May a covered entity use or disclose protected health information for litigation? May a covered entity use or disclose protected health information for litigation?
May a covered entity use or disclose protected health information for litigation?
Answer:
A covered entity may use or disclose protected health information as permitted or required by the Privacy Rule, see 45 CFR 164.502(a)
(PDF); and, subject to certain conditions the Rule typically permits
uses and disclosures for litigation, whether for judicial or
administrative proceedings, under particular provisions for judicial and
administrative proceedings set forth at 45 CFR 164.512(e) (GPO), or as part of the covered entity’s health care operations, 45 CFR 164.506(a) (PDF).
Depending on the context, a covered entity’s use or disclosure of
protected health information in the course of litigation also may be
permitted under a number of other provisions of the Rule, including uses
or disclosures that are:
- required by law (as when the court has ordered certain disclosures),
- for a proceeding before a health oversight agency (as in a contested licensing revocation),
- for payment purposes (as in a collection action on an unpaid claim), or
- with the individual’s written authorization.
Where a covered entity is a party to a legal proceeding, such as
a plaintiff or defendant, the covered entity may use or disclose
protected health information for purposes of the litigation as part of
its health care operations. The definition of “health care operations”
at 45 CFR 164.501
(GPO) includes a covered entity’s activities of conducting or arranging
for legal services to the extent such activities are related to the
covered entity’s covered functions (i.e., those functions that make the
entity a health plan, health care provider, or health care
clearinghouse), including legal services related to an entity’s
treatment or payment functions. Thus, for example, a covered entity that
is a defendant in a malpractice action or a plaintiff in a suit to
obtain payment may use or disclose protected health information for such
litigation as part of its health care operations. The covered entity,
however, must make reasonable efforts to limit such uses and disclosures
to the minimum necessary to accomplish the intended purpose. See 45 CFR 164.502(b) , 164.514(d).
Where the covered entity is not a party to the proceeding, the
covered entity may disclose protected health information for the
litigation in response to a court order, subpoena, discovery request, or
other lawful process, provided the applicable requirements of 45 CFR 164.512(e) (GPO) for disclosures for judicial and administrative proceedings are met.
| HHS Issues Guidance on HIPAA and Audio-Only Telehealth Today, the U.S. Department of Health and Human Services (HHS), through its Office for Civil Rights (OCR), is issuing guidance on how covered health care providers and health plans can use remote communication technologies to provide audio-only telehealth services when such communications are conducted in a manner that is consistent with the applicable requirements of the Health Insurance Portability and Accountability Act of 1996 (HIPAA) Privacy, Security, and Breach Notification Rules, including when OCR’s Notification of Enforcement Discretion for Telehealth - PDF is no longer in effect. This guidance will help individuals ...read more |
| May a covered entity dispose of protected health information in dumpsters accessible by the public? For example, depending on the circumstances, proper disposal methods may include (but are not limited to): Shredding or otherwise destroying PHI in paper records so that the PHI is rendered essentially unreadable, indecipherable, and otherwise cannot be reconstructed prior to it being placed in a dumpster or other trash receptacle.Maintaining PHI for disposal in a secure area and using a disposal vendor as a business associate to pick up and shred or otherwise destroy the PHI.In justifiable cases, based on the size and the ...read more |
| Wednesday, November 9, 2022 A federal grand jury in Newark, New Jersey, returned an indictment today charging an Indian national for fraudulently obtaining millions of dollars in Paycheck Protection Program (PPP) loans guaranteed by the Small Business Administration (SBA) under the Coronavirus Aid, Relief, and Economic Security (CARES) Act. According to court documents, Abhishek Krishnan, 40, previously resided in Wake County, North Carolina, before returning to his home country of India. After returning to India, Krishnan allegedly submitted numerous fraudulent PPP loan applications to federally insured banks, including on behalf of purported companies that were not registered business entities. ...read more |
| Private Practice Revises Access Procedure to Provide Access Despite an Outstanding Balance Covered Entity: Private Practice Issue: Access A complainant alleged that a private practice physician denied her access to her medical records, because the complainant had an outstanding balance for services the physician had provided. During OCR’s investigation, the physician confirmed that the complainant was not given access to her medical record because of the outstanding balance. OCR provided technical assistance to the physician, explaining that, in general, the Privacy Rule requires that a covered entity provide an individual access to their medical record within 30 days of ...read more |
|
February 2026
| Su | Mo | Tu | We | Th | Fr | Sa |
| 1 | 2 | 3 | 4 | 5 | 6 | 7 |
| 8 | 9 | 10 | 11 | 12 | 13 | 14 |
| 15 | 16 | 17 | 18 | 19 | 20 | 21 |
| 22 | 23 | 24 | 25 | 26 | 27 | 28 |
Blog Home
Newest Blog Entries
1/21/25 Understanding Business Associate Agreements
11/12/22 Modernizing Medicine Agrees to Pay $45 Million to Resolve Allegations of Accepting and Paying Illegal Kickbacks and Causing False Claims
11/12/22 Indian National Charged in $8 Million COVID-19 Relief Fraud Scheme
11/12/22 Former Hospital Employee Pleads Guilty To Criminal HIPPA Charges
11/12/22 Covered entities and those persons rendered accountable by general principles of corporate criminal liability may be prosecuted directly under 42 U.S.C. § 1320d-6
11/12/22 The Delaware Division of Developmental Disabilities Services Data Breach
11/12/22 OCR Settles Three Cases with Dental Practices for Patient Right of Access under HIPAA
11/12/22 HHS Issues Guidance on HIPAA and Audio-Only Telehealth
11/12/22 Five Former Methodist Hospital Employees Charged with HIPAA Violations
11/12/22 May a covered entity use or disclose protected health information for litigation?
11/12/22 When does the Privacy Rule allow covered entities to disclose protected health information to law enforcement officials?
Blog Archives
January 2025 (1) November 2022 (54)
Blog Labels
PPP Fraud (1) ePHI (2) EHR Fraud (1) BAA (4) Telehealth (1) Covered Entity (40) HIPAA Enforcement (3) HIPAA (2) Data Breach (1)
|