5.3 Confidentiality, HIPAA & Protected Health Information

Key Takeaways

  • Protected Health Information (PHI) encompasses individually identifiable health information in any form (electronic, paper, or oral) held by covered entities, including pharmacies.

  • Under HIPAA (45 CFR § 164.506), pharmacies may disclose PHI without patient authorization for Treatment, Payment, and Health Care Operations (TPO).

  • Disclosures to or requests by healthcare providers for treatment purposes are completely exempt from HIPAA's 'minimum necessary' rule.

  • Under the HITECH Act, if a patient pays out-of-pocket in full and requests that PHI not be disclosed to a health plan, the pharmacy MUST honor that restriction request.

  • Under the Breach Notification Rule, covered entities must notify affected individuals within 60 calendar days of discovering a breach; breaches affecting 500 or more individuals require concurrent notice to HHS and prominent media outlets.

Last updated: September 2026

5.3 Confidentiality, HIPAA & Protected Health Information

Pharmacists routinely handle deeply sensitive patient health data, from psychiatric medication records to diagnostic laboratory values and HIV therapies. Safeguarding patient confidentiality is both a federal mandate under the Health Insurance Portability and Accountability Act of 1996 (HIPAA) (codified across 45 CFR Parts 160 and 164) and a statutory obligation under the Utah Pharmacy Practice Act (Utah Code § 58-17b-604(4) and § 58-17b-502(1)(j)). Candidates preparing for the Utah MPJE must master the definitions of Protected Health Information (PHI), the operational rules governing disclosures, the minimum necessary rule, individual privacy rights, and breach notification thresholds.


Protected Health Information (PHI) Defined

Under 45 CFR § 160.103, Protected Health Information (PHI) is defined as individually identifiable health information held or transmitted by a covered entity (such as a pharmacy, hospital, or physician practice) or its business associates, in any form or medium—whether electronic, paper, or oral. PHI relates to:

  1. The past, present, or future physical or mental health condition of an individual;
  2. The provision of healthcare services to an individual; or
  3. The past, present, or future payment for the provision of healthcare to an individual.

To be classified as PHI, the data must identify the individual or provide a reasonable basis to believe the information can be used to identify the individual. Federal law recognizes 18 specific identifiers (including patient names, geographic subdivisions smaller than a state, all elements of dates except the year (and all ages over 89), telephone numbers, fax numbers, email addresses, Social Security numbers, medical record numbers, health plan beneficiary numbers, account numbers, biometric identifiers, full-face photographs, and any other unique identifying number or code, such as a prescription number).

Note

De-identified health information is not PHI and is exempt from HIPAA restrictions. Data can be de-identified either through formal statistical verification by a qualified expert or through the safe harbor method (removing all 18 specified identifiers where the covered entity has no actual knowledge that remaining information could identify the person).


Notice of Privacy Practices (NPP) Requirements

Under 45 CFR § 164.520, every pharmacy must develop and distribute a comprehensive Notice of Privacy Practices (NPP) explaining how patient PHI is used, disclosed, and protected, as well as outlining individual patient privacy rights:

  • Timing of Delivery: The pharmacy must furnish the NPP to the patient no later than the date of the first service delivery (i.e., upon dispensing the patient's initial prescription).
  • Physical & Digital Posting: The NPP must be prominently posted inside the pharmacy facility in a location where patients can easily view and read it, and must be published on the pharmacy's public website if one is maintained.
  • Written Acknowledgment: The pharmacy must make a good-faith effort to obtain a signed, written acknowledgment of receipt from the patient. If the patient refuses to sign or emergency circumstances prevent signing, the pharmacy must document its good-faith effort and the reason the acknowledgment was not obtained.
  • No Conditioning of Service: A pharmacy cannot refuse to fill or dispense a prescription solely because a patient declines to sign the NPP acknowledgment.
  • Record Retention: Signed NPP acknowledgments and documentation of good-faith efforts must be retained for at least six (6) years from the date of creation under 45 CFR § 164.530(j).

