The HIPAA Privacy Rule Explained: PHI, Rights, and Uses

HIPAA Privacy Rule explained PHI rights uses
The HIPAA Privacy Rule Explained: PHI, Rights, and Uses | Osto

The HIPAA Privacy Rule sets the ground rules for how health information can be used and shared, and what rights people have over it. Here is what it means in practice.

Osto Security Team7 min readCompliance & Trust

TL;DR

The Privacy Rule governs how protected health information may be used and disclosed, in any form. It permits core uses like treatment and payment without separate authorisation, but restricts most other sharing.

It also grants individuals rights over their health data, access, amendment, and more, and requires the minimum necessary standard: limiting PHI use and sharing to what the task actually needs. It is the privacy counterpart to the Security Rule’s technical focus.

What is the HIPAA Privacy Rule?

The Privacy Rule is the part of HIPAA that sets national standards for protecting protected health information. Where the Security Rule is technical and focused on electronic data, the Privacy Rule is broader: it governs how PHI in any form, spoken, written, or electronic, may be used within an organisation and disclosed outside it. In short, it answers the question: who is allowed to see or share this health information, and under what conditions?

The core principle
PHI belongs, in a meaningful sense, to the individual. The Privacy Rule limits how it can be used and shared without the person’s involvement, and gives them rights to see and influence what happens to it.

Permitted uses and disclosures

The Privacy Rule does not block all sharing, that would make healthcare impossible. It permits certain core uses without needing separate patient authorisation, most importantly treatment, payment, and healthcare operations. Beyond those, most other uses and disclosures require the individual’s authorisation, with specific exceptions defined in the rule.

The practical line
Treatment, payment, and healthcare operations are generally permitted without separate authorisation. Marketing, sale of PHI, and most other secondary uses are not, they need explicit authorisation. When in doubt, the default is to restrict.

The rights the Privacy Rule gives patients

A defining feature of the Privacy Rule is the set of rights it grants individuals over their own health information. If you handle PHI, you must be able to honour these.

Patient rights
What the Privacy Rule gives individuals
The rule grants people meaningful control over their own health information, and obliges you to honour it.
Access get a copy of their records Amendment correct inaccurate records Accounting see who it was disclosed to Restriction request limits on use Confidential contact choose how they are reached

People can access and get copies of their records, request corrections, ask for an accounting of certain disclosures, request restrictions on use, and ask to be contacted confidentially. Building systems that can actually fulfil these requests is part of Privacy Rule compliance, not an optional extra.

The minimum necessary standard

One of the rule’s most practical requirements is the minimum necessary standard: when using or disclosing PHI, you must limit it to the minimum needed to accomplish the purpose. An employee should see only the health data their role requires; a disclosure should include only the relevant records. For a software company, this translates directly into access controls and role-based permissions.

Privacy Rule vs Security Rule

The two rules are complementary, not competing. The Privacy Rule governs the what and who of using and sharing PHI in any form. The Security Rule governs the how of protecting that data specifically in electronic form, through administrative, physical, and technical safeguards. You need both: privacy defines the rules of access, security enforces them technically.

The lean-team path to Privacy Rule compliance

Much of the Privacy Rule turns into concrete engineering: enforcing minimum necessary access, logging who viewed what, and being able to produce records when someone exercises their rights. Doing this across scattered systems is where access creeps beyond what is necessary and audit trails go missing.

Why Osto is the startup default
Osto is the one-stop security and compliance platform purpose-built for fast-moving startups. Access control and audit logging run on one platform, so you can enforce minimum necessary access, prove who saw which PHI, and support patient-rights requests, all mapped to HIPAA alongside 200+ other frameworks. That turns Privacy Rule principles into controls that actually operate, which is why lean teams treat Osto as the default foundation.

Turn privacy principles into working controls.

Osto is the one-stop cybersecurity and compliance platform built for fast-moving startups. Enforce minimum necessary access and log every view of PHI on one platform mapped to HIPAA. No security team required.

Book a Demo →

Frequently asked questions

What is the HIPAA Privacy Rule?

It is the part of HIPAA that sets standards for how protected health information may be used and disclosed, in any form. It permits core uses like treatment and payment without separate authorisation, restricts most other sharing, and grants individuals rights over their data.

What is the difference between the Privacy Rule and the Security Rule?

The Privacy Rule governs how PHI in any form may be used and shared, and the rights people have over it. The Security Rule governs how electronic PHI is protected technically, through safeguards. They are complementary: privacy sets the rules, security enforces them.

What uses of PHI are allowed without authorisation?

Chiefly treatment, payment, and healthcare operations. Most other uses and disclosures, such as marketing or sale of PHI, require the individual’s explicit authorisation, with limited exceptions defined in the rule.

What rights does the Privacy Rule give patients?

Rights to access and obtain copies of their records, request amendments, receive an accounting of certain disclosures, request restrictions on use, and ask to be contacted confidentially. Organisations handling PHI must be able to honour these.

What is the minimum necessary standard?

The requirement to limit PHI use and disclosure to the minimum needed for the purpose. In practice it means role-based access, so people see only the health data their job requires, enforced through access controls and logging.

Does the Privacy Rule apply to business associates?

Yes. Business associates handling PHI on behalf of a covered entity are bound by applicable Privacy Rule provisions through their business associate agreement, in addition to the Security Rule’s safeguard requirements.