
Short answer: Under the HIPAA Privacy Rule, covered entities may use and disclose PHI without the patient's authorization for treatment, payment and health care operations (TPO), for specific public-interest purposes in 45 CFR 164.512, and incidentally. They must disclose to the individual and to HHS on request. Most other uses, including most marketing and most sales of PHI, need a signed authorization.
Related guides:
- What is the HIPAA minimum necessary rule?
- HIPAA release forms explained
- What is a HIPAA business associate agreement?
Key takeaways
- The Privacy Rule starts from a default of "no": a covered entity may use or disclose PHI only as the rule permits or requires (45 CFR 164.502(a)).
- Only two disclosures are required: to the individual (for access and accounting requests) and to HHS when it investigates or reviews compliance.
- TPO covers most day-to-day healthcare sharing and needs no HIPAA authorization, though stricter state or federal rules can apply.
- Public-interest disclosures under 164.512 are permitted, not mandatory, and each one has its own conditions.
- Business associates can only do what their BAA allows, and generally cannot do anything with PHI that the covered entity itself could not do.
- Many non-routine disclosures must be logged for an accounting of disclosures.
How does HIPAA decide whether a PHI disclosure is allowed?
HIPAA allows a use or disclosure of PHI only when it fits a category the Privacy Rule names; anything outside those categories needs the individual's written authorization.
A "use" happens inside your organization. A "disclosure" releases or gives access to PHI outside it. Both follow the same structure:
| Category | Authorization needed? | Main citation |
|---|---|---|
| Required disclosures (individual, HHS) | No | 45 CFR 164.502(a)(2) |
| Treatment, payment, health care operations | No | 45 CFR 164.506 |
| Uses with an opportunity to agree or object (facility directories, family and friends involved in care) | No, but the individual can object | 45 CFR 164.510 |
| Public-interest and benefit purposes | No, conditions apply | 45 CFR 164.512 |
| Incidental uses and disclosures | No, if safeguards and minimum necessary are in place | 45 CFR 164.502(a)(1)(iii) |
| Limited data set under a data use agreement | No | 45 CFR 164.514(e) |
| Everything else | Yes | 45 CFR 164.508 |
De-identified data that meets 45 CFR 164.514(a) and (b) is not PHI, so these rules stop applying to it. For the wider context, see our HIPAA Privacy Rule guide.
Which disclosures are required, not just permitted?
A covered entity must disclose PHI in exactly two situations: to the individual who asks for their own information, and to HHS when it is investigating or reviewing compliance.
- To the individual. When a patient exercises the right of access (45 CFR 164.524) or asks for an accounting of disclosures (45 CFR 164.528), you must respond within the rule's timeframes and formats: 30 days for an access request and 60 days for an accounting of disclosures, each with one possible 30-day extension.
- To HHS. The Office for Civil Rights can require access to PHI to determine compliance.
Business associates have a parallel duty. They must disclose PHI to HHS when required to investigate compliance, and to the covered entity, the individual or the individual's designee as needed to satisfy access requests involving electronic copies (45 CFR 164.502(a)(4)). For a SaaS platform, that usually means an export path that lets customers answer access requests on time.
What are TPO disclosures?
TPO disclosures are uses and disclosures for treatment, payment and health care operations, and HIPAA permits them without the patient's authorization.
| Purpose | Typical examples | Who it covers |
|---|---|---|
| Treatment | Referrals, consultations between providers, care coordination, e-prescribing | Your own treatment activities and those of any health care provider |
| Payment | Eligibility checks, claims, billing, utilization review, collections | Your own payment activities, and disclosures to another covered entity or provider for its payment activities |
| Health care operations | Quality improvement, credentialing, audits, compliance programs, business planning, customer service | Your own operations; disclosures to another covered entity for certain of its operations only if both have a relationship with the individual |
Five practical points:
- Reproductive health records. A 2024 HHS rule that added limits on reproductive health care disclosures was largely vacated by a federal court in June 2025 (Purl v. HHS opinion). Notice of Privacy Practices changes tied to Part 2 records were left in place. Check the HHS reproductive health page for the current position. State laws may still add protections.
