HIPAA fundamentals

The HIPAA Privacy Rule Explained: What It Requires and Who Must Comply

People treat HIPAA and the Privacy Rule as the same thing, but the Privacy Rule is one specific part of the law with its own rules about who can use protected health information, when they need permission, and what rights patients hold. Here is a plain-language walk through what the Privacy Rule requires, how it differs from the Security Rule, who has to follow it, and why every workforce member who touches patient data has to be trained on it.

July 4, 2026

HIPAA Privacy Rule summary: what it is and where it lives

When people say a company is HIPAA compliant, or that something was a HIPAA violation, they are almost always talking about the Privacy Rule without naming it. The Privacy Rule is the part of HIPAA that decides who is allowed to use and share a patient's health information, when they need the patient's permission, and what rights the patient holds over their own records. It is not the whole of HIPAA, and confusing the part for the whole is where a lot of misunderstanding starts. HIPAA is a package of related rules, and the Privacy Rule is the one that governs the everyday handling of protected health information in every form it takes. This guide explains what the Privacy Rule actually requires, where it comes from in the regulation, how it differs from the Security Rule people often mix it up with, who has to comply, and why the rule places a direct training duty on every organization it covers.

The Privacy Rule has a formal home in the Code of Federal Regulations. It lives at 45 CFR Part 160 and Part 164, Subparts A and E, and its full name is the Standards for Privacy of Individually Identifiable Health Information. Congress created the framework in the Health Insurance Portability and Accountability Act of 1996, the Department of Health and Human Services wrote the rule, and the HHS Office for Civil Rights enforces it. The Privacy Rule took effect in 2003, and the HITECH Act of 2009 later strengthened it and extended direct liability to business associates. Understanding that the rule is federal regulation, not vague best practice, matters because every requirement below is an enforceable legal standard with a citation you can point to, and the penalties for ignoring it are real. When this guide names a section such as 45 CFR 164.502, that is the actual rule text a regulator would apply.

The subject of the Privacy Rule is protected health information, usually shortened to PHI, which is individually identifiable health information held or transmitted by a covered entity or business associate in any form, whether spoken, written on paper, or stored electronically. That last point is the cleanest way to separate the Privacy Rule from the Security Rule: the Privacy Rule protects PHI in every form, including a conversation at the front desk and a chart on paper, while the Security Rule applies only to electronic protected health information and the technical and physical safeguards that keep it secure. So the Privacy Rule is the broad rule about who may use and disclose information and what patients can do about it, and the Security Rule is the narrower companion about locking down the electronic version. If you want the full breakdown of what counts as PHI and what does not, our guide to protected health information and the eighteen HIPAA identifiers walks through the definition in detail, because you cannot apply the Privacy Rule to information you cannot first recognize as protected.

Permitted uses and disclosures: the core of the Privacy Rule

The heart of the Privacy Rule is one deceptively simple sentence at 45 CFR 164.502(a): a covered entity or business associate may not use or disclose protected health information except as the Privacy Rule permits or requires. That is the default posture, and it flips the intuition many people have. The rule does not start by listing what is forbidden and allow everything else. It starts by forbidding use and disclosure and then carves out the specific situations where they are allowed. Everything the Privacy Rule does after that first sentence is either describing a permitted use, requiring a disclosure, demanding the patient's written permission, or granting the patient a right. Once you see that structure, the rest of the rule stops feeling like a random pile of requirements and reads as a set of answers to a single question: when may this information move, and on whose authority.

The largest category of permitted use is treatment, payment, and health care operations, often abbreviated TPO and set out at 45 CFR 164.506. A covered entity may use and disclose PHI without the patient signing anything in order to treat them, to bill and collect payment for that care, and to run the core operations of the organization such as quality review, training, and administration. This is why your doctor can send your records to a specialist, why a hospital can share information with your insurer to get paid, and why a clinic can audit its own charts for quality. The Privacy Rule treats these as the ordinary business of health care and does not force a signature for each one. Alongside TPO, the rule requires disclosure in only two situations at 164.502(a)(2): to the individual when they ask for their own information, and to HHS when it is investigating compliance. Everything a covered entity is required to hand over comes down to those two, and everything else is either permitted or needs authorization.

Beyond treatment, payment, and operations, the Privacy Rule permits a set of disclosures that serve the public interest, and these are spelled out at 45 CFR 164.512. They include reporting to public health authorities, disclosures required by other laws, reporting abuse or neglect, responding to certain law enforcement requests, working with coroners and medical examiners, supporting essential government functions, and complying with workers compensation laws. Each of these carries its own conditions and limits, and they are permissions rather than open doors, so a covered entity still has to confirm the specific requirements before releasing anything. The reason this category exists is that society sometimes needs health information to move without the patient's signature, for example to contain an outbreak, and the rule tries to allow those uses while keeping them bounded. Staff get into trouble when they treat these as blanket exceptions rather than narrow, condition-laden permissions, which is one more reason training matters.

