Nursing & Allied Health Foundations · Foundations

Confidentiality

Want it in plain words first? Jump to Eli explains — the same idea, no jargon.
On this page 9 sections
  1. In 30 seconds
  2. Why this matters
  3. The college version
  4. Eli explains
  5. Worked example
  6. Key takeaway
  7. Quick check
  8. Study tools
  9. Sources & references

In 30 seconds

in healthcare means keeping a patient's health information private — sharing it only with the people who need it to provide care. In the United States, the law sets the floor: names, diagnoses, treatments, and records are protected, and care team members see them on a need-to-know basis. The rules allow sharing for treatment, payment, the patient's own request, and public health. In practice: private conversations, secure screens, careful phone calls. Confidentiality is trust made routine.

Why this matters

Confidentiality is the promise underneath every other skill in this course. Patients share their bodies, histories, habits, and fears with healthcare workers precisely because they expect those details to stay private; without that expectation, people delay care, hide symptoms, and lose trust in the system. Practically, a nurse handles protected information every shift — in conversations, on screens, over the phone — and small habits decide whether that information stays safe. Academically, confidentiality ties together the ethics, informed-consent, and documentation topics that follow, and it introduces the legal floor, HIPAA, that governs U.S. health care. The same habits — checking who is listening, who is watching, who really needs to know — transfer to every setting where sensitive information is handled.

The college version

What confidentiality means

Confidentiality is the practice of keeping a patient's health information private. OpenStax's Fundamentals of Nursing defines confidentiality as safeguarding health information so that it is not disclosed to unauthorized individuals. The related idea of privacy, in the same text, means that a patient's information is kept confidential and shared only with individuals on a need-to-know basis. Why does this carry so much weight? Patients share deeply personal details — symptoms, habits, family history, fears — in order to receive care, and they do it because they expect those details to stay protected. The American Nurses Association, cited by OpenStax, frames this as a responsibility of healthcare workers: patients share sensitive and personal information to receive care, and it is essential that this information stays confidential. Confidentiality is not a rule against talking; it is a rule about who may know.

The HIPAA idea: a national privacy floor

In the United States, the legal foundation for health information privacy is HIPAA — the Health Insurance Portability and Accountability Act, a federal law enacted in 1996. Under HIPAA, the U.S. Department of Health and Human Services issued the Privacy Rule, which established, for the first time, national standards for the protection of certain health information; within HHS, the Office for Civil Rights implements and enforces it. Think of HIPAA as the floor: it guarantees a basic national level of protection, and states and organizations may go further. The rules apply to covered entities — health plans, health care clearinghouses, and health care providers that transmit health information electronically — and to the business associates that work with them. This lesson states the idea simply and does not offer legal advice: HIPAA is the national standard that says health information is protected, and shared only in defined ways.

Protected information: name, diagnosis, treatments, records

The Privacy Rule protects individually identifiable health information in any form — electronic, paper, or oral. That includes common identifiers such as the patient's name, address, birth date, and Social Security number; information about their past, present, or future physical or mental health; the health care provided to them; and payment for that care. Four kinds of information carry most of the weight in daily practice. Name: who the patient is, linked with their health information. Diagnosis: what the patient is being treated for. Treatments: the medications, procedures, and therapies the patient receives. Records: the chart, test results, and notes that hold all of it together. OpenStax adds the practical list — demographic information, medical histories, test results, and health insurance information are all protected health information.

Who may see it, and the exceptions

The basic rule, from HHS's Office for Civil Rights: a may not use or disclose protected health information except as the Privacy Rule permits or requires, or as the patient authorizes in writing. Who, then, may see a patient's information? The care team — the nurses, providers, therapists, and others directly involved in the patient's care — on a need-to-know basis, and only the for the task. The minimum necessary standard is central: reasonable efforts to use, disclose, and request only the smallest amount of protected information needed for the purpose. The physical therapist needs the patient's mobility status, not their full psychiatric history. The Privacy Rule also permits sharing without for defined purposes. Treatment: providing, coordinating, or managing care, including consultation between providers. Payment: billing and reimbursement. Patient request: patients may access their own records, request corrections, and receive an accounting of disclosures. Public health: disclosures to public health authorities authorized by law to prevent or control disease, injury, or disability, including reports of child abuse and communicable-disease exposure. These are the exceptions — defined, limited, and factual. They do not mean information flows freely.

