Protected Health Information (PHI)
PHI is individually identifiable health information that is transmitted or maintained in any form (electronic, paper, or oral) by a covered entity or business associate. There are 18 identifiers that make health information individually identifiable:
- Names
- Geographic data smaller than a state
- Dates (except year) related to an individual
- Telephone numbers
- Fax numbers
- Email addresses
- Social Security numbers
- Medical record numbers
- Health plan beneficiary numbers
- Account numbers
- Certificate/license numbers
- Vehicle identifiers and serial numbers
- Device identifiers and serial numbers
- Web URLs
- IP addresses
- Biometric identifiers
- Full-face photographs
- Any other unique identifying number or code
Covered Entities and Business Associates
| Type | Description | Examples |
|---|---|---|
| Health Plans | Entities that provide or pay the cost of healthcare | Health insurance companies, HMOs, Medicare, Medicaid |
| Healthcare Clearinghouses | Entities that process health information between nonstandard and standard formats | Billing services, repricing companies |
| Healthcare Providers | Providers who transmit health information electronically | Hospitals, physicians, pharmacies, labs |
| Business Associates | Persons or entities performing functions on behalf of a covered entity involving PHI | Billing companies, EHR vendors, attorneys, accountants |
Minimum Necessary Standard
Covered entities must make reasonable efforts to limit PHI to the minimum necessary to accomplish the intended purpose of the use, disclosure, or request. Exceptions to the minimum necessary standard include:
- Disclosures to or requests by a healthcare provider for treatment purposes
- Disclosures to the individual who is the subject of the information
- Uses or disclosures made pursuant to a valid authorization
- Disclosures to HHS for compliance investigations
- Uses or disclosures required by law
Patient Rights Under the Privacy Rule
| Right | Details | Timeframe |
|---|---|---|
| Right of Access | Patients can inspect and obtain a copy of their PHI in a designated record set | 30 days (one 30-day extension permitted) |
| Right to Amend | Patients can request amendments to their PHI; denial allowed if information is accurate | 60 days (one 30-day extension permitted) |
| Right to Accounting of Disclosures | Patients can receive a list of disclosures made in the prior 6 years (excludes TPO, patient-authorized, and others) | 60 days (one 30-day extension permitted) |
| Right to Request Restrictions | Patients can ask to restrict uses/disclosures; covered entity generally not required to agree | No specific timeframe |
| Right to Confidential Communications | Patients can request PHI be sent by alternative means or to alternative locations | Must accommodate reasonable requests |
| Right to Notice of Privacy Practices | Patients must receive a description of how their PHI may be used and disclosed | At first service delivery |
Treatment, Payment, and Operations (TPO)
PHI may be used or disclosed without patient authorization for:
- Treatment: Provision, coordination, or management of healthcare (e.g., sharing records between consulting physicians)
- Payment: Activities related to obtaining reimbursement (e.g., claims processing, eligibility determinations, utilization review)
- Healthcare Operations: Administrative and quality activities (e.g., quality assessment, training programs, compliance activities, business planning)
When Authorization Is Required
A valid authorization must be obtained for uses and disclosures not otherwise permitted or required. Required elements include:
- Description of the information to be used or disclosed
- Name or class of persons authorized to make the disclosure
- Name or class of persons to whom the disclosure may be made
- Purpose of the use or disclosure
- Expiration date or event
- Signature and date of the individual
- Right to revoke the authorization in writing
Authorizations are always required for: psychotherapy notes, marketing communications, and sale of PHI.
Permitted Disclosures Without Authorization (Beyond TPO)
- As required by law (e.g., court orders, subpoenas)
- Public health activities (e.g., reporting communicable diseases)
- Victims of abuse, neglect, or domestic violence
- Health oversight activities (e.g., audits, investigations)
- Judicial and administrative proceedings
- Law enforcement purposes (under specific conditions)
- Decedents - to coroners, medical examiners, funeral directors
- Organ and tissue donation
- Research with IRB or Privacy Board waiver of authorization
- To avert a serious threat to health or safety
- Workers compensation
Breach Notification Requirements
| Breach Size | Notification Requirement | Timeframe |
|---|---|---|
| Fewer than 500 individuals | Notify affected individuals and log for annual report to HHS | Within 60 days of discovery; annual log submitted to HHS |
| 500 or more individuals | Notify affected individuals, HHS, and prominent media outlet in the state | Within 60 days of discovery - without unreasonable delay |
A breach is the acquisition, access, use, or disclosure of unsecured PHI in a manner not permitted by the Privacy Rule that compromises the security or privacy of the PHI. Exceptions include unintentional acquisition by workforce members acting in good faith, inadvertent disclosures between authorized persons, and situations where the recipient could not reasonably retain the information.
Notice of Privacy Practices (NPP)
- Must be provided to patients at first service delivery
- Must describe uses and disclosures of PHI, patient rights, and the entity's legal duties
- Must be posted in a clear and prominent location at the facility
- Must be available on the covered entity's website if one exists
- A good-faith effort must be made to obtain a written acknowledgment of receipt