Minimum necessary, authorizations, and everyday disclosures

Layered on top of every use and disclosure is the minimum necessary standard at 45 CFR 164.502(b) and 164.514(d), and it is the rule most workforce members live under day to day. Minimum necessary says that when you use, disclose, or request PHI, you must limit it to the least amount needed to accomplish the purpose. A billing clerk resolving a claim needs the codes and dates tied to that claim, not the patient's entire chart. A scheduler needs a name and an appointment time, not a full history. The standard has important exceptions, most notably that it does not apply to disclosures for treatment, because a treating clinician needs the full picture, and it does not apply when the patient has authorized the disclosure. But for the routine internal uses that make up most of a workday, minimum necessary is the discipline that keeps access proportionate, and it only works if people can tell what counts as protected health information and what their job actually requires.

When a use or disclosure falls outside the permitted categories, the Privacy Rule requires the patient's written authorization under 45 CFR 164.508. An authorization is a specific, informed, signed permission that describes what information will be shared, with whom, for what purpose, and when it expires. The rule singles out several situations where authorization is almost always required, including most marketing, any sale of protected health information, and the use or disclosure of psychotherapy notes, which receive heightened protection. An authorization is not the same as the general consent forms a patient signs at intake, and it is not the same as the notice of privacy practices, a distinction people routinely blur. Getting this right protects the organization, because using PHI for a purpose that needed an authorization and did not have one is a classic violation, and it protects the patient, whose signature is supposed to reflect a real, specific choice rather than a buried checkbox.

Two situations sit between the formal permissions and a violation, and staff worry about both more than the rule requires. The first is the incidental disclosure. The Privacy Rule at 45 CFR 164.502(a)(1)(iii) permits disclosures that occur incident to an otherwise permitted use, so long as the organization applied reasonable safeguards and minimum necessary limits. If a visitor overhears a nurse quietly discussing care with a patient in a semi-private room, that overheard fragment is not a violation, because the underlying conversation was permitted and reasonable precautions were taken. Sign-in sheets and calling names in a waiting room survive on the same logic. The second is disclosure to family and friends under 164.510(b). When a patient is present and can make decisions, a provider may share relevant information with a spouse, relative, or friend involved in the patient's care if the patient agrees or simply does not object when given the chance. When the patient is unavailable or incapacitated, the provider may use professional judgment to share what is directly relevant with someone involved in the care or with payment for it. Facility directories under 164.510(a) work the same way, with an opportunity to opt out. None of this is a loophole; each rests on safeguards, professional judgment, and the patient's chance to say no.

Patient rights and the Notice of Privacy Practices

The Privacy Rule does not only restrain organizations, it grants patients a set of enforceable rights over their own information, and these rights are a frequent source of both search traffic and complaints. The right of access at 45 CFR 164.524 lets individuals inspect and get copies of their records, generally within thirty days and for no more than a reasonable, cost-based fee, and access failures are among the most commonly enforced violations. The right to amend at 164.526 lets patients ask to correct information they believe is wrong. The right to an accounting of disclosures at 164.528 lets them request a list of certain disclosures going back six years. The right to request restrictions at 164.522 lets them ask a provider to limit certain uses, including a specific right to restrict disclosure to a health plan when they pay out of pocket in full. And every covered entity must give patients a notice of privacy practices under 164.520 that explains how it uses their information and what rights they have. A workforce that does not know these rights exist cannot honor them, which is exactly how access complaints reach OCR.

One patient right deserves a longer look because every covered entity has to produce a document for it: the Notice of Privacy Practices required by 45 CFR 164.520. The notice is the plain-language explanation a covered entity must give patients describing how it may use and disclose their PHI, the rights patients hold under the Privacy Rule, the entity's own legal duties, and who to contact with a complaint. The rule dictates specific elements, including a required header, descriptions of treatment, payment, and operations uses with examples, the list of patient rights, and statements added by the 2013 Omnibus Rule about breach notification and the uses that require authorization. Direct treatment providers must make a good faith effort to obtain a written acknowledgment that the patient received the notice, must post it prominently at the facility, and must publish it on their website if they have one. Health plans distribute the notice at enrollment and remind members of its availability every three years. An out-of-date notice is one of the easiest findings for an investigator to spot and one of the easiest problems to fix. If yours predates the Omnibus amendments or you are starting from scratch, our free Notice of Privacy Practices generator builds a notice mapped to each required element of 164.520.

