HIPAA Privacy Rule: Patient Rights and Permitted Disclosures Explained

Quick answer: The HIPAA Privacy Rule (45 CFR Part 160 and Subparts A and E of Part 164) sets the national standard for how covered entities and their business associates may use and disclose protected health information (PHI), and it gives patients enforceable rights over their own records. Where the Security Rule protects electronic PHI through technical safeguards, the Privacy Rule governs every form of PHI — paper, oral, and electronic — and answers a different question: not “is the data secured?” but “are you even allowed to use or share it this way?”

What the Privacy Rule actually regulates

The core principle is that PHI may not be used or disclosed unless the Privacy Rule permits or requires it. Treatment, payment, and health care operations (TPO) are permitted without patient authorization — this is what lets a clinic bill insurance and coordinate care without paperwork for every action. Most other disclosures require a valid written authorization under 45 CFR § 164.508. A handful of public-interest exceptions (court orders, public health reporting, law enforcement under specific conditions) are also permitted, but each has precise conditions that are easy to over-read.

Layered on top of nearly every disclosure is the minimum necessary standard (§ 164.502(b) and § 164.514(d)): you must limit PHI to the least amount needed to accomplish the purpose. A notable trap is that minimum necessary does not apply to disclosures for treatment — but it absolutely applies to operations, billing questions, and internal access. Our guide to the HIPAA minimum necessary standard walks through where this rule bites hardest in day-to-day workflows.

The patient rights the Privacy Rule creates

The Privacy Rule is unusual among security regulations because it grants individuals affirmative rights, and OCR enforces them aggressively. Patients have the right to access and obtain copies of their records (§ 164.524), to request amendments to inaccurate information (§ 164.526), to an accounting of certain disclosures (§ 164.528), to request restrictions on uses and disclosures (§ 164.522), to request confidential communications (such as being contacted only at a specific phone number), and to receive a Notice of Privacy Practices describing how their information is used. The right of access has been OCR’s single most active enforcement initiative — see our breakdown of the HIPAA right of access for the 30-day response clock and the fee limits that trip up most practices.

Where the Privacy Rule meets your Security Risk Analysis

Privacy and security are not separate compliance projects. The HIPAA Security Rule requires a Security Risk Analysis under 45 CFR § 164.308(a)(1)(ii)(A) — an accurate, thorough assessment of the risks to all electronic PHI. That analysis is where Privacy Rule obligations become concrete: it should map who can access PHI (enforcing role-based minimum necessary), how authorizations and access requests are tracked, and where PHI flows to vendors who need business associate agreements. A risk analysis that secures servers but ignores who is permitted to see what leaves your single most-cited compliance gap unaddressed.

The proposed 2026 Security Rule update

In December 2024, the HHS Office for Civil Rights published a Notice of Proposed Rulemaking (NPRM) proposing the first major overhaul of the Security Rule in over a decade. It is a proposal, not final law — nothing in it is enforceable today. If finalized as written, it would tighten documentation, mandate measures that are currently “addressable” (such as encryption and multi-factor authentication), and require regular review of access rights. Covered entities would have roughly a 240-day compliance window after a final rule is published. The practical takeaway: the proposal rewards organizations that already keep a current risk analysis and disciplined access controls, so building those habits now is the lowest-risk path.

How Medcurity helps

Medcurity gives covered entities and business associates a guided Security Risk Analysis that ties Privacy Rule obligations — minimum necessary, access tracking, business associate management, and patient-rights workflows — to documented, audit-ready evidence. Instead of a spreadsheet that goes stale, you get a living assessment, remediation tracking, and the documentation OCR asks for first. Pricing is $499/year (about $42/month) for a single organization; larger or multi-entity organizations can request a quote. The goal is simple: make “are we allowed to do this, and can we prove it?” a question you can answer on demand.

Frequently Asked Questions

Does the HIPAA Privacy Rule apply to paper records?

Yes. The Privacy Rule covers PHI in every form — paper, oral, and electronic. The Security Rule is the part that applies specifically to electronic PHI. So a fax left on a printer or a conversation overheard at a front desk can be a Privacy Rule violation even though no computer was involved.

Do we need patient authorization to share records for treatment?

No. Uses and disclosures for treatment, payment, and health care operations (TPO) are permitted without authorization. Most other disclosures — marketing, sharing with an employer, or releasing records to a third party at the patient’s direction — require a valid written authorization under 45 CFR § 164.508.

What is the difference between the Privacy Rule and the Security Rule?

The Privacy Rule governs whether and how PHI may be used or disclosed and what rights patients have over it. The Security Rule sets the administrative, physical, and technical safeguards that protect electronic PHI specifically. You need to comply with both; a Security Risk Analysis is required under the Security Rule but should reflect Privacy Rule access limits.

How long do we have to respond to a patient’s request for their records?

Generally 30 days from the request, with one possible 30-day extension if you notify the patient in writing of the reason. The right of access has been the focus of dozens of OCR enforcement settlements, so timely, reasonably priced responses matter.