- Consent is optional under HIPAA. A covered entity may choose to obtain consent for TPO, but the Privacy Rule does not require it (45 CFR 164.506(b)). State laws, and separate federal rules such as those for substance use disorder treatment records under 42 CFR Part 2, can be stricter. A 2024 final rule aligned many Part 2 requirements more closely with HIPAA, and its compliance date was February 16, 2026, so the aligned rules now apply (see 42 CFR Part 2 on eCFR).
- Operations has limits. "Health care operations" is a defined term. Your own product analytics or model training does not automatically qualify.
- Minimum necessary still applies to payment and operations, though not to disclosures to a provider for treatment.
- Psychotherapy notes are the exception. Most uses and disclosures of psychotherapy notes need authorization even for TPO (45 CFR 164.508(a)(2)). See the authorization section below.
When can PHI be disclosed without authorization for public-interest purposes?
Section 164.512 permits disclosures for a defined set of public-interest purposes, each with its own conditions, and none of them obliges you to disclose unless another law does.
At a high level, the categories are:
- Required by law, limited to what the law requires.
- Public health activities, such as reporting disease to a public health authority or adverse events to the FDA.
- Victims of abuse, neglect or domestic violence, to authorized government authorities under specific conditions.
- Health oversight activities, such as audits and investigations by oversight agencies.
- Judicial and administrative proceedings, in response to a court order, or a subpoena or discovery request that meets the rule's assurance requirements.
- Law enforcement purposes, in specific listed circumstances, such as certain court-ordered process or identifying a suspect.
- Decedents, to coroners, medical examiners and funeral directors.
- Organ, eye and tissue donation.
- Research, with an IRB or privacy board waiver or other listed conditions.
- To avert a serious threat to health or safety.
- Specialized government functions, such as certain military and national security activities.
- Workers' compensation, as authorized by those laws.
Treat each request as a review item. Verify the requester's identity and authority (45 CFR 164.514(h)), check the conditions in the relevant paragraph, apply minimum necessary where it applies, and log the disclosure.
Which uses and disclosures always need an authorization?
Any use or disclosure not otherwise permitted or required needs a valid authorization, and the rule calls out three categories specifically: psychotherapy notes, marketing and sale of PHI.
- Psychotherapy notes (45 CFR 164.508(a)(2)). Most uses and disclosures need authorization, with narrow exceptions such as the originator's own treatment use.
- Marketing (45 CFR 164.508(a)(3)). Authorization is needed for most marketing communications. Face-to-face communications and promotional gifts of nominal value are exceptions. If the covered entity receives financial remuneration from a third party for the marketing, the authorization must say so.
- Sale of PHI (45 CFR 164.508(a)(4)). Receiving remuneration in exchange for PHI requires an authorization that states the remuneration, subject to limited exceptions in the rule.
A valid authorization needs core elements such as the information covered, the recipient, the purpose, an expiration and a signature. Our HIPAA authorization guide covers the full list.
How do incidental disclosures and minimum necessary fit in?
An incidental disclosure is a secondary, unavoidable disclosure that happens alongside a permitted one, and it is allowed only if you have reasonable safeguards and apply the minimum necessary standard.
A classic example is another patient overhearing a name called in a waiting room. It is not a cover for poor controls: a misdirected email or an over-broad database role is not incidental.
The minimum necessary standard (45 CFR 164.502(b) and 164.514(d)) is the second filter on almost every permitted disclosure. It asks you to limit PHI to what the purpose requires, with exceptions such as disclosures to a provider for treatment and disclosures to the individual. We cover role-based access, standard protocols and the exceptions in detail in our minimum necessary rule guide.
What can a business associate do with PHI?
A business associate may use and disclose PHI only as its business associate agreement permits or requires, or as required by law (45 CFR 164.502(a)(3) and 164.504(e)).
In practice, a BAA typically allows you to:
- Perform the contracted services for the covered entity, such as hosting, billing, analytics or communications.
