US Medical BillingRevenue cycle solutions
Compliance and Regulations

Applying the Minimum Necessary Standard in Medical Billing

The HIPAA Privacy Rule permits a practice to use and disclose protected health information to get a claim paid. The minimum necessary standard is the limit on that permission, and the part billing teams most often get wrong is treating it as a single instruction — send less — when the rule actually asks a covered entity to build the limit into three different places in its operation. Applying it well is less about any one disclosure and more about the defaults a billing operation runs on.

Updated 11 min read

On this page

Key takeaways

The standard applies in three places, not one

The rule states the standard once and applies it three ways. A covered entity or business associate must make reasonable efforts to limit protected health information to the minimum necessary to accomplish the intended purpose of a use, a disclosure, or a request (45 CFR 164.502(b)(1)). The three words at the end are the ones that get lost. Most teams hear “disclosure” and scope what they send a payer, which is right but incomplete — the same limit governs what staff can see inside the practice and what the practice asks other organizations to hand over.

Use
Sharing, examining, or applying PHI within the practice — what a biller, a poster, or a follow-up rep looks at to do the work. The limit here is access.
Disclosure
Releasing PHI to a party outside the practice — a claim to a payer, records in response to a review, a file to a collections vendor. The limit here is scope.
Request
Asking another covered entity for PHI — records from a referring provider, an itemized remittance from a payer. The limit here is the ask itself.

The implementation detail for all three lives at 45 CFR 164.514(d), and the standard it opens with is deliberately flexible: a covered entity develops and implements policies and procedures appropriate to its own operation. There is no single correct configuration the rule hands down — there is a limit, and the practice is expected to design the defaults that meet it.

Uses: role-based access inside the practice

The internal limit is the one that never shows up on a claim, so it is the easiest to leave unbuilt. The rule asks a covered entity to identify the persons or classes of persons in its workforce who need access to PHI to carry out their duties, to identify the category or categories of information each needs, and then to make reasonable efforts to limit access accordingly (45 CFR 164.514(d)(2)). In practice that is role-based access: a payment poster and a prior-authorization coordinator do not need the same view of a chart, and the system should not give them one.

This is where minimum necessary meets the ordinary architecture of a billing system — user roles, permission groups, and which screens a role can open. The point is not to starve staff of what they need; it is that the default view should map to the job, so that seeing more than the role requires takes a deliberate step rather than being the resting state.

The work surface counts as a use

Disclosures: a protocol for the routine, review for the rest

Most of what a billing operation discloses is the same handful of things over and over — a claim, a response to a payer's records request, a secondary claim with the primary remittance attached. The rule does not ask a practice to make a fresh minimum-necessary judgment on each one. For a disclosure made on a routine and recurring basis, a covered entity may implement policies and procedures, which may be standard protocols, that limit the information to what is reasonably necessary for that purpose (45 CFR 164.514(d)(3)(i)).

That is the efficient reading of the standard, and the one that keeps it from becoming a drag on getting paid: decide once what a clean claim of a given type carries, and what a standard response to a records request for a given service includes, and encode it. The judgment is made at the protocol level, not the claim level.

Everything that falls outside the routine is handled differently. For all other disclosures, the rule asks a covered entity to develop criteria designed to limit the information to what is reasonably necessary and to review each request on an individual basis against those criteria (45 CFR 164.514(d)(3)(ii)). An unusual records demand, a subpoena-adjacent request, a request that reaches for more than the claim in question — these get looked at, not run through the standard protocol.

How the minimum necessary standard treats routine versus non-routine disclosures
How the minimum necessary standard treats routine versus non-routine disclosures
DimensionRoutine and recurringAll other disclosures
Examples in billingSubmitting a clean claim; a standard response to a payer records request; a secondary claim with the primary remittanceAn unusually broad records demand; a request that reaches beyond the claim at issue; a one-off release to a new kind of recipient
What the rule asksA standard protocol that scopes the disclosure once (164.514(d)(3)(i))Written criteria plus individual review of each request (164.514(d)(3)(ii))
Where the judgment is madeAt the protocol level, in advanceAt the request level, case by case

The entire-record limit and the payer records request

The single most common failure of the standard in billing is the reflex to attach the whole chart because it is faster than deciding what supports the claim. The rule addresses it directly: a covered entity may not use, disclose, or request an entire medical record except when the entire medical record is specifically justified as the amount that is reasonably necessary to accomplish the purpose (45 CFR 164.514(d)(5)).

So when a payer asks for records to adjudicate a claim, the right response is scoped to what substantiates that claim — the documentation for the dates and services at issue, the note that supports medical necessity, the order or referral the payer's policy requires. Sending the full history because the request said “records” is the error the limit exists to prevent. If a payer genuinely needs the entire record, that can be justified — but it is a decision to make and be able to explain, not a default.

Minimum necessary is not a reason to underpay the request

Requests, and when you can rely on the other party

The surface teams forget is the request. When a practice asks another covered entity for PHI — records from a referring provider to support a claim, a detailed remittance from a payer — the standard applies to the ask. The rule asks a covered entity to limit any request to what is reasonably necessary for its purpose, again by standard protocol for routine requests and by individual review for the rest (45 CFR 164.514(d)(4)). Asking for a patient's complete file when the claim turns on a single encounter is a minimum-necessary problem on the requesting side.

