May a covered entity use or disclose protected health information for litigation? May a covered entity use or disclose protected health information for litigation?
May a covered entity use or disclose protected health information for litigation?
Answer:
A covered entity may use or disclose protected health information as permitted or required by the Privacy Rule, see 45 CFR 164.502(a)
(PDF); and, subject to certain conditions the Rule typically permits
uses and disclosures for litigation, whether for judicial or
administrative proceedings, under particular provisions for judicial and
administrative proceedings set forth at 45 CFR 164.512(e) (GPO), or as part of the covered entity’s health care operations, 45 CFR 164.506(a) (PDF).
Depending on the context, a covered entity’s use or disclosure of
protected health information in the course of litigation also may be
permitted under a number of other provisions of the Rule, including uses
or disclosures that are:
- required by law (as when the court has ordered certain disclosures),
- for a proceeding before a health oversight agency (as in a contested licensing revocation),
- for payment purposes (as in a collection action on an unpaid claim), or
- with the individual’s written authorization.
Where a covered entity is a party to a legal proceeding, such as
a plaintiff or defendant, the covered entity may use or disclose
protected health information for purposes of the litigation as part of
its health care operations. The definition of “health care operations”
at 45 CFR 164.501
(GPO) includes a covered entity’s activities of conducting or arranging
for legal services to the extent such activities are related to the
covered entity’s covered functions (i.e., those functions that make the
entity a health plan, health care provider, or health care
clearinghouse), including legal services related to an entity’s
treatment or payment functions. Thus, for example, a covered entity that
is a defendant in a malpractice action or a plaintiff in a suit to
obtain payment may use or disclose protected health information for such
litigation as part of its health care operations. The covered entity,
however, must make reasonable efforts to limit such uses and disclosures
to the minimum necessary to accomplish the intended purpose. See 45 CFR 164.502(b) , 164.514(d).
Where the covered entity is not a party to the proceeding, the
covered entity may disclose protected health information for the
litigation in response to a court order, subpoena, discovery request, or
other lawful process, provided the applicable requirements of 45 CFR 164.512(e) (GPO) for disclosures for judicial and administrative proceedings are met.
| National Pharmacy Chain Extends Protections for PHI on Insurance Cards Covered Entity: Pharmacies Issue: Impermissible Uses and Disclosures; Safeguards A pharmacy employee placed a customer's insurance card in another customer's prescription bag. The pharmacy did not consider the customer's insurance card to be protected health information (PHI). OCR clarified that an individual's health insurance card meets the statutory definition of PHI and, as such, needs to be safeguarded. Among other corrective actions to resolve the specific issues in the case, the pharmacy revised its policies regarding PHI and retrained its staff. The revised policies are applicable to all individual ...read more |
| Private Practice Ceases Conditioning of Compliance with the Privacy Rule Covered Entity: Private Practice Issue: Conditioning Compliance with the Privacy Rule A physician practice requested that patients sign an agreement entitled “Consent and Mutual Agreement to Maintain Privacy.” The agreement prohibited the patient from directly or indirectly publishing or airing commentary about the physician, his expertise, and/or treatment in exchange for the physician’s compliance with the Privacy Rule. A patient’s rights under the Privacy Rule are not contingent on the patient’s agreement with a covered entity. A covered entity’s obligation to comply with all requirements of the Privacy Rule ...read more |
| Physician Revises Faxing Procedures to Safeguard PHI Covered Entity: Health Care Provider Issue: Safeguards A doctor's office disclosed a patient's HIV status when the office mistakenly faxed medical records to the patient's place of employment instead of to the patient's new health care provider. The employee responsible for the disclosure received a written disciplinary warning, and both the employee and the physician apologized to the patient. To resolve this matter, OCR also required the practice to revise the office's fax cover page to underscore a confidential communication for the intended recipient. The office informed all its employees of the ...read more |
| Large Medicaid Plan Corrects Vulnerability that Resulted in Disclosure to Non-BA Vendors Covered Entity: Health Plans Issue: Impermissible Uses and Disclosures; Safeguards A municipal social service agency disclosed protected health information while processing Medicaid applications by sending consolidated data to computer vendors that were not business associates. Among other corrective actions to resolve the specific issues in the case, OCR required that the social service agency develop procedures for properly disclosing protected health information only to its valid business associates and to train its staff on the new processes. The new procedures were instituted in Medicaid offices and independent ...read more |
|
September 2026
| Su | Mo | Tu | We | Th | Fr | Sa |
| | 1 | 2 | 3 | 4 | 5 |
| 6 | 7 | 8 | 9 | 10 | 11 | 12 |
| 13 | 14 | 15 | 16 | 17 | 18 | 19 |
| 20 | 21 | 22 | 23 | 24 | 25 | 26 |
| 27 | 28 | 29 | 30 |
Blog Home
Newest Blog Entries
1/21/25 Understanding Business Associate Agreements
11/12/22 Modernizing Medicine Agrees to Pay $45 Million to Resolve Allegations of Accepting and Paying Illegal Kickbacks and Causing False Claims
11/12/22 Indian National Charged in $8 Million COVID-19 Relief Fraud Scheme
11/12/22 Former Hospital Employee Pleads Guilty To Criminal HIPPA Charges
11/12/22 Covered entities and those persons rendered accountable by general principles of corporate criminal liability may be prosecuted directly under 42 U.S.C. § 1320d-6
11/12/22 The Delaware Division of Developmental Disabilities Services Data Breach
11/12/22 OCR Settles Three Cases with Dental Practices for Patient Right of Access under HIPAA
11/12/22 HHS Issues Guidance on HIPAA and Audio-Only Telehealth
11/12/22 Five Former Methodist Hospital Employees Charged with HIPAA Violations
11/12/22 May a covered entity use or disclose protected health information for litigation?
11/12/22 When does the Privacy Rule allow covered entities to disclose protected health information to law enforcement officials?
Blog Archives
November 2022 (54) January 2025 (1)
Blog Labels
Data Breach (1) Covered Entity (40) BAA (4) PPP Fraud (1) HIPAA (2) HIPAA Enforcement (3) Telehealth (1) EHR Fraud (1) ePHI (2)
|