Health Administration · Law and Policy

Patient Privacy

Want it in plain words first? Jump to Eli explains — the same idea, no jargon.
On this page 9 sections
  1. In 30 seconds
  2. Why this matters
  3. The college version
  4. Eli explains
  5. Worked example
  6. Key takeaway
  7. Quick check
  8. Study tools
  9. Sources & references

In 30 seconds

Patient privacy is the principle that people control who sees their health information, and is the duty of everyone entrusted with that information to protect it. These ideas are older than any statute, because patients only speak candidly when they trust that what they say stays protected. HIPAA gives the principle legal force, but the everyday work is judgment: share only the minimum necessary, for a legitimate purpose, with people who need to know.

Why this matters

Confidentiality is not a bureaucratic formality; it is a precondition for care. A patient who fears exposure may hide a symptom, skip a test, or avoid treatment entirely, which harms both that person and public health. Administrators set the routines that make privacy real or hollow: who can open a chart, how staff talk in hallways, what a front desk says out loud. Getting the principle right protects patients, sustains the trust an organization runs on, and keeps the institution clear of the legal and reputational damage that follows a breach. It also frames the more technical topics ahead, because every rule about records, systems, and disclosures exists to serve this underlying duty.

The college version

Why confidentiality is the foundation of care

Long before any privacy statute, medicine treated confidentiality as a professional duty. The reason is practical as much as ethical: diagnosis and treatment depend on honest disclosure, and patients disclose honestly only when they trust that what they reveal will be protected. Someone worried that a mental-health note, a positive test, or a substance-use history could reach an employer, a family member, or a neighbor may downplay symptoms, decline screening, or avoid care altogether. That silence produces worse outcomes for the individual and, when it happens at scale, weaker public health surveillance and slower response to outbreaks. Confidentiality, then, is not a courtesy layered on top of good care; it is a condition that makes candid clinical conversation possible. It also underpins institutional trust. A clinic or hospital that leaks information loses the confidence of the community it serves, and rebuilding that confidence is far harder than protecting it in the first place. HHS's Office for Civil Rights frames the federal Privacy Rule around exactly this tension: the goal is to protect individuals' health information while still allowing the flow of information needed to deliver high-quality care and protect public health. Privacy is not secrecy for its own sake; it is control exercised so that information moves for legitimate purposes and stops at the edge of them. Administrators inherit this duty and translate it into daily operations, because principles that are never built into workflow do not survive contact with a busy floor.

Privacy, confidentiality, and security are not synonyms

These three words are often used interchangeably, but they name different things, and confusing them leads to muddled policy. Privacy is the individual's interest in controlling who may access information about them and for what purposes; it is a right that belongs to the patient. Confidentiality is the corresponding duty of the people and organizations entrusted with that information not to disclose it improperly; it is an obligation that belongs to the clinician, the coder, the billing clerk, and the administrator. Security is the set of administrative, physical, and technical safeguards that actually protect information, especially electronic information, from unauthorized access, alteration, or loss, whether the threat is a hacker, a lost laptop, or a curious employee. The distinctions matter in practice. A hospital can have excellent security, with encryption and strong passwords, and still violate confidentiality if a staff member with legitimate access looks up a celebrity's chart out of curiosity. Conversely, a well-meaning promise of confidentiality is empty if weak security lets records leak. Privacy is the goal, confidentiality is the promise, and security is the mechanism. Under HIPAA these map roughly onto the Privacy Rule and the Security Rule, but you do not need the full regulatory machinery, covered here only by reference, to reason clearly about the underlying concepts. Keeping them separate helps an administrator diagnose where a failure actually occurred and design the right fix rather than the reflexive one.

Protected health information and the minimum necessary principle

The information the law protects is called protected health information, or PHI: individually identifiable health information held or transmitted by a covered entity or its business associate, in any form. That means not only diagnoses and lab results but also the fact that a person is a patient, their appointment times, and their billing records, when tied to identifiers such as name, address, dates, or a medical record number. Information that has been properly de-identified, so it can no longer reasonably be linked to a person, falls outside this protection, which is why de-identified data can be used more freely for research and analysis. The organizing idea for everyday handling of PHI is the : when using or disclosing PHI, or requesting it, a covered entity must make reasonable efforts to limit the information to the minimum needed to accomplish the purpose. A billing clerk resolving a claim needs the codes and dates of service, not the full clinical narrative; a scheduler needs the appointment, not the biopsy result. There is a crucial exception that trips people up: minimum necessary does not apply to disclosures to a health care provider for treatment, because clinicians caring for a patient need the full picture. Alongside minimum necessary sits the framework of permitted uses and disclosures. HIPAA lets covered entities use and share PHI without separate patient for treatment, payment, and health care operations, often abbreviated TPO, and for a defined set of public-purpose disclosures such as those required by law or to report certain abuse. Uses outside those permitted categories, such as most marketing or releasing psychotherapy notes, generally require the patient's written authorization. The detailed rule structure belongs to the companion HIPAA topic; here the point is conceptual: information should move for a legitimate reason, in the smallest amount that reason requires.