Everyday practice, and the honest framing

Confidentiality lives in small habits. Private conversations: discuss patients where they cannot be overheard — not in elevators, hallways, or crowded waiting areas, where a name plus a diagnosis is a breach. Secure screens: log in with your own credentials, log off after every session, and make sure no one without a reason to know can read what is on your monitor. Careful phone calls: confirm who is calling and what the facility's policy allows before sharing any detail, because a family member is not automatically authorized to receive everything. The honest framing: confidentiality is trust made routine. Patients rarely see the policies; they see whether their information stays safe. Every private conversation, locked screen, and verified caller is a small deposit into that trust — and one careless disclosure can spend it all.

Eli, the EliExplains learning guide

Eli explains

The same idea, in plain words

Explain it like I’m 10

Confidentiality means keeping a patient's health information private. When a patient tells a nurse about symptoms, a diagnosis, or a family history, that information is protected: it goes to the people who need it to give care, and to almost no one else. In the United States, a federal law called HIPAA sets the national floor for this protection. It covers identifiable health information — names, diagnoses, treatments, and records — in any form: paper, electronic, or spoken. Care team members may see it on a need-to-know basis, and only the minimum amount needed. The rules also name the exceptions: sharing for treatment, for payment, at the patient's own request, and for public health purposes such as disease control. In daily practice, confidentiality means holding conversations where they cannot be overheard, keeping screens secure, and being careful on the phone. It is not secrecy for its own sake; it is the privacy patients are promised.

Picture it like this

Think of a locked mailbox. A letter addressed to you is read by you alone — the mail carrier delivers it but does not open it, and the neighbors cannot read it. A patient's health information is like that letter: the care team is the mail carrier, permitted to deliver it to the people on the route who need it — the doctors, nurses, and therapists involved in the care — but not to open it for the street. The lock is the habit: private conversations, secure screens, careful phone calls.

Where the picture stops working

The mailbox comparison is too tidy: in health care, the same information must move freely among many people — specialists, labs, insurers — so confidentiality is not one lock but a set of rules about who may open which envelope and how much of it. And unlike a letter, health information is also a legal record, governed by laws like HIPAA, with defined exceptions for payment and public health.

Worked example

Ms. Delgado is admitted for gallbladder surgery, and nursing student Andre is helping with her care. At the nurses' station, a visitor leans over and asks Andre, 'How is the lady in room 212 doing?' Andre smiles, says he cannot share patient information, and points the visitor to the front desk. Later, he discusses Ms. Delgado's post-op plan with his preceptor in the empty family room, not in the hallway. When Ms. Delgado's daughter calls, Andre transfers the call to the charge nurse, who follows the unit's policy for phone inquiries. On the computer, Andre signs out of the chart every time he steps away, and he opens Ms. Delgado's record only for his assigned tasks — the labs, the medication list, the plan — not the parts of her history he has no reason to see. Nothing about his shift was dramatic; everything he did kept one promise: her information stayed private.

Key takeaway

Confidentiality is trust made routine: keep the patient's health information private, share it only with the care team on a need-to-know basis, and let the defined exceptions — treatment, payment, patient request, public health — guide the rest.

Quick check

3 questions here, of 5 in this lesson’s practice set. Answers stay hidden until you check.

Question 1 of 3foundational

A nursing student is explaining confidentiality to a roommate who knows nothing about health care. Which description is accurate?

Choose an answer, then check it.
Question 2 of 3intermediate

A nurse needs to review a patient's lab results with the provider. Which is the appropriate setting for that conversation?

Choose an answer, then check it.
Question 3 of 3intermediate

A patient is recovering from surgery, and several people are in and out of the unit. Which person may appropriately see the patient's health information?

