When the Code Goes Hospital-Wide, HIPAA Doesn't Clock Out
A category 4 hurricane is bearing down on the Gulf Coast. Your hospital's emergency operations center activates. Patient transfers begin. Staff from neighboring facilities show up to help. Reporters call. Family members flood the lobby demanding information. And somewhere in the chaos, someone on your team shares a patient's medical record with the wrong person.
Emergency management in hospital settings creates the exact conditions where HIPAA violations thrive — urgency, confusion, unfamiliar staff, and enormous pressure to act fast. I've seen hospitals assume that a declared disaster somehow suspends the Privacy Rule. It doesn't. And that assumption has cost organizations millions.
This post walks you through how HIPAA actually works during emergencies, what the HHS Secretary can waive (and what they can't), and the specific training your workforce needs before the next crisis hits.
The Myth That Emergencies Suspend HIPAA
Every time a major disaster strikes, I hear the same thing from hospital administrators: "HIPAA is waived during emergencies, right?" The answer is more nuanced than a simple yes or no — and getting it wrong is dangerous.
The HHS Secretary can issue a limited waiver under Section 1135 of the Social Security Act during a presidentially declared emergency. But that waiver is narrow. It only applies to certain provisions of the Privacy Rule, only to hospitals in the emergency area, and only for a limited time — typically 72 hours from when the hospital activates its disaster protocol.
Even during an active 1135 waiver, hospitals cannot abandon core patient privacy protections. The waiver covers specific requirements like obtaining patient consent before speaking with family or friends involved in care, honoring opt-out requests for facility directories, and distributing a Notice of Privacy Practices. Everything else — the minimum necessary standard, the Security Rule, breach notification — stays fully in force.
What Actually Gets Waived (and What Doesn't)
Here's a quick breakdown your compliance team should tape to the wall of your emergency operations center:
- Potentially waived (during an active 1135 waiver): Requirement to get patient agreement before sharing PHI with family/friends involved in care. Requirement to honor opt-out of facility directory. Requirement to distribute Notice of Privacy Practices at admission.
- Never waived: The Security Rule for ePHI. Minimum necessary standard for disclosures. Breach notification requirements. Business associate agreement requirements. Patients' right to request restrictions on disclosures.
The full details are available on the HHS emergency preparedness guidance page.
Real Enforcement Actions That Started During Crises
OCR doesn't pause investigations because a hospital was under stress. In fact, some of the most consequential enforcement actions trace directly back to emergency or high-pressure situations where organizations let their guard down.
Consider the $4.3 million settlement with the University of Texas MD Anderson Cancer Center in 2018. While not a natural disaster case, the underlying violations involved unencrypted ePHI on portable devices — exactly the kind of vulnerability that explodes during emergency operations when staff grab laptops, tablets, and thumb drives and rush between locations.
Or look at the $2.14 million settlement with St. Joseph Health in 2016, where PHI was publicly accessible on the internet for over a year. The root cause wasn't malice. It was a configuration error that went undetected because proper safeguards and monitoring weren't in place. During emergencies, when IT teams are stretched thin and temporary systems get spun up, this exact scenario becomes far more likely.
OCR's resolution agreements page is a sobering read for any hospital administrator who thinks good intentions provide legal cover.
Emergency Management in Hospital Settings: The PHI Danger Zones
I've consulted with hospitals on emergency preparedness for over a decade, and certain PHI exposure points come up again and again during drills and real activations.
Patient Tracking and Transfer
When you're evacuating a facility or receiving surge patients, tracking boards go up — sometimes on whiteboards in open areas. Patient manifests get printed and handed to transport teams. Digital tracking systems get accessed by staff who don't normally have authorization. Every one of these is a PHI disclosure that needs to comply with the minimum necessary standard.
Volunteer and Temporary Staff
During large-scale emergencies, hospitals accept help from physicians, nurses, and support staff from other organizations. These individuals may not have completed your HIPAA workforce training. They may not have signed your confidentiality agreements. They may not understand your facility's specific policies around PHI access. This is a massive gap.
Media and Public Information
Reporters want names. They want conditions. They want to know if a public figure was admitted. Your public information officer needs crystal-clear protocols on what can be shared, what requires patient authorization, and what falls under the facility directory rules.
Communication System Failures
When primary communication systems go down, staff improvise. They text PHI on personal phones. They use unsecured email. They share patient information over radio channels. Every one of these workarounds can constitute a breach of the Security Rule.
