Not Everything Is a Violation — But Most People Don't Know Where the Line Is

A nurse at a mid-size hospital once told me she was afraid to confirm a patient's name to a family member standing at the front desk. She'd heard so many horror stories about HIPAA fines that she froze. That fear cost the family 40 minutes of confusion — and it was completely unnecessary.

Understanding what information can be shared without violating HIPAA is just as important as knowing what you can't share. The law was never designed to shut down communication. It was designed to put guardrails around it. Yet in my experience, the average healthcare worker overestimates the restrictions and underestimates the permissions.

This post breaks down the specific categories of information sharing that HIPAA actually allows. If you work at a covered entity — hospital, clinic, health plan, clearinghouse — or a business associate, this is your practical guide to lawful disclosure.

HIPAA's Core Framework: The "Minimum Necessary" Standard

Before we get into the specifics, you need to understand one principle that governs almost every permissible disclosure: the minimum necessary standard. Under 45 CFR § 164.502(b), covered entities must make reasonable efforts to limit PHI access to the minimum amount needed for the purpose at hand.

That doesn't mean "share nothing." It means "share only what's relevant." A billing department doesn't need a patient's psychiatric notes to process an insurance claim. A referring physician doesn't need a full family history to schedule a follow-up appointment.

Once you internalize this standard, the rest of the rules make a lot more sense.

Treatment, Payment, and Health Care Operations — The Big Three

The HIPAA Privacy Rule carves out three broad categories where PHI can flow without patient authorization. These are outlined in HHS guidance on disclosures for treatment, payment, and operations, and they cover the vast majority of day-to-day information sharing in healthcare.

Treatment

Providers can share PHI with other providers for treatment purposes. Your primary care doctor can send lab results to your cardiologist. A hospital ER can fax records to a specialist across town. No authorization form required.

This also applies to consultations. If a surgeon calls a radiologist to discuss imaging findings on a specific patient, that conversation is permissible. The key is that the disclosure serves the patient's care.

Payment

Covered entities can share PHI with health plans and clearinghouses to get paid. This includes submitting claims, verifying eligibility, obtaining prior authorizations, and coordinating benefits. Your billing team sends diagnosis codes, procedure codes, and patient identifiers to insurers every single day — and that's exactly what HIPAA allows.

Health Care Operations

This is the category most people forget. Quality assessment, compliance audits, workforce training, credentialing, fraud detection — all of these qualify as health care operations under the Privacy Rule. PHI can be used internally for these purposes without patient consent, as long as the minimum necessary standard applies.

For example, a compliance officer reviewing patient records during an internal audit isn't violating HIPAA. Neither is a quality improvement team analyzing outcomes data. These activities keep your organization running and keep patients safer.

What About Sharing With the Patient Themselves?

The Right of Access

Here's one that trips up more organizations than you'd expect. Under HIPAA, patients have an almost absolute right to access their own PHI. You can — and must — share it with them upon request. The only narrow exceptions involve psychotherapy notes and certain information compiled for litigation.

This right was reinforced dramatically when OCR launched its HIPAA Right of Access Initiative in 2019. Since then, OCR has settled numerous enforcement actions over access delays. Cignet Health paid $4.3 million in penalties for denying 41 patients access to their records. That's not ancient history — it's a warning.

If a patient asks for their records, provide them. You have 30 days (with one 30-day extension if needed). Dragging your feet is one of the most common — and most avoidable — violations in the industry.

Disclosures That Don't Require Patient Authorization

Beyond treatment, payment, and operations, HIPAA identifies several other situations where you can share PHI without written authorization. These are detailed in 45 CFR Part 164, Subpart E, and they include:

  • Public health activities: Reporting communicable diseases to state health departments, reporting adverse events to the FDA, and workplace medical surveillance.
  • Victims of abuse, neglect, or domestic violence: Disclosures to government authorities when required or authorized by law.
  • Health oversight activities: Sharing with agencies like HHS during audits, investigations, or licensure inspections.
  • Judicial and administrative proceedings: Responding to court orders or subpoenas that meet specific conditions.
  • Law enforcement: Limited disclosures to identify suspects, locate fugitives, or report certain types of wounds and injuries as required by state law.
  • Coroners, medical examiners, and funeral directors: Sharing PHI to identify a deceased person or determine cause of death.
  • Organ and tissue donation: Disclosures to procurement organizations for transplant coordination.
  • Research: When an Institutional Review Board or privacy board has granted a waiver of authorization.
  • Serious threat to health or safety: Sharing PHI to prevent or lessen a serious and imminent threat — this includes notifying law enforcement about a credible threat of violence.
  • Workers' compensation: Disclosures as authorized by workers' comp laws.