The Privacy Rule also imposes a set of administrative requirements at 45 CFR 164.530 that turn the rule from a set of principles into an operating program, and this is the section that most directly affects staff. A covered entity must designate a privacy official responsible for its policies under 164.530(a). It must train all members of its workforce on its privacy policies and procedures under 164.530(b), and must do so for new members within a reasonable time and again when policies materially change. It must have appropriate administrative, technical, and physical safeguards under 164.530(c), maintain a complaint process under 164.530(d), apply sanctions to workforce members who violate its policies under 164.530(e), mitigate harm from improper disclosures, and refrain from retaliating against people who exercise their rights or from requiring patients to waive those rights. Finally, under 164.530(j), it must keep its privacy policies and the required documentation, including training records, for six years. That documentation duty is why a HIPAA course produces a dated certificate: the certificate is part of the record the rule requires an organization to retain.

Business associates, exceptions, and de-identified data

Business associates deserve their own mention because the Privacy Rule reaches beyond the doctors and hospitals people picture. A business associate is any outside person or company that creates, receives, maintains, or transmits PHI on behalf of a covered entity, which sweeps in billing companies, IT and cloud vendors, transcription services, analytics firms, shredding companies, and many software providers. Under 45 CFR 164.502(e), a covered entity may only share PHI with a business associate under a written business associate agreement, and since HITECH, business associates are directly liable for Privacy Rule obligations rather than only answerable through a contract. The practical consequence is that a software engineer at a health-tech startup or a clerk at a billing vendor is subject to the Privacy Rule even though they never wear scrubs, and their employer carries the same training and safeguard duties a clinic does. This is one of the most common blind spots, because non-clinical companies often assume HIPAA is somebody else's problem right up until an audit or a breach proves otherwise.

Just as important is what the Privacy Rule does not cover, because the exceptions confuse people in both directions. HIPAA binds covered entities and business associates, not information itself, so the same fact about your health can be protected in one set of hands and unprotected in another. Employment records that an employer holds in its role as an employer are expressly excluded from the definition of protected health information, even at a hospital, so a doctor's note sitting in an HR file falls outside the Privacy Rule while the identical note in the treatment chart is protected. Education records covered by FERPA, including most school health records, are likewise excluded and follow FERPA instead. A fitness tracker, a wellness app you download yourself, or a period-tracking app generally sits outside HIPAA entirely unless it operates on behalf of a covered entity, and the same is true of health information you post publicly or share with family on your own. Life insurers, most employers, and many direct-to-consumer genetic services are not covered entities either. None of this means the information is fair game, since state privacy laws and the Federal Trade Commission increasingly fill the gap, but a complaint to OCR about an app or an employer usually goes nowhere because the Privacy Rule never applied in the first place.

The Privacy Rule also stops at de-identified data, and it is precise about what that means. Under 45 CFR 164.514(a), health information that neither identifies an individual nor provides a reasonable basis to identify them is not protected health information at all, and the rule recognizes exactly two ways to get there. The safe harbor method at 164.514(b)(2) removes eighteen specific identifiers, including names, geographic units smaller than a state in most cases, all elements of dates except the year, phone numbers, email addresses, record and account numbers, device identifiers, IP addresses, full-face photographs, and biometric identifiers, and it requires that the entity have no actual knowledge the remaining data could identify someone. The expert determination method at 164.514(b)(1) instead has a qualified statistician apply accepted methods and document that the risk of re-identification is very small. Properly de-identified data can be used and shared freely, which is why research and analytics teams care so much about doing it correctly. Between fully identified and de-identified sits the limited data set under 164.514(e), which strips direct identifiers but keeps dates and some geography, and which may be shared for research, public health, or health care operations only under a data use agreement. Deleting a name by itself accomplishes none of this.

Privacy Rule vs Security Rule and who enforces them

Search behavior shows that people constantly ask about the HIPAA privacy and security rules as a pair, so the relationship between the two is worth stating cleanly. The Privacy Rule answers who and when: who may use and disclose protected health information, in any form, and when the patient's permission or a specific permission written into the rule is required. The Security Rule answers how: how electronic PHI must be protected, through the administrative, physical, and technical safeguards of 45 CFR 164.308 through 164.312, such as access controls, encryption, workstation security, and audit logs. They overlap by design, since the Privacy Rule's general safeguards duty at 164.530(c) expects reasonable protection for PHI in every form, while the Security Rule turns that expectation into a formal, documented program for the electronic subset. The third sibling, the Breach Notification Rule at 45 CFR 164.400 through 164.414, governs what happens when those safeguards fail, requiring notice to affected individuals within sixty days, to HHS, and in large breaches to the media. A compliant organization needs all three at once: privacy policies that control use and disclosure, a security program that protects systems, and a tested breach response plan. Our guides to the Security Rule and to the three rules of HIPAA cover the other two in the same depth as this one.