How Should Hospitals Handle PHI During a Disaster?
This is the question I get asked most often, so here's the direct answer. Under the HIPAA Privacy Rule, a covered entity can disclose PHI without patient authorization during a disaster in these specific circumstances:
- Treatment: PHI can be shared with other healthcare providers for treatment purposes, just like during normal operations.
- Public health activities: Disclosures to public health authorities for disease surveillance, injury reporting, or other public health functions are permitted.
- To prevent serious and imminent threat: PHI can be shared with anyone who can reasonably prevent or lessen a serious and imminent threat to health or safety.
- To disaster relief organizations: The Privacy Rule allows covered entities to share PHI with organizations like the American Red Cross for disaster relief coordination, even without patient authorization — but only for the purpose of notifying family members of the patient's location and condition.
- Facility directory: If a patient hasn't objected (or is incapacitated and can't object), the hospital can confirm to callers that the patient is at the facility and share their general condition.
Outside these categories, standard authorization requirements apply — emergency or not.
The Training Gap That Keeps Getting Hospitals in Trouble
Here's what frustrates me most: hospitals spend millions on emergency management infrastructure — generators, satellite phones, decontamination tents — but allocate almost nothing to training their workforce on how HIPAA applies when those systems activate.
Your emergency management plan likely has detailed sections on incident command, triage protocols, and resource allocation. But does it include a section on PHI handling during surge operations? Does it address how temporary staff get onboarded for HIPAA compliance? Does it define who authorizes disclosures to disaster relief organizations?
If the answer to any of those questions is no, you have a gap that OCR can and will act on.
The HHS enforcement guidance makes clear that workforce training is not optional — it's a regulatory requirement under 45 CFR § 164.530(b). And that training needs to cover the specific scenarios your staff will face, including emergencies. Generic annual training that never mentions disaster situations leaves your organization exposed.
Our HIPAA training catalog includes scenario-based modules that cover exactly these situations — PHI handling during patient transfers, communication with disaster relief organizations, and managing temporary workforce access to ePHI.
Building HIPAA Into Your Emergency Operations Plan
After working with hospitals across the country on this issue, here's the framework I recommend.
1. Designate a Privacy Officer Role in Your Incident Command
Your incident command structure should include someone responsible for real-time HIPAA compliance decisions. This person monitors PHI disclosures, advises the public information officer, and manages access provisioning for temporary staff.
2. Pre-Position PHI Handling Protocols
Don't wait until the emergency to figure out your rules. Create laminated quick-reference cards for staff that summarize what PHI can be shared, with whom, and under what circumstances. Include contact information for your privacy officer and legal counsel.
3. Train Before the Disaster, Not After
Emergency HIPAA training needs to happen during calm times. Include HIPAA scenarios in your tabletop exercises and full-scale drills. If your team hasn't practiced making PHI disclosure decisions under pressure, they'll default to either sharing too much or sharing nothing — both of which create problems.
Our workforce training programs can be integrated into your existing emergency preparedness curriculum, giving your staff the specific knowledge they need before the next activation.
4. Audit Your Emergency Communication Systems
Every communication channel you plan to use during emergencies — radios, backup email systems, mobile devices, satellite phones — needs to be evaluated for ePHI security. If your backup communication plan involves unencrypted channels, you need compensating controls documented and tested.
5. Plan for the After-Action HIPAA Review
After every emergency activation, conduct a specific review of PHI handling. Were there unauthorized disclosures? Did temporary staff access records they shouldn't have? Were any devices lost? This review feeds directly into your breach risk assessment process and demonstrates good faith to OCR if questions arise later.
The Bottom Line for Hospital Leaders
Emergency management in hospital environments will always involve tension between speed and privacy. But that tension doesn't have to result in violations. The hospitals that weather emergencies without HIPAA incidents are the ones that planned, trained, and drilled specifically for PHI protection under crisis conditions.
Your emergency preparedness plan is incomplete if it doesn't address HIPAA. Your workforce training is inadequate if it doesn't include disaster scenarios. And your incident command structure has a blind spot if no one owns privacy compliance during activations.
The next disaster won't wait for your compliance program to catch up. Start closing these gaps now — explore the HIPAA training options at HIPAACertify and build privacy protection into every layer of your emergency response.