The Privacy Rule, from the top

One question governs the whole rule: may this information move, to this person, for this reason. The permission structure, the individual rights, the administrative machinery, and the four places an ABA clinic gets it wrong.

Last verified: 2026-07-12

The Security Rule is about systems. The Privacy Rule is about a question, asked over and over, all day, in every clinic in America:

May this information move, to this person, for this reason?

That is the whole rule. Everything in it is either an answer to that question, a right the individual holds over the answer, or the machinery that makes you capable of answering it consistently.

Which is why the common mental model is wrong. The Privacy Rule is not a rule about secrecy. It is a rule about permission, and the difference is the entire subject. Secrecy would mean saying no. The rule mostly says yes, under conditions, and then holds you to the conditions.

The permission structure

The rule is closed by default. You may use or disclose PHI only where the rule permits or requires it (45 CFR 164.502(a)). Everything else needs the individual’s written authorization.

“The Privacy Rule is not a rule about secrecy. It is a rule about permission, and the difference is the entire subject”

Inside that fence, the permissions run in a rough order of how routine they are:

Treatment, payment, and health care operations (45 CFR 164.506). This is most of your day and it requires no authorization and no signed consent form. Delivering therapy, supervising, coordinating with another provider, billing, checking eligibility, requesting authorization from a payer, training your staff, running quality review. Clinics routinely believe they need a signed consent to do these things. They do not, and the belief causes real harm: staff hesitate over an ordinary clinical handoff because a form is missing.

Disclosures to the individual themselves, which are not merely permitted but in some cases required (45 CFR 164.502(a)(2)).

The agree-or-object situations (45 CFR 164.510). Family and others involved in care, informally, with an opportunity to object. In an ABA clinic this is the grandparent at pickup and the aunt in the living room.

The twelve no-authorization situations (45 CFR 164.512). Required by law, public health, abuse reporting, health oversight, judicial proceedings, law enforcement, decedents, research, averting a serious and imminent threat, and the rest. Each has conditions, and the conditions are the point.

And everything else needs an authorization (45 CFR 164.508), with required elements: a specific description, who discloses, who receives, the purpose, an expiration, a signature, and the three statements (revocation, conditioning, redisclosure).

Minimum necessary, and its holes

When PHI does move, you must make reasonable efforts to limit it to the minimum needed for the purpose (45 CFR 164.502(b); operationalized at 45 CFR 164.514(d)).

The exceptions are as important as the rule, because clinics apply the standard where it does not belong and skip it where it does. It does not apply to disclosures to or requests by a provider for treatment, to disclosures to the individual, to uses or disclosures under an authorization, to disclosures to HHS, or to disclosures required by law.

So: sending a complete record to a treating provider is fine. Sending a complete record to a payer who asked for an authorization form is not. The clinic that redacts a clinical handoff and then faxes a full chart for a billing question has the standard exactly backwards.

The individual rights, which is where enforcement lives

Four rights, and a clinic that runs them well is most of the way to a defensible privacy program.

Access (45 CFR 164.524). The individual, or the parent as personal representative, may inspect and obtain a copy of PHI in the designated record set. Thirty days, one 30-day extension, in the form requested where readily producible, for a reasonable cost-based fee only, and never a retrieval fee. This is the most enforced right in HIPAA and the subject of OCR’s longest-running initiative.

Amendment (45 CFR 164.526). Sixty days, with a right to a statement of disagreement if you deny.

Accounting of disclosures (45 CFR 164.528). Six years back, excluding TPO, which means in practice it captures the 164.512 disclosures: the subpoenas, the reports. Keep the log as you go; it cannot be reconstructed.

Restrictions and confidential communications (45 CFR 164.522). Mostly optional to grant, with one exception you must honor, covered below.

The four places an ABA clinic gets it wrong

One: psychotherapy notes. The single most consequential misunderstanding in this field. The definition excludes session times, modalities and frequencies, test results, and summaries of diagnosis, treatment plan, symptoms, functional status, and progress (45 CFR 164.501). Read against what an ABA clinic actually writes, nearly everything is excluded. Your session notes are almost certainly not psychotherapy notes, they sit in the designated record set, and withholding them from a parent on that basis is not a protection. It is a right-of-access violation, in the exact area OCR enforces most.

Two: sharing outside TPO without an authorization. Sending session data to a school district. Using a clip in a training video or a conference talk. Posting a success story. None of these is treatment, payment, or operations, and each needs a written authorization with the required elements (45 CFR 164.508). Clinics routinely rely on the intake consent, which does not cover them.

Three: incidental disclosures with nothing behind them. The rule tolerates incidental disclosures (the sibling who glances at the screen, the name overheard in a waiting room) but only where you applied minimum necessary and reasonable safeguards (45 CFR 164.502(a)(1)(iii); 45 CFR 164.530(c)). The tolerance is conditional. A clinic with no safeguards has not earned it, and the same glance becomes evidence that nothing was ever in place.

Four: the self-pay restriction, which is mandatory. Individuals may request restrictions, and you may usually decline. But there is one you must honor: no disclosure to a health plan for payment or operations purposes where the individual paid for the item or service in full, out of pocket, and no law requires the disclosure (45 CFR 164.522(a)(1)(vi)). The family that pays cash and asks you not to bill or tell their insurer has a legal right, not a favor to request. Very few clinics have a process for it.

The administrative machinery

The rule’s back half is the part that makes the front half real (45 CFR 164.530): a named privacy official, training on your policies, safeguards including limits on incidental disclosures, a complaint process, sanctions applied to workforce members who violate policy, mitigation of harm you learn about, no retaliation, no waiver of rights as a condition of treatment, written policies, and six-year documentation.

Read that list next to the Security Rule’s administrative safeguards and notice how much of it is the same program under a different name. That is the point everyone misses: you do not run a privacy program and a security program. You run one program that answers to both rules.

The clarification that matters most in this field

Nothing in the Privacy Rule prevents you from making a mandated report of suspected child abuse or neglect. The rule explicitly makes room for it (45 CFR 164.512(b) and (c)).

Say that plainly in your training, because clinicians do hesitate, and the hesitation is the most dangerous confusion HIPAA causes in behavioral health. A privacy rule that stopped a clinician from protecting a child would be an indefensible rule. It does not, and it never has.

The short version

  • The rule is a closed permission structure: PHI may move only where the rule permits or requires it, and everything else needs an authorization.
  • Treatment, payment, and health care operations cover most of what a clinic does day to day, without authorization and without a signed consent.
  • Minimum necessary governs almost everything except treatment disclosures, disclosures to the individual, and authorized disclosures.
  • The individual rights are where enforcement actually lands: access within 30 days is OCR's longest-running initiative.
  • The four ABA failures: psychotherapy notes misunderstood, authorizations skipped for non-TPO sharing, incidental disclosures with no safeguards behind them, and the self-pay restriction nobody knows is mandatory.

This article is educational information about the HIPAA regulations, not legal advice. It describes what the rules say; it does not tell you what to do about your specific situation, and reading it does not create an attorney-client or consultant-client relationship. Regulations change, and enforcement positions change with them. For advice on your clinic, talk to a qualified professional.

Sources

Permission, on the record.

Who asked, what you sent, under what authority, and when: the Privacy Rule turns on answers you either have or do not. WiseUpHIPAA holds them from your clinic's real operations, honestly.