Permissible Disclosures: Treatment, Payment & Operations (TPO)

Under 45 CFR § 164.506, a covered entity may use and disclose PHI without obtaining a specific signed patient authorization for Treatment, Payment, and Health Care Operations (TPO):

  1. Treatment: The provision, coordination, or management of healthcare services among providers. Examples include consulting with a prescribing physician regarding drug-drug interactions, discussing prescription regimens with home health nurses, or transferring prescription refill data to another licensed pharmacy.
  2. Payment: Activities undertaken to obtain reimbursement or determine coverage for healthcare services. Examples include adjudicating prescription claims with third-party insurance payers or PBMs, processing Medicaid/Medicare co-payments, and communicating with patient assistance programs.
  3. Health Care Operations: Internal administrative, legal, and quality improvement activities necessary to run the pharmacy business. Examples include internal dispensing quality assurance audits, employee competency assessments, and legal compliance reviews.

Other Permissible Disclosures without Authorization

HIPAA permits disclosures without individual authorization for specific public interest purposes: disclosures required by law (e.g., reporting dispensing data to the Utah Controlled Substance Database [CSD]); public health activities (e.g., adverse event reports to FDA MedWatch); health oversight activities (e.g., DOPL inspections and audits); reporting suspected child abuse or neglect; compliance with judicial court orders or qualifying subpoenas; and responding to legitimate law enforcement inquiries under narrow statutory constraints.


The Minimum Necessary Rule & Its Critical Exceptions

Under 45 CFR § 164.502(b), covered entities must make reasonable efforts to limit the use, disclosure, or request of PHI to the minimum amount necessary to accomplish the intended clinical or administrative purpose. Pharmacies implement this through role-based access protocols (e.g., billing clerks access insurance payment fields but not clinical diagnosis notes; inventory technicians access stock counts but not patient medical histories).

Important

The Provider Treatment Exception: The "minimum necessary" rule does NOT apply to disclosures to or requests by a healthcare provider for treatment purposes. When a physician, nurse practitioner, or another pharmacist requests a patient's medication profile to treat the patient, the pharmacy may disclose the complete, unredacted medication history without violating HIPAA.

Full List of Minimum Necessary Exceptions

The minimum necessary standard does NOT apply to:

  1. Disclosures to or requests by a healthcare provider for treatment;
  2. Disclosures made directly to the patient;
  3. Uses or disclosures made pursuant to a valid, signed patient authorization;
  4. Disclosures required by law (e.g., mandatory reporting to DOPL or the DEA);
  5. Disclosures required for compliance with HIPAA Privacy Rule enforcement; and
  6. Disclosures made to the U.S. Department of Health and Human Services (HHS).

Individual Patient Rights under HIPAA

HIPAA empowers patients with enforceable legal rights regarding their health records:

  • Right of Access & Inspection (45 CFR § 164.524): Patients have the right to inspect and obtain copies of their PHI. The pharmacy must respond within 30 calendar days of the request (a single 30-day extension is permitted if written explanation is provided). The pharmacy may charge a reasonable, cost-based administrative fee for paper or electronic media copies.
  • Right to Accounting of Disclosures (45 CFR § 164.528): Patients may request an accounting of all non-TPO disclosures made by the pharmacy during the preceding six (6) years.
  • Right to Request Restrictions (45 CFR § 164.522): Generally, a pharmacy is not legally obligated to agree to patient-requested disclosure restrictions. However, under the HITECH Act amendment, there is one mandatory exception: if a patient pays for a healthcare item or service entirely out-of-pocket (cash) and explicitly requests that the pharmacy not disclose PHI regarding that item to their health insurance plan, the pharmacy MUST comply with the restriction.
  • Right to Request Confidential Communications: Patients may request to receive communication by alternative means (e.g., cell phone only) or at alternative locations (e.g., mailing to a P.O. Box).

Breach Notification Rule (45 CFR §§ 164.400–414)

A breach is defined as the impermissible acquisition, access, use, or disclosure of unsecured PHI that compromises the security or privacy of the information. Any unauthorized acquisition is presumed to be a breach unless the covered entity demonstrates a low probability of compromise through a formal four-factor risk assessment.