- Use PHI for your own proper management and administration and to carry out your legal responsibilities, if the BAA allows it. Disclosures for those purposes need either a legal requirement or reasonable assurances of confidentiality from the recipient.
- Provide data aggregation services relating to the covered entity's health care operations, if the BAA allows it.
- De-identify PHI, only if the BAA permits it.
Generally, a business associate cannot do anything with PHI that would violate the Privacy Rule if the covered entity did it. Subcontractors that handle PHI on your behalf need their own BAA with you (45 CFR 164.502(e)(1)(ii)), agreeing to the same restrictions and conditions that apply to you (45 CFR 164.504(e)(5)).
For SaaS teams, the risk usually sits in quiet secondary uses, like copying production PHI into test environments or sending raw logs to tools without a BAA. Map every PHI flow to a clause in the BAA.
Which disclosures must be tracked for an accounting?
Individuals have a right to an accounting of certain disclosures made in the six years before the request (45 CFR 164.528), so you need to log disclosures that fall outside the excluded categories.
Disclosures that generally do not need to be accounted for include those for TPO, to the individual, incidental disclosures, those under an authorization, facility directory and family involvement disclosures, certain national security and correctional disclosures, and those in a limited data set.
That leaves most 164.512 disclosures, such as public health reports, court orders and law enforcement requests, plus impermissible disclosures. Each entry records the date, recipient, a brief description of the PHI and the purpose. BAAs usually require business associates to supply their disclosure records to the covered entity.
Decision table: can we share this PHI?
Use this as a first pass, then check the citation and your BAA.
| Situation | Allowed without authorization? | Log for accounting? |
|---|---|---|
| Patient asks for a copy of their records | Yes, required | No |
| HHS OCR requests records in an investigation | Yes, required | Likely yes, as it is not among the 164.528(a)(1) exclusions. Check 164.528 for your case |
| Sending records to a specialist for a referral | Yes, treatment | No |
| Submitting a claim to a health plan | Yes, payment | No |
| Internal quality review or compliance audit | Yes, operations | No |
| Reporting a reportable disease to a public health authority | Yes, 164.512(b) | Yes |
| Responding to a subpoena without a court order | Only if 164.512(e) conditions are met | Yes |
| Sending patient lists to a third party for its marketing | No, authorization needed | Not applicable |
| Selling patient records to a data broker | No, authorization needed | Not applicable |
| Business associate using PHI to build an unrelated product | Only if the BAA permits and the Privacy Rule allows | Depends on use |
How SecureSlate helps
SecureSlate helps you turn the disclosure categories in this guide into written procedures your team can follow. Policy management helps you keep disclosure, authorization and minimum necessary procedures versioned and approved. Vendor risk management helps you track which vendors receive PHI and whether a BAA is in place, and identity integrations help you collect evidence of the access controls that limit who can see PHI in the first place.
Start your free SecureSlate trial
FAQ
Do we need patient consent to share PHI for treatment?
Not under HIPAA. Treatment, payment and health care operations disclosures are permitted without authorization, and consent for TPO is optional. State laws and other federal rules for certain sensitive records can still require consent, so check those before you rely on TPO alone.
Is a HIPAA disclosure to law enforcement mandatory?
Usually not. Section 164.512 permits certain disclosures to law enforcement but does not require them. A disclosure becomes mandatory only when another law, such as a court order, requires it, and then only to the extent required.
Can a business associate use PHI to improve its own product?
Only if the BAA permits it and the use is consistent with the Privacy Rule. Many teams de-identify data first, which requires the BAA to allow de-identification and the data to meet the standard in 45 CFR 164.514.
Disclaimer (legal note)
This article is for general information only and is not legal, regulatory or professional advice. Requirements vary by framework, industry and jurisdiction. Consult qualified advisors for your specific obligations.
Need compliance without the complexity?
SecureSlate automates ISO 27001, SOC 2, GDPR, HIPAA, and more. Built for growing teams. See it in action.
Find compliance gaps in 30 seconds