When Can You Break Patient Confidentiality Under HIPAA?
The challenge with answering when can you break patient confidentiality under HIPAA is that HIPAA does not define patient confidentiality, yet the HIPAA Privacy Rule “authorizes” multiple uses and disclosures of Protected Health Information that might be classed as breaches of patient confidentiality under other definitions of the term.
The earliest recorded reference to “patient confidentiality” is the famous oath attributed to Hippocrates in the 4th century BCE – “What I may see or hear in the course of the treatment or even outside of the treatment in regard to the life of men, which on no account one must spread abroad, I will keep to myself, holding such things shameful to be spoken about.”
This reference has been used as the basis for subsequent definitions of patient confidentiality -several of which conflate patient confidentiality with protecting informational privacy. For example, the World Health Organization defines confidentiality as “the obligation of not disclosing data about information delivered in confidence to unauthorized third parties”.
The AMA’s Opinions on Patient Confidentiality
Due to the difficulty in defining patient confidentiality in a single sentence, the American Medical Association (AMA) has published extended “opinions” on what patient confidentiality consists of in different scenarios. In the context of explaining when can you break patient confidentiality under HIPAA, the most relevant opinion states:
“In general, patients are entitled to decide whether and to whom their personal health information is disclosed. However, specific consent is not required in all situations”. Source: AMA Opinion 3.2.1
The opinion continues by listing the types of disclosures for which specific consent is not required. These are limited to disclosures for providing care and for health care operations, disclosures required by law, and disclosures to third parties to mitigate the risk of harm to the patient or other identifiable individual(s). The opinion concludes:
“For any other disclosures, physicians should obtain the consent of the patient (or authorized surrogate) before disclosing personal health information”. Source: AMA Opinion 3.2.1
What HIPAA Says about Patient Confidentiality
HIPAA does not say anything about patient confidentiality because the purpose of HIPAA’s Administrative Simplification Requirements is to safeguard the privacy and security of Protected Health Information (PHI). In addition, the HIPAA definition of confidentiality only applies to the HIPAA Security Rule and PHI in electronic format:
“Confidentiality means the property that data or information is not made available or disclosed to unauthorized persons or processes”. (45 CFR §164.304).
To explain the difference between how HIPAA defines confidentiality and AMA’s opinion on patient confidentiality, if a digital image of a tattoo can identify a patient and is maintained in the same designated record set as health, treatment, or payment information relating to the patient, it is protected by HIPAA and must not be “made available or disclosed to unauthorized persons or processes.”
However, if the patient shares the personal reason for getting the tattoo or the personal significance of the tattoo with their physician, HIPAA only protects the confidentiality of the information if the nature or sensitivity of the information is considered medically important and the information is included in a protected dedicated record set.
Under AMA’s opinion on patient confidentiality, non-medical information shared by the patient should not be further disclosed without the consent of the patient unless it is necessary for providing care or for health care operations, required by law, or to mitigate the risk of harm. Under HIPAA’s definition of confidentiality, the information can be freely disclosed if it does not qualify for – or assume – protected status.
When Else Can You Break Patient Confidentiality Under HIPAA?
In addition to being able to break patient confidentiality under HIPAA when information about a patient does not assume protected status, 45 CFR §164.512 of the HIPAA Privacy Rule lists numerous scenarios in which it is permissible to use or disclose information about a patient – without their consent – when the information does have protected status. These include:
- For public health activities – including to conduct post-marketing surveillance on FDA-regulated products.
- To an employer – to support the employer’s OSHA reporting requirements for work related injuries and illnesses.
- To a school – if the school requires evidence of a prospective student’s immunization status.
- For health oversight activities – including when PHI is disclosed to determine compliance with civil rights laws.
- To law enforcement officers – to help locate a suspect, fugitive, material witness, or missing person.
- For research purposes – when an Institutional Review Board authorizes disclosures of identifiable PHI.
It is also possible to break patient confidentiality under HIPAA when an incidental disclosure of PHI is secondary to a primary disclosure, or when consent is implied but not actually obtained – for example, if a patient is accompanied to an appointment by a family member and the patient does not object to disclosures of PHI with the family member present.
Why (and How) Physicians Should Explain When Can Patient Confidentiality be Broken
Each year, HHS’ Office for Civil Rights receives more than 30,000 complaints alleging violations of the HIPAA Privacy Rule. Around two-thirds of complaints are dismissed because “the activity described does not violate HIPAA Rules”. For example, when a physician has disclosed PHI in circumstances in which the HIPAA Privacy Rule permits such a disclosure.
Many healthcare organizations encourage patients to submit complaints directly to them rather than to HHS’ Office for Civil Rights. It is not known how many patients submit complaints this way, but if the proportion of unjustified complaints is similar, organizations may dedicate many resources explaining when patient confidentiality can be broken under HIPAA.
Physicians could save their organizations a lot of time and money by explaining when can patient confidentiality be broken under HIPAA, and the best way to do this is by including all possible uses and disclosures of PHI in the HIPAA Notice of Privacy Practices. This includes uses for health care operations, and an explanation of what health care operations are.
Although many patients do not fully read or understand a HIPAA Notice of Privacy Practices, it is a lot easier to refer a complainant to the Notice of Privacy Practices than it is to explain the relevant section of the HIPAA Privacy Rule that allows a physician to break patient confidentiality under HIPAA. Healthcare organizations requiring more explanation about this concept, or who require help phrasing a HIPAA Notice of Privacy Practices to reduce privacy complaints, are advised to seek HIPAA compliance advice.

