A pharmaceutical company wires $47,000 to a cardiologist for consulting fees. A device manufacturer flies a surgeon to a resort conference and picks up the $3,200 tab. None of this is illegal — but under the US Sunshine Act, every dollar must be reported publicly. And if your organization handles the data behind those payments, you're sitting on a compliance intersection that most privacy officers never see coming.

The US Sunshine Act isn't a HIPAA regulation. But it creates data flows that touch physician identifiers, prescribing patterns, and sometimes protected health information (PHI) in ways that demand your attention. If you work in compliance at a covered entity, a drug manufacturer, or a group purchasing organization, this is your problem too.

What the US Sunshine Act Actually Requires

Officially titled the Physician Payments Sunshine Act — Section 6002 of the Affordable Care Act — this law requires "applicable manufacturers" of drugs, devices, biologics, and medical supplies to report payments and transfers of value made to physicians and teaching hospitals. CMS then publishes the data in its Open Payments database.

We're talking about meals, travel, research grants, royalties, speaker fees, consulting payments, and ownership interests. Every category. Every dollar above $10 (or $100 aggregate per year). Every covered physician.

The data is publicly searchable. Anyone — patients, journalists, attorneys — can look up a specific doctor and see exactly what payments they received from which companies. That transparency is the whole point.

Who Must Report Under the Act

Applicable manufacturers and group purchasing organizations (GPOs) carry the reporting burden. Hospitals and physician practices don't file these reports themselves, but they receive notifications and have a window to review and dispute the data before CMS publishes it.

Here's where it gets tricky for HIPAA-covered entities. If your health system employs physicians who receive reportable payments, you may handle internal tracking data that links physician identifiers to specific drug or device interactions — data that can brush up against patient treatment records.

Where HIPAA and the US Sunshine Act Collide

The Sunshine Act doesn't require the disclosure of PHI. In theory, Open Payments data is about physicians, not patients. But I've seen the messy reality firsthand.

Consider a manufacturer reporting a research payment tied to a clinical trial. The internal records supporting that payment might include patient enrollment data, treatment outcomes, or device implantation records — all of which constitute PHI or ePHI under HIPAA. The payment itself is Sunshine Act territory. The underlying documentation? That's HIPAA territory.

The Risk Most Organizations Miss

Compliance teams often silo these two programs. The Sunshine Act team sits in legal or government affairs. The HIPAA privacy officer sits in IT or compliance. They rarely talk to each other.

That gap creates real exposure. When manufacturer reps request physician payment verification from a hospital, the response sometimes includes more information than necessary — procedure volumes, patient counts, or clinical details that qualify as PHI. I've reviewed internal audit findings where staff emailed spreadsheets containing both payment data and patient identifiers to manufacturer compliance teams with zero encryption.

That's not just a Sunshine Act documentation problem. That's a potential HIPAA breach.

OCR Doesn't Care About Your Silos

The HHS Office for Civil Rights (OCR) has made it clear: the minimum necessary standard applies regardless of why you're sharing information. If your team discloses PHI while fulfilling Sunshine Act data verification requests, you can't claim the payment transparency law as a HIPAA exception.

There is no Sunshine Act carve-out in the HIPAA Privacy Rule. Period.

OCR's enforcement actions archive is full of cases where organizations disclosed PHI in contexts they assumed were "business-related" rather than clinical. The $4.3 million settlement with the University of Texas MD Anderson Cancer Center in 2017 — while about ePHI on unencrypted devices — drove home the principle that PHI protections follow the data, not the department handling it.

The Minimum Necessary Rule in Practice

When a manufacturer asks your employed physician or your administration to verify a reported payment, respond with only the information needed to confirm or dispute the payment record. That means dollar amounts, dates, and payment categories. Not patient names. Not procedure details. Not case volumes tied to identifiable patients.

Train your staff on this explicitly. Most workforce training programs cover minimum necessary in clinical contexts but never mention financial reporting or manufacturer interactions. That's a gap you need to close.

What Is the Open Payments Database?

For anyone searching this question directly: the Open Payments database is the CMS-managed public platform where all US Sunshine Act data is published. It contains records of payments and transfers of value from manufacturers and GPOs to covered physicians (MDs, DOs, dentists, podiatrists, optometrists, chiropractors) and teaching hospitals. The database is updated annually, with a review-and-dispute period before publication. You can search it at openpaymentsdata.cms.gov. No PHI appears in the public data — but the internal records behind those entries are where HIPAA risk lives.

Five Steps to Align Sunshine Act and HIPAA Compliance

Here's what I recommend to every health system and manufacturer compliance team I work with:

  • Map the data flows. Trace exactly how payment data moves between your organization and manufacturers. Identify every point where PHI could be included — intentionally or accidentally.
  • Apply minimum necessary at every handoff. Create templates for Sunshine Act verification responses that strip out any clinical or patient-level detail. Lock them down so staff can't freelance.
  • Cross-train your compliance teams. Your Sunshine Act team needs basic HIPAA literacy. Your HIPAA team needs to understand Open Payments reporting. Invest in comprehensive HIPAA workforce training that addresses real-world scenarios beyond clinical settings.
  • Encrypt everything. Any Sunshine Act verification communication containing physician identifiers and financial data should be encrypted in transit and at rest. If that data accidentally includes PHI, encryption is your safety net under the breach notification rule.
  • Audit annually. Pull a sample of Sunshine Act communications from the past year. Check for PHI leakage. Document findings. This is exactly the kind of evidence OCR wants to see if they ever come knocking.

Breach Notification: When Sunshine Act Mistakes Trigger HIPAA Obligations

Let's say your revenue cycle analyst emails a manufacturer a spreadsheet verifying speaker payments for six physicians. Buried in the file is a tab with patient procedure codes linked to those physicians' cases. The manufacturer's compliance analyst opens it, realizes the mistake, and calls you.

That's an impermissible disclosure of PHI to a non-business-associate entity. Under the HIPAA Breach Notification Rule, you now need to conduct a risk assessment. If the PHI wasn't encrypted and you can't demonstrate a low probability of compromise, you're looking at individual notifications, potentially HHS reporting, and possible OCR scrutiny.

All because two compliance programs weren't talking to each other.

The Training Gap That Creates the Exposure

Most HIPAA training programs teach staff about clinical disclosures — don't leave charts on the counter, don't discuss patients in the elevator, log out of the EHR. That's necessary but insufficient.

Your finance team, your government affairs team, your legal department — anyone who touches Sunshine Act data — needs to understand what PHI looks like and why it can never ride along with payment verification data. A targeted module in your HIPAA training program that covers non-clinical disclosure scenarios can close this gap faster than any policy memo.

I've watched organizations spend months perfecting their Open Payments submissions while completely ignoring the HIPAA risk embedded in the process. Don't be that organization.

Looking Ahead: Expanded Reporting and Growing Risk

CMS has expanded the categories of covered practitioners under Open Payments over the years, adding physician assistants, nurse practitioners, clinical nurse specialists, certified registered nurse anesthetists, and certified nurse midwives. More covered practitioners means more data, more verification requests, and more opportunities for PHI to slip through the cracks.

As the scope of the US Sunshine Act's reporting requirements grows, so does the surface area for HIPAA risk. The organizations that treat these as two separate compliance programs will keep getting surprised. The ones that integrate them — shared training, shared audits, shared data governance — will stay ahead.

Your Sunshine Act compliance and your HIPAA compliance aren't two separate problems. They're two sides of the same data governance challenge. Treat them that way, and you'll protect your organization from a collision that most people don't see until it's already too late.