For detailed requirement language, visit the U.S. Dept of Health and Human Services.
Requirement | Guidance |
§164.502(a)(5)(i): Prohibited uses and disclosures -Use and disclosure of genetic information for underwriting purposes | Unless your organization is an issuer of long-term care policies, define requirements for ensuring the health plan does not use or disclose PHI that is genetic information for underwriting purposes. View instructions for defining underwriting requirements. |
§164.502(g): Personal representatives | Implement controls over personal representatives as it pertains to disclosure and access to PHI. |
§164.502(i): Uses and disclosures consistent with notice | Establish policies for participation in Organized Health Care Arrangements (OHCA), ensuring compliance with any applicable HIPAA requirements. |
§164.502(j)(1): Disclosures by whistleblowers | Allow disclosures of PHI are allowed when necessary to prevent or lessen a serious and imminent threat to health or safety, provided such disclosure is made to a person or entity able to prevent or mitigate the threat. |
§164.502(j)(2): Disclosures by workforce members who are victims of a crime | Allow disclosures of PHI when necessary to prevent or lessen a serious and imminent threat to health or safety, provided such disclosure is made to a person or entity able to prevent or mitigate the threat. |
§164.504(f): Requirements for group health plans | Allow disclosures of PHI to group health plans only as necessary for plan administration purposes and in compliance with HIPAA. |
§164.504(g): Requirements for a covered entity with multiple covered functions | Establish, document, and enforce policies to segregate PHI handling by covered function (health plan, health care provider, or health care clearinghouse) and restrict workforce access to PHI based on the specific function being performed. |
§164.506(a): Permitted uses and disclosures | Allow uses and disclosures of PHI for treatment, payment, and health care operations without requiring patient authorization, as permitted by HIPAA. |
§164.506(b)(1&2): Consent for uses and disclosures | Develop and enforce a policy to manage individual consent for using or disclosing PHI for treatment, payment, or health care operations, ensuring consent is not used where authorization is required. |
§164.508(a)(1-3)(b)(1&2): Authorizations for uses and disclosures | Require written authorization from the individual before using or disclosing PHI, except as permitted or required by HIPAA without authorization. View instructions for documenting authorizations. |
§164.508(b)(3): Compound authorizations - Exceptions | Ensure that authorizations for the use or disclosure of PHI are not combined with other documents to create a compound authorization, except in limited circumstances as allowed under HIPAA. |
§164.508(b)(4): Prohibition on conditioning of authorizations | Do not condition the provision of treatment, payment, enrollment in a health plan, or eligibility for benefits on an individual’s authorization for the use or disclosure of PHI, except as explicitly allowed by HIPAA. |
§164.510(a)(1&2): Use and disclosure for facility directories - Opportunity to object | Develop and implement policies for including patient information (e.g., name, location, condition, religious affiliation) in facility directories. |
§164.510(a)(3): Uses and disclosures for facility directories in emergency circumstances | Develop and implement policies for including patient information (e.g., name, location, condition, religious affiliation) in facility directories. |
§164.510(b)(1): Permitted uses and disclosures | Establish clear policies for disclosing PHI to family members, close contacts, or others involved in the patient’s care, based on the individual’s consent or inferred agreement. |
§164.510(b)(2): Uses and disclosures with the individual present | Use or disclose PHI only after obtaining the individual’s explicit agreement. |
§164.510(b)(3): Limited uses and disclosures when the individual is not present | Implement a process to disclose PHI in situations where the individual is not present or unable to provide consent due to incapacity or emergency, if you determine the disclosure is in the individual's best interests. |
§164.510(b)(4): Uses and disclosures for disaster relief purposes | Allow the use or disclosure of PHI to public or private entities authorized by law or charter to assist in disaster relief efforts. |
§164.510(b)(5): Uses and disclosures when the individual is deceased | Allow the disclosure of PHI to family members or other individuals involved in the deceased individual’s care or payment for healthcare prior to their death. |
§164.512(a): Uses and disclosures required by law | Define a policy that governs PHI disclosures required by law, ensuring compliance with all applicable legal mandates. |
§164.512(b): Uses and disclosures for public health activities | Define policies for disclosures to public health authorities for disease control, prevention, and other public health purposes. |
§164.512(c): Disclosures about victims of abuse, neglect or domestic violence | Define policies for disclosures of PHI related to victims of abuse, neglect, or domestic violence, including when disclosures are permissible and mandatory. |