Patient rights, special protections, and everyday practice

Privacy is not only a set of restrictions on the organization; it also grants affirmative rights to the patient. Individuals have the right to inspect and obtain a copy of their own health information in the designated record set, to request an amendment when they believe something is inaccurate or incomplete, to receive an accounting of certain disclosures the organization has made, to request restrictions and confidential communications, and to be given a notice of privacy practices describing how their information may be used and what rights they hold. These rights turn privacy from a promise the institution makes about the patient into something the patient can actively exercise. Baseline HIPAA is a floor, not a ceiling. Some categories of information carry stricter protection. Records of substance use disorder treatment from federally assisted programs are governed by a separate federal regulation, , which historically has required patient consent for many disclosures that HIPAA would permit, precisely because the stigma and legal exposure around addiction make confidentiality especially consequential; a 2024 final rule aligned parts of Part 2 more closely with HIPAA while preserving its heightened protections. State laws frequently add their own stricter requirements for sensitive information such as HIV status, mental health, genetic data, and minors' care, and when a state law is more protective it generally governs. The everyday practice of privacy is mostly unglamorous: logging into systems under your own credentials and never sharing them, accessing only the records your job requires, positioning screens away from waiting areas, lowering your voice at the front desk, verifying a caller's identity before releasing anything, and disposing of paper securely. Most breaches are not sophisticated attacks but ordinary lapses, and it is the administrator's routines, training, and culture, more than any single rule, that keep the principle intact.

Eli, the EliExplains learning guide

Eli explains

The same idea, in plain words

Explain it like I’m 10

When you tell a doctor something private, you are trusting them to keep it safe. Privacy means it is your information and you get a say in who sees it. Confidentiality is the promise the doctor and everyone at the clinic make to protect it. Security is the locks, passwords, and careful habits that actually keep it protected. The main rule for the people who handle your information is simple: only look at what you need to do your job, and only share the smallest amount needed, with people who have a real reason to see it. You also have rights, like getting a copy of your own records and asking to fix a mistake. Some information, like treatment for addiction, gets extra-strong protection because it could hurt someone if it leaked.

Picture it like this

Think of your health information like the contents of your house. Privacy is your right to decide who gets a key. Confidentiality is the promise a trusted house-sitter makes not to snoop or invite others in. Security is the actual locks, alarm, and window latches. A house-sitter you trust still should only go into the rooms they need to water the plants, not wander through every drawer, and that is the minimum necessary idea.

Where the picture stops working

The house analogy breaks down because health information can be copied and shared instantly and invisibly, unlike objects in a house, so a single careless disclosure can spread in ways a physical break-in cannot. It also understates that many people are legitimately allowed in at once, and that some sharing, such as billing a claim, is required rather than optional.

Worked example

A patient named Dana is admitted for a procedure, and over one afternoon her information moves through several hands. The surgeon and floor nurse read her full chart, including her medication list and history, because minimum necessary does not restrict information shared for treatment. The billing specialist pulls only the diagnosis codes, procedure codes, and dates of service to submit the claim to Dana's insurer; that is a payment use, and she deliberately does not open the operative note because she does not need it. A quality analyst later reviews de-identified data from many patients to track infection rates, a health care operations use that no longer identifies Dana at all. That evening a neighbor calls the front desk asking how Dana is doing; the clerk confirms nothing and does not even acknowledge that Dana is a patient, because status and presence are themselves PHI and the neighbor has no permitted reason to receive it. Each step reflects the same principle applied differently: information flows for a legitimate purpose, limited to the minimum that purpose requires, and stops at the boundary of that purpose.

Key takeaway

Privacy is the patient's right to control their health information, confidentiality is the duty to protect it, and security is the safeguards that enforce it; in daily practice, handle PHI on a need-to-know basis, share only the minimum necessary for a legitimate purpose, and respect the stricter protections that apply to especially sensitive records.

Quick check

3 questions here, of 5 in this lesson’s practice set. Answers stay hidden until you check.

Question 1 of 3intermediate

Which statement best captures why confidentiality is considered foundational to health care rather than merely a legal formality?

Choose an answer, then check it.
Question 2 of 3intermediate

A hospital uses strong encryption and unique passwords, yet an employee with legitimate system access opens a neighbor's chart out of curiosity. Which concept has primarily been violated?

Choose an answer, then check it.
Question 3 of 3advanced

Under the minimum necessary principle, which situation is an EXCEPTION where the limit does not apply?

Choose an answer, then check it.
Practice all 5

Keep learning

Ready to build on this? Continue to the next lesson.

