A hospital receptionist in Texas called a patient's employer to confirm an upcoming surgery date. She thought she was being helpful. That single phone call triggered an OCR investigation, a corrective action plan, and months of mandatory staff retraining. The receptionist didn't know she'd violated one of the most foundational laws in American healthcare. If you're asking what are the privacy rules of HIPAA, that story is exactly where the answer starts — with everyday moments where protected health information leaves your organization without authorization.

I've spent years helping covered entities untangle their privacy obligations. The Privacy Rule isn't a single sentence or a poster on a break room wall. It's a detailed federal regulation that governs how your organization uses, discloses, and safeguards every piece of individually identifiable health information it touches. And OCR — the Office for Civil Rights at HHS — enforces it with real teeth.

What Are the Privacy Rules of HIPAA, Exactly?

The HIPAA Privacy Rule is codified at 45 CFR Part 164, Subpart E. It establishes national standards for the protection of individually identifiable health information — what the industry calls protected health information (PHI). PHI covers everything from a patient's name linked to a diagnosis, to billing records, to verbal conversations about treatment in a hallway.

The Privacy Rule applies to three categories of covered entities: health plans, healthcare clearinghouses, and healthcare providers who transmit health information electronically. It also extends to business associates — vendors and contractors who handle PHI on your behalf.

Here's the core principle: PHI cannot be used or disclosed unless the Privacy Rule specifically permits or requires it, or the individual provides written authorization. That's the default. Everything else flows from there.

The Minimum Necessary Standard

One of the most misunderstood provisions is the minimum necessary standard. When your organization uses or discloses PHI, it must make reasonable efforts to limit the information to the minimum amount needed for the purpose. Your billing department doesn't need psychotherapy notes to process a claim. Your front desk doesn't need lab results to schedule an appointment.

I've seen organizations treat PHI like an open buffet — everyone on staff accessing full medical records because "they might need it." That's a Privacy Rule violation waiting to happen. Role-based access controls aren't optional. They're the minimum necessary standard in action.

Patient Rights Under the Privacy Rule

The Privacy Rule grants patients a specific set of rights over their health information. These aren't suggestions — they're federally enforceable requirements:

  • Right to access: Patients can request copies of their medical records, and you must provide them within 30 days (with a possible 30-day extension).
  • Right to amend: Patients can request corrections to their PHI if they believe it's inaccurate.
  • Right to an accounting of disclosures: Patients can ask for a log of who their PHI has been shared with outside of treatment, payment, and operations.
  • Right to request restrictions: Patients can ask you to limit certain uses or disclosures, though you're not always required to agree.
  • Right to confidential communications: A patient can ask you to contact them at a specific number or address, and you must accommodate reasonable requests.

Denying or ignoring these rights has led to significant OCR enforcement actions. In 2019, Bayfront Health St. Petersburg paid $85,000 to settle a case where a patient was denied timely access to her medical records. That same year, Korunda Medical paid $85,000 for the same type of violation. OCR launched its Right of Access Initiative specifically to crack down on this pattern.

The $2.175 Million Mistake: When Privacy Failures Compound

Sentara Hospitals agreed to a $2.175 million settlement with OCR in 2019 after mailing PHI — including patient names, account numbers, and dates of service — to wrong addresses. The issue affected 577 patients. But the penalty wasn't just about the mailing error. Sentara initially claimed the incident wasn't a breach because the mailings didn't include medical diagnoses. OCR disagreed. Billing information linked to a patient is PHI. Period.

That case illustrates something I tell every organization I work with: you don't get to define what PHI is based on what feels sensitive. The Privacy Rule defines it. Your job is to follow the definition, not create your own.

Permitted Uses and Disclosures: Where Organizations Get Confused

The Privacy Rule allows use and disclosure of PHI without patient authorization in specific circumstances. The most common are:

  • Treatment: Sharing PHI between providers involved in a patient's care.
  • Payment: Submitting claims to insurers, verifying coverage, billing.
  • Healthcare operations: Quality assessment, training, compliance activities, auditing.