When the practice is on the other end — the one disclosing in response to a request — it does not always have to second-guess the requester. A covered entity may reasonably rely on a requested disclosure as the minimum necessary in defined situations: a request from a public official for a disclosure the rule permits, a request from another covered entity, a request from a professional who is a member of the workforce or a business associate providing professional services, and documentation supporting a research request (45 CFR 164.514(d)(3)(iii)). Reliance is permitted, not required — the practice can still scope its own response — but it means a routine records request from another covered entity does not oblige the practice to relitigate what the requester needs.

Where the standard does not apply — and why that matters

Applying minimum necessary in the wrong place is as much a mistake as failing to apply it in the right one, because it delays disclosures the rule never restricted. The standard does not apply to a fixed list of situations (45 CFR 164.502(b)(2)):

  • Disclosures to, or requests by, a health care provider for treatment. Care coordination is not scoped down by this rule.
  • Uses or disclosures made to the individual who is the subject of the information. Giving a patient their own record, or their own Good Faith Estimate, is outside the standard.
  • Uses or disclosures made pursuant to a valid authorization signed by the patient.
  • Disclosures to the Secretary of HHS for a compliance or enforcement action.
  • Uses or disclosures required by law, and those required for compliance with the HIPAA Administrative Simplification Rules.

The payment disclosures a billing operation lives on — claims, records to adjudicate a claim, coordination with a secondary payer — are not on that list, so they are squarely inside the standard. Knowing the boundary keeps a team from scoping down a treatment or patient-facing disclosure that was never meant to be limited. HIPAA is also a floor: substance use disorder records under 42 CFR Part 2 and some state laws impose stricter limits still, and where a stricter rule applies it governs.

Building minimum necessary into billing policy

The rule expects a covered entity to translate the standard into policies and procedures appropriate to its own operation, so applying it is a matter of building a few defaults and keeping them current.

  1. Map roles to the PHI each one needs

    Write down the classes of staff that touch claims and the categories of information each needs, then set system access to match (164.514(d)(2)). Review it when roles or systems change.
  2. Write standard protocols for the disclosures you repeat

    Decide once what a clean claim of each type carries and what a standard response to a records request for a given service includes, so routine disclosures are scoped by the protocol rather than by whoever is at the keyboard (164.514(d)(3)(i)).
  3. Set criteria and a review step for the non-routine

    Define what makes a request unusual and route those to individual review against written criteria, rather than through the standard protocol (164.514(d)(3)(ii)).
  4. Make “not the whole chart” the default response

    Build the records-request workflow to assemble what substantiates the claim, with sending an entire record as a justified exception someone signs off on, not the path of least resistance (164.514(d)(5)).
  5. Limit what you ask others for

    Apply the same scoping to requests the practice makes of other covered entities, so an information request is no broader than the claim it supports (164.514(d)(4)).
  6. Flag records that carry a stricter rule

    Identify substance use disorder records and state-protected categories before any payment disclosure, so the stricter requirement is applied rather than missed.

This standard is one boundary inside the larger permission that lets billing use PHI at all — the HIPAA Privacy Rule in medical billing sets out that permission and the business associate contracts that go with it, and the wider set of duties sits in the Compliance and Regulations category. Because the rules are revised and their enforcement guidance evolves, written procedures should point to the current regulation and be reviewed when it changes.

Educational, not legal advice

Common questions

Does the minimum necessary standard apply to what our staff can see internally, or only to what we send out?

Both. The standard applies to uses of PHI as well as disclosures (45 CFR 164.502(b)(1)). The internal mechanism is role-based access: identify the classes of staff that need PHI to do their work and the categories each needs, and limit system access accordingly (164.514(d)(2)). A payment poster and a prior-authorization coordinator do not need the same view of a chart.

Do we have to review every records request individually to meet the standard?

No. For disclosures made on a routine and recurring basis, the rule lets a practice work from a standard protocol that scopes the disclosure once (45 CFR 164.514(d)(3)(i)). A clean claim and a standard response to a common records request are routine. It is the non-routine or unusually broad request that gets individual review against written criteria (164.514(d)(3)(ii)).

A payer asked for the patient's records. Can we send the entire chart?

Only if the entire record is specifically justified as reasonably necessary for the purpose (45 CFR 164.514(d)(5)). The default response is scoped to what substantiates the claim — the documentation for the services and dates at issue and what supports medical necessity — not the full history. Sending the whole chart because it is faster is the error the entire-record limit exists to prevent.

Does minimum necessary apply to information we give the patient?

No. Uses or disclosures made to the individual who is the subject of the information are outside the standard (45 CFR 164.502(b)(2)(ii)). Giving a patient their own records, statement, or Good Faith Estimate is not a minimum-necessary decision. Applying the standard there would restrict a disclosure the rule never limited.

When we request records from another provider or payer, does the standard apply to us?

Yes. The standard applies to requests as well as uses and disclosures (45 CFR 164.502(b)(1)), so a practice must limit what it asks another covered entity for to what is reasonably necessary (164.514(d)(4)). Asking for a complete file when the claim turns on a single encounter is a minimum-necessary problem on the requesting side.

Authoritative sources

Ready to improve your revenue cycle?

Explore our services and knowledge base to see how we can help.