Practice this lesson
Study tools & related lessonsYou’ll learn to · Common mistakes · Easily confused · Key vocabulary · Related

You’ll learn to

  • Explain the ethical and practical reasons confidentiality is foundational to health care.
  • Distinguish privacy, confidentiality, and security as three related but separate concepts.
  • Define protected health information (PHI) and apply the minimum necessary principle.
  • Describe, at a conceptual level, the permitted uses and disclosures for treatment, payment, and operations and the core patient rights over records.
  • Identify special protections, such as 42 CFR Part 2 for substance use disorder records and stricter state laws, that go beyond baseline HIPAA.

Common mistakes

  • Treating privacy, confidentiality, and security as the same thing.

    Privacy is the patient's right to control access, confidentiality is the duty to protect what you were entrusted with, and security is the safeguards that enforce it. A breach can occur in one without the others failing, and naming the right one guides the right fix.

  • Believing that having legitimate access means you may look at any record.

    Access must be tied to a job-related need. Opening a coworker's, a relative's, or a celebrity's chart out of curiosity violates confidentiality even when your account technically can reach it; the minimum necessary and need-to-know standard still applies.

  • Thinking only clinical details like diagnoses count as protected health information.

    PHI also includes identifiers tied to health information, such as the fact that someone is a patient, their appointment times, and billing records. Confirming to an outside caller that a person is here can itself be an improper disclosure.

  • Assuming HIPAA is the maximum protection and the same everywhere.

    HIPAA is a floor. Substance use disorder records under 42 CFR Part 2 and many state laws covering HIV, mental health, genetics, and minors are stricter, and the more protective rule generally governs.

  • Applying the minimum necessary limit to doctors treating the patient.

    Minimum necessary does not apply to disclosures to a health care provider for treatment. Clinicians caring for a patient need the complete picture; the limit targets payment, operations, and other non-treatment uses.

Easily confused

Privacy vs. Confidentiality

Privacy is the patient's right to control who accesses their information; confidentiality is the duty of those entrusted with it not to disclose it improperly. One is held by the patient, the other by the organization and its staff.

Confidentiality vs. Security

Confidentiality is the obligation to protect information; security is the concrete administrative, physical, and technical safeguards that carry out that obligation, especially for electronic records.

Baseline HIPAA protection vs. 42 CFR Part 2 and stricter state law

HIPAA sets a national floor for handling PHI; substance use disorder records and many sensitive categories under state law receive heightened protection, and the more protective rule generally controls.

Key vocabulary

Privacy (in health care)
An individual's interest in controlling who may access information about them and for what purposes; a right that belongs to the patient.
Confidentiality
The duty of a person or organization entrusted with someone's information not to disclose it improperly; an obligation held by clinicians, staff, and administrators.
Security (in health care)
The administrative, physical, and technical safeguards that protect information, especially electronic information, from unauthorized access, alteration, or loss.
Protected health information (PHI)
Individually identifiable health information held or transmitted by a covered entity or business associate in any form, including the fact of being a patient and billing data when linked to identifiers.
Minimum necessary principle
The requirement to make reasonable efforts to limit the use, disclosure, or request of PHI to the least information needed to accomplish the purpose; it does not apply to disclosures for treatment.
Treatment, payment, and health care operations (TPO)
The three broad purposes for which a covered entity may use and disclose PHI without a separate patient authorization.
Authorization
A patient's written permission required before a covered entity may use or disclose PHI for purposes outside those the rule already permits, such as most marketing or releasing psychotherapy notes.
De-identified information
Health information from which identifiers have been removed so it can no longer reasonably identify a person; because it is not PHI, it can be used and shared more freely.
Notice of privacy practices (NPP)
A document a covered entity must provide describing how it may use and disclose PHI and what rights the individual has over that information.
42 CFR Part 2
A separate federal regulation giving heightened confidentiality protection to substance use disorder treatment records from federally assisted programs, historically requiring patient consent for many disclosures HIPAA would allow.

Sources & references

  1. 45 CFR Part 160 - General Administrative Requirements (HIPAA applicability, definitions, and preemption) — U.S. Government Publishing Office / Office of the Federal Register (eCFR)
  2. 45 CFR Part 164 Subpart E - Privacy of Individually Identifiable Health Information — U.S. Government Publishing Office / Office of the Federal Register (eCFR)
  3. 42 CFR Part 2 - Confidentiality of Substance Use Disorder Patient Records — U.S. Government Publishing Office / Office of the Federal Register (eCFR)
  4. Confidentiality of Substance Use Disorder (SUD) Patient Records; Final Rule, 89 FR 12472 — U.S. Department of Health and Human Services (Office for Civil Rights and SAMHSA), via the Federal Register
  5. Summary of the HIPAA Privacy Rule — U.S. Department of Health and Human Services, Office for Civil Rights

EliExplains lessons are original prose written from the open, credible references above. See Copyright & Licensing.

Researched 2026-08-19

Educational content only. It is not medical, legal or professional advice. Found an error? Tell us.