The HIPAA Privacy Rule governs who may see protected health information, what patients can demand about their own records, and when consent is required.
The short answer
The HIPAA Privacy Rule sets national standards for the use and disclosure of protected health information in any form, paper, electronic or spoken. It defines what a covered entity may do with PHI without asking, what needs written authorisation, and the rights individuals hold over their own records. Where the Security Rule is about protecting data, the Privacy Rule is about permission.
A useful split: the Privacy Rule asks whether you should have the data. The Security Rule asks whether you are protecting what you have.
On this page
Permitted uses and disclosures
When authorisation is required
Anything outside the permitted categories needs a signed authorisation. To be valid it has to be specific about what is disclosed and to whom, state an expiry, explain the right to revoke, and be written plainly. A blanket consent buried in terms of service does not qualify.
| Activity | Authorisation needed? |
|---|---|
| Sending records to a specialist for treatment | No |
| Submitting a claim to an insurer | No |
| Quality improvement and internal audit | No, healthcare operations |
| Marketing a third-party product to patients | Yes |
| Selling PHI to a data broker | Yes, and the authorisation must state payment is involved |
| Research using identifiable records | Yes, unless waived by an IRB or privacy board |
Individual rights
| Right | What it means in practice |
|---|---|
| Access | A copy of their records, generally within 30 days, in the electronic format requested where feasible |
| Amendment | Ask for corrections. You may refuse, but must record the disagreement |
| Accounting of disclosures | A list of certain disclosures made over the previous six years |
| Restriction | Request limits on use. Mandatory when they paid out of pocket in full |
| Confidential communications | Ask to be contacted by a specific channel or at a specific address |
| Notice of privacy practices | A plain-language notice of how PHI is used and what rights apply |
The right of access drives most enforcement
Failing to provide records on time is among the most frequently penalised HIPAA violations, and the fines are routine rather than exceptional. If you build health software, an export path for a patient’s full record is a compliance feature, not a nice-to-have.
What compliance looks like
Role-based access
People see only what their job requires, which is the minimum necessary standard made operational.
A privacy officer
A named individual accountable for the policies and for handling complaints.
Records of disclosures
Logging that can answer an accounting request without a manual reconstruction.
How Osto supports it
Privacy is enforced through access. Osto provides identity and access management, role-based control and audit logging that records who reached which record and when, plus file access DLP to catch PHI leaving through channels it should not. The compliance platform maps those controls to HIPAA and generates the policy documentation the rule expects.
Free security assessment
Privacy enforced through access, not policy alone
Role-based access, audit logging and DLP turn a privacy policy into something you can actually demonstrate.
Get a free security assessment Book a platform walkthroughAccess recorded · Policies generated · One platform, everything
Frequently asked questions
What is the HIPAA Privacy Rule?
The national standard governing use and disclosure of protected health information in any form. It defines what covered entities may do with PHI without authorisation, what requires consent, and the rights individuals hold over their records.
What is the difference between the Privacy Rule and the Security Rule?
The Privacy Rule covers PHI in every form and governs permission: who may access it and for what. The Security Rule covers electronic PHI only and governs protection: the safeguards that keep it secure.
What is the TPO exception?
Treatment, payment and healthcare operations. Disclosures for these three purposes are permitted without patient authorisation, which covers most routine sharing between providers and payers.
How long do you have to respond to a records request?
Generally 30 days, with one 30-day extension available if the individual is notified of the reason. Delays are among the most commonly enforced violations.
Does the Privacy Rule apply to business associates?
Partly. Business associates are bound by the use and disclosure limits in their BAA and by the minimum necessary standard, and must support covered entities in honouring individual rights.