Beyond treatment, payment, and operations (TPO), the Privacy Rule permits disclosures for public health activities, law enforcement purposes, judicial proceedings, and certain research scenarios — all with specific conditions attached. If you're disclosing PHI outside of TPO, you need to know exactly which provision authorizes it.

This is where verbal disclosures become a minefield. A nurse discussing a patient's condition within earshot of other patients. A therapist confirming a client's appointment to a family member who calls. These are real Privacy Rule violations that happen daily. Our course on Verbal Disclosures: Watch What You Say walks your workforce through the exact scenarios where spoken PHI crosses the line.

Every covered entity must provide patients with a Notice of Privacy Practices (NPP). This document explains how your organization uses and discloses PHI, what the patient's rights are, and how to file a complaint. You must make a good-faith effort to obtain a written acknowledgment from the patient that they received it.

I've reviewed NPPs that were last updated in 2013. That's a problem. HHS has issued guidance updates, and state laws have evolved. Your NPP needs to reflect your actual current practices — not what you were doing a decade ago.

Workforce Training Isn't Optional — It's a Privacy Rule Requirement

Section 164.530(b) of the Privacy Rule requires covered entities to train all workforce members on their privacy policies and procedures. "Workforce" doesn't just mean employees. It includes volunteers, trainees, and anyone under your organization's direct control — whether or not they're paid.

Training must happen at onboarding and whenever material changes occur. Yet I consistently see organizations running a single training session at hire and never revisiting it. That gap is exactly where violations breed.

Nurses face unique privacy challenges in clinical workflows — bedside conversations, shared workstations, EHR access across units. That's why role-specific training like our HIPAA Training for Nurses course exists. Generic compliance videos don't address what a charge nurse encounters at 2 a.m. during shift change.

Mental and behavioral health providers operate under even stricter privacy constraints, particularly around psychotherapy notes and substance use disorder records governed by 42 CFR Part 2. Our HIPAA Training for Mental & Behavioral Health course covers these layered requirements in detail.

Breach Notification: What Happens When the Privacy Rule Fails

When a Privacy Rule violation results in an impermissible use or disclosure of PHI, the breach notification rule kicks in. You must notify affected individuals within 60 days. If the breach affects 500 or more individuals, you must also notify HHS and prominent media outlets in the affected state.

Smaller breaches — those affecting fewer than 500 individuals — must still be logged and reported to HHS annually. There's no "too small to report" exception. The HHS Breach Notification Rule page lays out every requirement.

The Risk Assessment Exception

Not every impermissible disclosure triggers a breach notification. If your organization conducts a four-factor risk assessment and determines there's a low probability that the PHI was compromised, you can document that conclusion and avoid notification. But "low probability" requires documented analysis — not a gut feeling from your privacy officer.

Administrative Requirements Most Organizations Overlook

The Privacy Rule mandates several administrative safeguards that go beyond training:

  • Designate a Privacy Officer: Someone must be responsible for developing and implementing your privacy policies.
  • Implement complaint procedures: Patients and workforce members must have a way to report privacy concerns without retaliation.
  • Sanction policy: Your organization must apply appropriate sanctions against workforce members who violate privacy policies.
  • Maintain documentation: Privacy policies, training records, NPPs, and complaint logs must be retained for six years.

These aren't aspirational goals. They're auditable requirements. When OCR shows up — and they do, often triggered by a single patient complaint — they ask for documentation first. If you can't produce it, you've already lost.

Your Organization Already Knows the Stakes

If you've read this far, you understand that what are the privacy rules of HIPAA isn't an academic question. It's an operational one. Every email, every phone call, every EHR login, every hallway conversation either complies with the Privacy Rule or doesn't.

The organizations that stay out of OCR's enforcement spotlight are the ones that treat privacy as a daily discipline, not an annual checkbox. They train role-specifically. They audit consistently. They document relentlessly.

Start with the gaps you already suspect exist. Then close them — before someone else finds them for you. Explore our full HIPAA training catalog to build a workforce that understands what the Privacy Rule actually demands.