Describe the general principles for use and disclosure under the Privacy Rule.

Description should include

  • Basic Principle
    • defines and limits the circumstances under which PHI may be used or disclosed by covered entities
    • states that the covered entity may not disclose PHI except
      • as the Privacy Rule permits or requires
      • as the individual authorizes in writing

  • Required Disclosure
    • states that the covered entity must disclose PHI in only two situations
      • individual or individual’s representative (e.g., attorney)
      • HHS when it is undertaking a compliance investigation, review, or enforcement action.

Teacher Resource:

Minimum Necessary Requirements (https://www.hhs.gov/sites/default/files/ocr/privacy/hipaa/understanding/coveredentities/minimumnecessary.pdf Links to an external site.), Office of Civil Rights, U.S. Department of Health and Human Services

Process/Skill Questions:

  • What are the minimum requirements for general principles for use and disclosure?
  • What are acceptable methods of transferring PHI?
  • What individuals or entities have the right to access PHI?