Each of these has specific conditions and limitations. "Permissible" does not mean "unlimited." But the point stands: HIPAA has far more allowances than most people realize.

De-Identified Data: The Information That Isn't PHI at All

If you strip data of all 18 identifiers listed in 45 CFR § 164.514(b) — names, dates, geographic data, Social Security numbers, medical record numbers, and so on — the result is de-identified data. HIPAA does not restrict the use or disclosure of de-identified data. At all.

Organizations use de-identified datasets for population health research, marketing analytics, and public reporting without any HIPAA implications. The catch is that de-identification must be done properly, either through the "Safe Harbor" method (removing all 18 identifiers) or the "Expert Determination" method (a qualified statistician certifies the risk of re-identification is very small).

Getting this wrong is expensive. Make sure your data scientists and analysts understand the requirements before they assume a dataset is clean.

The Facility Directory and Informal Permissions

Remember that nurse who was afraid to confirm a patient's name? Here's the rule she didn't know.

HIPAA allows covered entities to maintain a facility directory that includes a patient's name, location in the facility, general condition (such as "stable" or "critical"), and religious affiliation. This information can be shared with people who ask for the patient by name. Clergy can receive all four data points; other visitors can receive the first three.

The patient must be informed and given an opportunity to object. But absent an objection, this sharing is perfectly lawful. It's how hospitals have operated for decades — HIPAA just formalized the process.

What You Still Cannot Share Without Authorization

To understand what information can be shared without violating HIPAA, you also need to know where the hard lines are. Written patient authorization is required for:

  • Most marketing communications
  • Sale of PHI
  • Psychotherapy notes (with very few exceptions)
  • Disclosures that don't fit any of the permissible categories above

Violating these rules carries real consequences. In 2023, OCR settled with Yakima Valley Memorial Hospital for $240,000 after 23 security guards accessed patient medical records without authorization. That was a workforce snooping case — but the underlying principle is the same. Unauthorized access is unauthorized disclosure.

Your Workforce Needs to Know These Rules — Not Just Your Compliance Team

Here's the pattern I see over and over: the compliance officer understands HIPAA permissible uses perfectly. Everyone else is guessing. Front desk staff refuse to give information they're allowed to share. Clinicians avoid coordinating care because they're unsure about the rules. And sometimes, staff share PHI they shouldn't because nobody told them where the real boundaries are.

The fix is workforce training that goes beyond "protect PHI" and actually teaches your team when and how they can share information. Our HIPAA training catalog covers these exact scenarios — treatment disclosures, public health reporting, patient access requests, and facility directory rules — with role-specific modules that match how your staff actually works.

Training your entire workforce isn't optional, either. The Privacy Rule at 45 CFR § 164.530(b) requires it. And OCR has cited training failures in enforcement actions repeatedly.

Quick Reference: Can You Share This Without Authorization?

This section answers the question directly for anyone scanning quickly:

  • PHI for treatment coordination between providers? Yes.
  • PHI for submitting insurance claims? Yes.
  • PHI for internal quality improvement? Yes, with minimum necessary limits.
  • Patient's own records to the patient? Yes — it's required upon request.
  • De-identified data for research? Yes, if properly de-identified.
  • Patient name and room number to a visitor who asks by name? Yes, unless the patient has objected.
  • PHI for marketing emails? No — authorization required.
  • Psychotherapy notes to an insurer? No — authorization required.

Stop Guessing and Start Getting It Right

HIPAA violations happen in two directions. Sharing too much gets you on OCR's enforcement page. Sharing too little disrupts care, frustrates patients, and slows down your operations. Both are failures of education.

If your staff can't confidently answer the question "what information can be shared without violating HIPAA," you have a training gap that puts your organization at risk. Start closing it today with structured, role-specific HIPAA compliance training that gives your team clear rules — not just fear.

The line between compliant and non-compliant isn't blurry. It's just poorly taught.