Breach ScopeNotice to Affected IndividualsNotice to HHS SecretaryNotice to Prominent Media
< 500 IndividualsWithin 60 calendar days of discoveryAnnual log submitted within 60 days of calendar year endNot required
≥ 500 IndividualsWithin 60 calendar days of discoveryConcurrent notice within 60 calendar days of discoveryWithin 60 calendar days to prominent media if more than 500 residents of a state or jurisdiction are affected

Utah Confidentiality Rules

Utah adds its own rules on top of HIPAA:

  • Definition. "Confidential information" in the Pharmacy Practice Act means the same as HIPAA's "protected health information" (§ 58-17b-102(19)).
  • Unprofessional conduct. Disclosing confidential patient information in violation of HIPAA or other applicable law is unprofessional conduct (§ 58-17b-502(1)(j)). DOPL's fine schedule sets $100–$500 for a first offense.
  • Who may receive prescription and profile information (§ 58-17b-604(4)). A pharmacist, intern, or technician may release or discuss prescription or profile information only with the patient in person (or the patient's legal guardian or designee), a lawfully authorized drug enforcement officer, a third-party payer the patient has authorized, pharmacy staff or prescribers providing care to the patient, a pharmacy or prescriber receiving a transfer the patient requested, or the patient's attorney with notarized written authorization.
  • Controlled Substance Database. Knowingly and intentionally releasing CSD information in violation of the access limits is a third degree felony. Negligent or reckless release is a class C misdemeanor. Each knowing misuse can also carry a civil penalty of up to $5,000 (§ 58-37f-601).
  • Standing-order contraception data. Information collected under the hormonal contraception standing order is confidential "health data" under Title 26B (R433-200-4).
Loading diagram...
HIPAA Disclosure & Minimum Necessary Evaluation Protocol
Test Your Knowledge

A patient presents a new prescription for an expensive medication at a community pharmacy and decides to pay the entire cash price out-of-pocket rather than billing their health insurance plan. The patient explicitly requests in writing that the pharmacy not share any information regarding this prescription with their health insurer. Under HIPAA regulations (45 CFR § 164.522), how must the pharmacy respond?

A

The pharmacy may reject the request because pharmacies are never legally bound to accept patient disclosure restrictions

B

The pharmacy must notify the health plan of the patient's request and await health plan authorization before dispensing

C

The pharmacy must comply with the restriction request because the service was paid for entirely out-of-pocket

D

The pharmacy must submit the claim anyway to ensure the prescription counts toward the patient's annual insurance deductible

Test Your Knowledge

A hospital pharmacist in Salt Lake City receives a telephone call from a primary care physician treating a patient currently admitted to the hospital. The physician requests the patient's complete 12-month outpatient prescription history to evaluate drug interactions. Under HIPAA's Privacy Rule (45 CFR § 164.502), does the 'minimum necessary' standard apply to this disclosure?

A

Yes, the pharmacist may only disclose the single most recent prescription fill to satisfy the minimum necessary rule

B

Yes, the pharmacist must redact all medication names that are not directly relevant to the patient's chief complaint

C

Yes, the pharmacist must obtain a signed HIPAA authorization from the patient prior to discussing prescription history with any physician

D

No, disclosures to or requests by a healthcare provider for treatment purposes are explicitly exempt from the minimum necessary standard

Test Your Knowledge

An electronic database breach occurs at a licensed Utah pharmacy, resulting in the unauthorized access and extraction of unencrypted prescription records and Social Security numbers belonging to 1,200 Utah residents. Under the federal HIPAA Breach Notification Rule (45 CFR Part 164 Subpart D), which notification requirement must the pharmacy execute?

A

Notify all affected individuals, the Secretary of HHS, and prominent Utah media outlets within 60 calendar days of breach discovery

B

Notify affected individuals within 90 days and submit an annual summary to the Utah State Board of Pharmacy

C

Notify the local police department within 24 hours, but individual notices may be withheld if credit monitoring is provided

D

Notify only the Centers for Medicare & Medicaid Services (CMS) within 180 days of the incident

Test Your Knowledge

A patient presenting a new prescription to a Utah community pharmacy is handed a copy of the pharmacy's Notice of Privacy Practices (NPP) and a signature pad acknowledging receipt. The patient refuses to sign the written acknowledgment. How should the pharmacy proceed under federal HIPAA regulations?

A

The pharmacy must refuse to dispense the medication until the patient signs the acknowledgment form

B

The pharmacy must document its good-faith effort to obtain the acknowledgment and the reason it was not obtained, then dispense the medication

C

The pharmacy must contact the U.S. Department of Health and Human Services (HHS) to report an uncooperative patient

D

The pharmacy must charge an administrative penalty fee of $50 for non-compliance with privacy documentation

Sections you finish are checked off in the contents.