Access, Disclosure, Privacy & Security
This domain governs who may see protected health information (PHI), how it is released, and how it is safeguarded. The HIPAA Privacy and Security Rules and the HITECH breach-notification requirements are the backbone.
The Privacy Rule: TPO, authorization, and minimum necessary
The HIPAA Privacy Rule permits use and disclosure of PHI for treatment, payment, and health care operations (TPO) without patient authorization. Uses outside TPO — such as most marketing, the sale of PHI, and most research — require a valid authorization (or an IRB/Privacy Board waiver for research). The minimum necessary standard requires limiting PHI to the least amount needed, but it does not apply to disclosures for treatment, disclosures to the individual, or uses required by law. Correct release-of-information decisions turn on knowing these boundaries.
Security safeguards and breach notification
The HIPAA Security Rule requires administrative, physical, and technical safeguards for electronic PHI — including access controls, audit logs, encryption, and workforce training. Under the HITECH Breach Notification Rule, affected individuals must be notified without unreasonable delay and no later than 60 days after discovery of a breach of unsecured PHI; breaches affecting 500 or more people also trigger prompt notice to HHS and to prominent local media, while smaller breaches are logged and reported to HHS annually. HIM frequently coordinates the breach-response process and access-audit reviews.