The Privacy Rule (45 CFR Part 160 and Subparts A and E of Part 164) establishes national standards for the use and disclosure of individuals' protected health information (PHI). It applies to covered entities — health plans, health care clearinghouses, and health care providers who transmit health information electronically — and balances the need to protect PHI with the need to allow appropriate flow of health information for care and public health.
45 CFR § 164.500–534Answers, cited to the rule.
Browse by category or search. Every answer links to the specific CFR citation so you can verify the source.
Privacy Rule
4 answersPHI is individually identifiable health information held or transmitted by a covered entity or business associate in any form — electronic, paper, or oral. It includes demographic data that relates to the individual's past, present, or future physical or mental health, the provision of care, or payment for care, and that identifies the individual or could reasonably be used to identify them.
45 CFR § 160.103Covered entities may use or disclose PHI without authorization for treatment, payment, and health care operations (TPO). Other permitted disclosures include situations required by law, public health reporting, victim reporting, and limited purposes with the individual's informal permission. Any use or disclosure beyond these requires a written, signed authorization that meets specific content requirements.
45 CFR § 164.506, § 164.512, § 164.508When using, disclosing, or requesting PHI, covered entities must make reasonable efforts to limit it to the minimum necessary to accomplish the intended purpose. This does not apply to disclosures to or requests by a provider for treatment, to the individual themselves, or disclosures required by law.
45 CFR § 164.502(b)