Who enforces the HIPAA Privacy Rule is its own common question, and the answer has three parts. Civil enforcement belongs to the HHS Office for Civil Rights, which receives complaints, opens compliance reviews, and negotiates the settlements and penalties described below. Anyone may file a complaint with OCR, generally within 180 days of learning about the conduct, and OCR receives tens of thousands of complaints a year. Criminal enforcement belongs to the Department of Justice under 42 USC 1320d-6, which reaches knowing misuse of protected health information and can bring fines up to 250,000 dollars and ten years in prison when information is obtained or disclosed for commercial advantage or malicious harm. And since the HITECH Act, state attorneys general may bring civil actions on behalf of their residents, a power several states have used against both providers and vendors. What the Privacy Rule does not create is a private right of action: a patient cannot sue directly under HIPAA, though plaintiffs increasingly bring state-law negligence claims that use HIPAA as the standard of care. For workforce members the practical point is simple: complaints start with real people, usually patients or coworkers, and they land hardest on organizations that cannot document their own compliance.

Enforcement gives the Privacy Rule its teeth. The Office for Civil Rights investigates complaints and breaches, and it can impose civil money penalties that scale with culpability, from unknowing violations to willful neglect, with per-violation amounts that are adjusted annually and annual caps that reach into the millions. Many cases end in a resolution agreement with a settlement payment and a multi-year corrective action plan rather than a fine, but either way the cost is real and public. The violations that recur are worth naming because they are so preventable: denying or delaying a patient's access to their own records, snooping into charts without a work reason, disclosing more than the minimum necessary, losing unencrypted devices full of PHI, using information for marketing without authorization, and failing to have business associate agreements in place. Almost every one of these traces back to a workforce member who either did not know the rule or did not have the habit the rule expects, which is precisely the gap that training is meant to close.

Misconceptions, the training duty, and next steps

A few misconceptions about the Privacy Rule are worth correcting directly, because they cause both over-reaction and under-protection. The Privacy Rule does not apply to everyone who holds health information; it binds covered entities and business associates, so an employer acting as an employer, a school, or a fitness app outside that definition is generally not governed by it. It does not forbid all sharing; treatment, payment, operations, and the public-interest categories permit a great deal without a signature. It is not the same as the Security Rule, which covers only electronic PHI and its safeguards. A signed intake consent is not an authorization for marketing or for selling data. And being HIPAA compliant is not a one-time certificate an organization earns and forgets; the administrative requirements at 164.530, including ongoing training and documentation, describe a continuing program, not a plaque on the wall. Clearing up these points is the difference between a workforce that applies the rule sensibly and one that either panics over harmless sharing or ignores real exposure.

All of this lands on a single practical duty for organizations: the Privacy Rule requires you to train your workforce on it. The training mandate at 45 CFR 164.530(b) is not a suggestion, it applies to every covered entity, and through HITECH the same expectation reaches business associates, which means clinical staff, front desk staff, billing teams, IT vendors, and software developers all need to understand what the Privacy Rule permits, when authorization is required, what patient rights they must honor, and how minimum necessary limits their own access. Good training does not ask people to memorize section numbers; it teaches them to recognize protected health information, to know when they may act without a signature and when they may not, and to route access and restriction requests correctly, then it documents that they learned it. Our HIPAA certification path covers the Privacy Rule in plain language and gives each person a dated certificate you can retain as the proof the rule requires, and if you want to check your own understanding first, our free HIPAA practice test includes Privacy Rule questions.

The short version is that the HIPAA Privacy Rule is the part of the law that decides who may use and share protected health information, when they need the patient's written permission, and what rights the patient holds over their records, and it applies to covered entities and their business associates in every form the information takes. Its default is that PHI may not move except as the rule permits or requires; treatment, payment, operations, and specific public-interest categories are the main permissions; minimum necessary limits routine access; authorizations cover the rest; patients hold rights of access, amendment, accounting, and restriction; and the administrative requirements at 164.530, including workforce training and six-year documentation, turn the rule into an ongoing program. If you want to see where protected health information lives in your own systems, our free HIPAA risk assessment tool walks through the safeguards, team training for organizations makes it straightforward to train everyone who touches PHI, and the HIPAA certification path gives each person the documented proof that they understand the Privacy Rule and how to work within it.


Recommended resources

Keep exploring the topic.

Use the related training, compliance, and documentation pages when you need the next practical step after this guide.

Related HIPAA guides

Related guides

Other HIPAA guides worth reading.

Stay on the same workflow thread with adjacent articles from the resource library.