§164.512(d): Uses and disclosures for health oversight activities | Define policies for disclosures of PHI to health oversight agencies for audits, investigations, licensure, and other oversight activities. |
§164.512(e): Disclosures for judicial and administrative proceedings | Define policies for disclosing PHI in response to subpoenas, court orders, or other legal requests in judicial and administrative proceedings. |
§164.512(f)(1): Disclosures for law enforcement purposes | Define policies for responding to law enforcement requests for PHI, including subpoenas, court orders, warrants, and emergency disclosures. |
§164.512(f)(2): Disclosures for law enforcement purposes - Identification and location | Define policies for responding to law enforcement requests for PHI, including subpoenas, court orders, warrants, and emergency disclosures. |
§164.512(f)(3): Disclosures for law enforcement purposes - PHI of a possible victim of a crime | Allow disclosure of PHI to law enforcement officials about an individual who is or is suspected to be a victim of a crime, provided the individual agrees to the disclosure. |
§164.512(f)(4): Disclosures for law enforcement purposes - Individual who has died as a result of suspected criminal conduct | Allow disclosure of PHI to law enforcement officials to alert them of an individual's death if there is suspicion that the death resulted from criminal conduct. |
§164.512(f)(5): Disclosures for law enforcement purposes -Crime on premises | Define policies for disclosing PHI to law enforcement when it constitutes evidence of criminal conduct on the covered entity’s premises. |
§164.512(f)(6): Disclosures for law enforcement purposes | Define policies for disclosing PHI to law enforcement when reporting a crime during an emergency situation, ensuring HIPAA compliance. |
§164.512(g): Uses and disclosures about decedents | Permit disclosures of PHI to coroners, medical examiners, and funeral directors as necessary to fulfill their duties, including identifying a deceased person, determining a cause of death, and arranging funeral services. |
§164.512(h): Uses and disclosures for cadaveric organ, eye or tissue donation | Allow the use or disclosure of PHI to organ procurement organizations or entities involved in the procurement, banking, or transplantation of cadaveric organs, eyes, or tissue. |
§164.512(i)(1): Uses and disclosures for research purposes - Permitted uses and disclosures | Define policies for disclosing PHI for research purposes, ensuring HIPAA compliance. |
§164.512(i)(2): Uses and disclosures for research purposes - Documentation of waiver approval | Ensure all research disclosures without individual authorization are approved by an IRB or privacy board, as specified by §164.512(i)(2). |
§164.512(k)(1): Uses and disclosures for specialized government functions - Military | Develop policies permitting PHI disclosures to the Department of Defense or Veterans Affairs for military and veterans' activities, in accordance with §164.512(k)(1). |
§164.512(k)(2): Uses and disclosures for specialized government functions - National security and intelligence activities | Establish policies permitting PHI disclosures to authorized federal officials for national security or intelligence purposes. |
§164.512(k)(3): Uses and disclosures for specialized government functions - Protective services | Develop policies allowing disclosures of PHI to authorized federal officials for protective services or investigations related to the President or other dignitaries. |
§164.512(k)(4): Uses and disclosures for specialized government functions - Medical suitability determinations | A covered entity that is a component of the Department of State may use protected health information to evaluate an individual’s medical suitability. |
§164.512(k)(5): Uses and disclosures for specialized government functions – Correctional institutions | A covered entity may disclose PHI about inmates or individuals in lawful custody to correctional institutions or law enforcement officials if the information is necessary for: |
§164.512(k)(6): Uses and disclosures for specialized government functions – Providing public benefits | Health plans that are government programs providing public benefits may disclose PHI related to eligibility or enrollment to other government agencies administering similar programs, if required or expressly authorized by statute or regulation. |
§164.512(l): Disclosures for workers' compensation | A covered entity may disclose PHI as authorized by laws related to workers' compensation or similar programs that provide benefits for work-related injuries or illnesses, regardless of fault. |
§164.514(f): Uses and disclosures for fundraising | Use or disclose PHI without prior authorization for the purposes of fundraising when that PHI consists of demographic information, dates of service, department of service information, treating physician, outcome information, and/or health insurance status. |
§164.514(g): Uses and Disclosures for underwriting and related purposes | Unless your organization is an issuer of long-term care policies, define requirements for ensuring the health plan does not use or disclose PHI that is genetic information for underwriting purposes. View instructions for defining underwriting requirements. |
§164.530(f): Mitigation | Develop a process to handle and report PHI breaches in compliance with the requirements of HIPAA §164.530(i). |