Privacy: Know These PHI Disclosure Essentials

Subscribe or sign in to view the full article.

Note:  The following article synopsis was NOT provided by AAPC. It was created by Find-A-Code/innoviHealth.

Article Overview

This article explains how HIPAA privacy obligations continue to apply during a public health emergency, including emergency situations tied to disease outbreaks and other disruptions. It summarizes general OCR guidance on protected health information disclosures, the roles of covered entities and business associates, and the broad categories of circumstances where disclosure without authorization may be permitted. The piece is intended for healthcare providers, compliance staff, and privacy professionals who need a high-level refresher on emergency privacy rules and patient confidentiality expectations.

Why This Topic Matters

Privacy practices can change operationally during emergencies, but HIPAA obligations do not disappear. Understanding the general boundaries of permitted disclosures helps organizations respond to public health needs while continuing to protect patient privacy.

Article Sections

  1. Emergency Privacy Reminder

    Introduces the article’s focus on privacy policy review during emergency situations, natural disasters, and disease outbreaks. It frames the discussion around public health emergency conditions and patient privacy obligations.

  2. HHS Public Health Emergency and OCR Bulletin

    Summarizes the public health emergency context and the federal privacy guidance issued in response. It covers the general relationship between the emergency declaration, HIPAA, and OCR’s clarification of privacy expectations.

  3. When PHI May Be Shared Without Authorization

    Outlines the broad categories of circumstances discussed in the guidance where disclosures may be permitted without patient authorization. The section groups the discussion around treatment, public health activities, family and friends, and imminent threat situations.

  4. Caution on Patient Privacy

    Highlights the reminder that emergency-related public health reporting does not eliminate privacy protections. It reinforces that confidentiality considerations still apply even when disclosures are allowed in limited circumstances.

What You Will Learn

  • How HIPAA privacy obligations continue during a public health emergency
  • What types of OCR guidance are discussed for emergency disclosures
  • Which general categories of situations may permit disclosure without authorization
  • Why privacy protections still matter during public health reporting and outbreak response

Who Should Read This

  • Healthcare providers
  • Practice managers
  • Compliance staff
  • Privacy officers
  • Revenue cycle and administrative staff involved in HIPAA compliance

Subscribe or sign in to view the full article.

Keep pace with evolving Medicare regulations — and onboard your team — with timely analysis of critical updates interpreted in an easy-to-follow, easy-to-apply format. Your subscription to TCI's Medicare Compliance & Reimbursement Alert will equip you to navigate code and guideline changes, CCI edits, and revisions to modifiers, payer policies, the fee schedule, OIG target areas, and more.

  • Current newsletters added each month
  • Fully searchable archives - over 4200 articles
  • ALL years/issues back to 2003 organized by year and issue
  • Codes mentioned in articles are linked to Code Information pages
  • Code Information pages link back to related articles

This feature is currently unavailable for online purchase. For more information, please call 801-770-4203 or Contact Us.

Thank you for choosing Find-A-Code, please Sign In to remove ads.

Aimee- AI -powered coding assistant - Try it now for Free Would you like Aimee - AI
to help you with this?