 Pa. Code § 27.18), a patient has the right to inspect and obtain a copy of their pharmacy records. Requirements:
- Patient request must be in writing; oral requests may be accepted at the pharmacy's option but written is safer.
- Pharmacy must act on the request within 30 days under HIPAA (a single 30-day extension is permitted with written justification).
- Reasonable, cost-based fee may be charged for copies (cannot include retrieval or search labor overhead).
- A patient may request an electronic copy if the pharmacy maintains electronic records; the pharmacy must provide it in the form requested if readily producible.
- A pharmacy may deny access only on narrow grounds (e.g., psychotherapy notes, information compiled for litigation) and must provide a written denial with review rights.
Authorized Representative
A pharmacy may release records to an authorized representative (personal representative) of the patient — a parent of an unemancipated minor, a guardian, a health-care proxy, or an executor of a deceased patient's estate. The pharmacy must verify the representative's authority (guardianship papers, HIPAA authorization, or POA) before release.
Record Retention
PA pharmacies must retain records per Board rules and federal law:
| Record Type | Retention Period | Authority |
|---|---|---|
| Prescription / dispensing records (non-CS) | At least 2 years from last entry | 49 Pa. Code Ch. 27 |
| Controlled substance dispensing records | At least 2 years | 21 CFR 1304.04; 49 Pa. Code Ch. 27 |
| DEA Forms 222, 41, 106 | At least 2 years | 21 CFR 1317 |
| Compounding records | At least 2 years | 49 Pa. Code §§ 27.601–27.606 |
| Immunization administration records | Per Board rule (typically 2+ years) | 49 Pa. Code § 27.404 |
| HIPAA policies, NPP, authorizations | At least 6 years | 45 CFR 164.530(j) |
| Patient counseling offer / refusal documentation | At least 2 years | 49 Pa. Code Ch. 27 |
A longer retention may be set by pharmacy policy; the table reflects the minimum.
Release of Records to Third Parties
Pharmacies routinely receive requests for records from prescribers, other pharmacies (transfers), payers, attorneys, and law enforcement. Each has a different standard:
- Prescriber or treating provider: permitted under HIPAA for treatment without authorization; minimum-necessary does not apply to treatment disclosures.
- Another pharmacy for refill transfer (non-CS): permitted with patient verbal or written authorization; documented in the dispensing record.
- Payer for adjudication: permitted under TPO without authorization; minimum-necessary applies.
- Patient's attorney or third party: requires a HIPAA-compliant written authorization signed by the patient.
- Law enforcement: requires a court order, subpoena, or grand jury subpoena; HIPAA permits but PA may require specific consent. An ordinary subpoena alone may not be sufficient; the pharmacy should consult counsel and may notify the patient.
- Subpoena duces tecum: pharmacy may respond if the patient has been notified and has had an opportunity to object, or if a court has entered a protective order.
Subpoenas and Court Orders — Trap
A common MPJE trap: a detective arrives with a subpoena and asks for a patient's prescription history. The correct response is not to immediately hand over the records. The pharmacy should:
- Verify the subpoena is valid (signed by a court or attorney of record).
- Determine whether the patient has been notified and given an opportunity to object.
- Consult the pharmacist-in-charge and, if needed, pharmacy counsel.
- Disclose only the minimum-necessary PHI responsive to the subpoena.
- Document the disclosure in the accounting-of-disclosures log.
For 42 CFR Part 2 records (SUD), a subpoena alone is never sufficient — a court order is required.
Documentation and the Accounting of Disclosures
Under HIPAA, pharmacies must maintain an accounting of disclosures of PHI made for purposes other than TPO, healthcare operations, and patient authorization. The accounting includes the date, recipient, description of PHI, and purpose. Patients may request an accounting for the prior 6 years. Disclosures made under a patient authorization, for treatment, for payment, or for health-care operations are not required to be included.
Key Takeaways for the Exam
- HIPAA covers pharmacies as covered entities; minimum-necessary applies except for treatment disclosures.
- PA is stricter on mental health, HIV, and SUD records — follow the stricter rule.
- 42 CFR Part 2 requires specific written consent and bars re-disclosure; subpoenas alone are insufficient.
- Patient access is required within 30 days; reasonable cost-based fees allowed.
- Subpoenas require careful handling — verify validity, notify patient, disclose minimum necessary, and document.
- Records retention: 2 years minimum for most pharmacy records; 6 years for HIPAA policy/NPP/authorizations.
A prescriber's office calls a Pennsylvania pharmacy to verify that a patient is taking buprenorphine for opioid use disorder as part of a coordinated care plan. The pharmacy has the prescription on file. What is the correct response under 42 CFR Part 2 and HIPAA?
A Pennsylvania patient submits a written request for a complete copy of her pharmacy records, including all prescriptions for the past 3 years. Under HIPAA and 49 Pa. Code § 27.18, what must the pharmacy do?
A detective arrives at a Pennsylvania pharmacy with a subpoena duces tecum requesting a patient's controlled-substance prescription history for the past 2 years. What is the most appropriate first response?