Choose an answer, then check it.
Practice all 5

Keep learning

Ready to build on this? Continue to the next lesson.

Practice this lesson
Study tools & related lessonsYou’ll learn to · Common mistakes · Easily confused · Key vocabulary · Related

You’ll learn to

  • Define confidentiality in healthcare as keeping a patient's health information private, following the definition in OpenStax's Fundamentals of Nursing.
  • Explain the HIPAA idea simply: the U.S. law that sets the national floor for protecting patients' health information.
  • Identify what counts as protected health information — name, diagnosis, treatments, and records — and give an example of each.
  • Apply the need-to-know principle to decide who may see a patient's information, using an original scenario.
  • Describe the main sharing exceptions — treatment, payment, patient request, and public health — factually.
  • Apply everyday confidentiality habits: private conversations, secure screens, and careful phone calls.

Common mistakes

  • It's okay to discuss a patient in the hallway as long as I don't say the name.

    Even without a name, a diagnosis, room number, or other details can identify a patient to someone listening. Discuss patients in private areas where the conversation cannot be overheard.

  • HIPAA means I can never share any patient information with anyone, ever.

    The rules permit sharing for treatment, payment, the patient's own request, and public health purposes. HIPAA protects information from unauthorized disclosure; it does not freeze the communication that care requires.

  • Only the doctor's notes and the chart are protected.

    Protected health information includes names, diagnoses, treatments, test results, and insurance information, in paper, electronic, or spoken form.

  • Anyone who works in the hospital can look at any patient's chart.

    Access follows the need to know, and the minimum necessary standard limits what may be used or disclosed. Curiosity is not a reason to open a chart.

  • The patient's family member is family, so I can tell them everything.

    Family members may receive information only as the patient's wishes and the facility's policy allow, and patients generally have the opportunity to agree to or object to such disclosures. Check the patient's preference and the policy first.

Easily confused

Privacy vs. Confidentiality

Privacy is the patient's right to have their information kept confidential and shared only on a need-to-know basis; confidentiality is the practice of safeguarding that information from unauthorized disclosure. One is the right; the other is the duty that honors it.

Confidentiality vs. Security

Confidentiality is the obligation to keep information from unauthorized individuals; security is the set of safeguards — passwords, screen locks, encryption — that make that possible. Confidentiality is the promise; security is the lock.

Protected health information vs. De-identified information

Protected health information identifies, or could identify, the individual and is protected; de-identified information has had the identifying elements removed and, per HHS, is not subject to the Privacy Rule's restrictions. Remove the link, and the protection lifts with it.

Key vocabulary

confidentiality
Safeguarding a patient's health information so that it is not disclosed to unauthorized individuals.
privacy
The state of a patient's information being kept confidential and shared only with those who need it for care.
protected health information (PHI)
Individually identifiable health information — such as name, diagnosis, treatments, or records — held or transmitted in any form by a covered entity.
HIPAA
The U.S. federal law, enacted in 1996, under which national standards for protecting the privacy and security of patients' health information were set.
need to know
The principle that patient information is shared only with care team members whose work actually requires it.
minimum necessary
The standard requiring that only the smallest amount of protected health information needed for a purpose be used or disclosed.
covered entity
A health plan, health care clearinghouse, or health care provider that transmits health information electronically, to which HIPAA's rules apply.
authorization
A patient's written permission for a use or disclosure of their health information beyond what the rules permit without it.
public health authority
A government body authorized by law to collect health information in order to prevent or control disease, injury, or disability.

Sources & references

  1. Summary of the HIPAA Privacy Rule — Office for Civil Rights (OCR), U.S. Department of Health and Human Services
  2. Fundamentals of Nursing, Section 9.3: Security, Privacy, and Informatics (OpenStax) — OpenStax (Rice University)
  3. Fundamentals of Nursing, Section 16.3: Legal Dimensions of Care (OpenStax) — OpenStax (Rice University)

EliExplains lessons are original prose written from the open, credible references above. See Copyright & Licensing.

Researched 2026-08-22

Educational content only. It is not medical, legal or professional advice. Found an error? Tell us.