US Medical BillingRevenue cycle solutions
Compliance and Regulations

The HIPAA Privacy Rule in Medical Billing

The HIPAA Privacy Rule is often read as an obstacle to billing. It is the opposite: it names billing as a permitted use of protected health information. Because getting a claim paid is a payment activity, a covered entity may use and disclose the information a claim carries without the patient's authorization. What the rule then does is draw the edges of that permission — how much may be shared, and with whom, and under what contract — and those edges are where a billing operation actually has work to do.

Updated 9 min read

On this page

Key takeaways

Why billing is a permitted use of PHI

The Privacy Rule does not require a patient's permission for a practice to bill for the care it provided. It permits a covered entity to use and disclose protected health information to carry out its own treatment, payment, and health care operations, and it does so without any authorization from the individual. That permission is set out at 45 CFR 164.506, and billing sits inside the middle term of it: payment.

The reason this matters is that "payment" is defined broadly. Under 45 CFR 164.501 it reaches the ordinary work of the revenue cycle — determining a patient's eligibility or coverage, adjudicating and billing claims, claims management, collection activities, obtaining reimbursement, and reviewing services for medical necessity or the justification of charges. If a task is part of getting the claim paid, it is almost certainly a payment activity, and the PHI it needs may be used and disclosed for it.

Consent is permitted, not required

Who the rule binds: covered entities and business associates

The Privacy Rule applies directly to covered entities — a health plan, a health care clearinghouse, or a health care provider that transmits health information electronically in connection with a HIPAA standard transaction (45 CFR 160.103). A practice that submits claims or checks eligibility electronically is a covered entity, and that is what puts its billing operation under the rule in the first place.

Most practices do not do all of their billing in-house, and the rule anticipates that. An outside party that creates, receives, maintains, or transmits PHI to perform a function for the practice is a business associate — a third-party billing company, a collections agency, a clearinghouse acting beyond the narrow clearinghouse role, a software or storage vendor whose systems hold claim data. A covered entity may hand PHI to a business associate only after it has a written contract in place: a business associate agreement, required by 45 CFR 164.502(e) and detailed at 164.504(e), that obligates the vendor to safeguard the information and use it only as permitted.

The contract comes before the data

The boundary on a permitted disclosure: minimum necessary

Being permitted to disclose PHI for payment is not the same as being permitted to disclose all of it. The minimum necessary standard (45 CFR 164.502(b)) requires a covered entity to make reasonable efforts to limit a use, disclosure, or request to the least information needed for the purpose. In billing, that is the difference between sending a payer the documentation that supports a claim and sending it the patient's entire chart because it is easier — and applying the minimum necessary standard in billing is a discipline of its own, built into how staff access records, how routine disclosures are scoped, and what the practice requests of others.

The standard has defined exceptions, and knowing them keeps a team from applying it in the wrong place. Minimum necessary does not apply to disclosures to a health care provider for treatment, to disclosures made to the individual who is the subject of the information, to uses or disclosures made under a valid authorization, to disclosures to HHS for an enforcement action, or to uses and disclosures required by law. A payer's request for records to adjudicate a claim, by contrast, is a payment disclosure and is squarely inside the standard — the response should be scoped to what substantiates that claim.

It is a reasonable-efforts standard, not a barrier to payment

Disclosing to another plan or provider

Payment work rarely stays inside one organization, and the rule permits the disclosures that make it flow. A covered entity may disclose PHI to another covered entity or to a health care provider for the payment activities of the entity that receives it (45 CFR 164.506(c)). That single permission is what lets a great deal of ordinary billing happen at all.

It is the basis for coordination of benefits: a practice can send the primary plan's remittance to a secondary payer so the secondary can process its share, which is exactly the mechanism secondary billing depends on. It is also why eligibility verification is not a privacy problem — determining coverage is itself a payment activity, so using PHI to confirm a patient's benefits is a permitted use, not a disclosure that needs separate consent.

When a stricter rule overrides the Privacy Rule

HIPAA sets a floor, not a ceiling. A more protective rule — federal or state — can require consent for a disclosure the Privacy Rule would have permitted, and where two rules apply to the same information the more protective one governs. Treating HIPAA as the whole answer is the mistake that produces the wrong disclosure.

The clearest example in billing is substance use disorder records from a federally assisted program, which are governed by 42 CFR Part 2 in addition to HIPAA. For those records a disclosure for payment can require patient consent structured for the specific disclosure, where HIPAA alone would not. State privacy laws can add their own restrictions on top. The safe practice is to identify every rule that reaches a given record and apply the strictest, rather than defaulting to the Privacy Rule and assuming it settles the question.

Building the Privacy Rule into the billing workflow

For a billing operation, compliance with the Privacy Rule is less a project than a set of defaults built into how the work already runs.

  1. Put a business associate agreement in place before any vendor sees PHI

    Every outside party that touches claim data — billing service, clearinghouse, collections agency, hosting or software vendor — needs a signed agreement first. Inventory the vendors that handle PHI and confirm each one is covered.
  2. Make minimum necessary the default for what leaves the practice

    Scope what goes on a claim, and what is sent in response to a records request, to the information the payer needs to adjudicate it. A standing habit of attaching the full chart is the standard's most common failure.
  3. Limit internal access to what a role requires

    The standard applies to internal uses as well as external disclosures. Role-based access so staff see only the PHI their job needs is how minimum necessary is met inside the practice.
  4. Flag records that carry a stricter rule

    Build a step that identifies substance use disorder records and any state-protected categories before they are disclosed for payment, so the stricter consent requirement is applied rather than missed.
  5. Keep operational logs free of PHI

    Work queues, spreadsheets, and templates should use non-identifying references. Patient identifiers, clinical documentation, and payer correspondence belong only in the approved secured systems.

The Privacy Rule is one part of HIPAA. Safeguarding the data itself, notifying affected people after a breach, and giving patients access to their own records are separate obligations with their own rules, and they are covered elsewhere in the Compliance and Regulations category — alongside the disclosure rules of the No Surprises Act and hospital price transparency. Because the rules are revised and their enforcement guidance evolves, written procedures should point to the current regulation and be reviewed when it changes.

Educational, not legal advice

Common questions

Do we need a signed HIPAA authorization to bill a patient's insurance?

No. Billing is a payment activity, and the Privacy Rule permits a covered entity to use and disclose PHI to carry out payment without the patient's authorization (45 CFR 164.506). A practice may choose to obtain a consent as a matter of policy, but it is not a precondition of billing. A signed authorization is required for uses and disclosures that fall outside treatment, payment, and health care operations.

A payer asked for the patient's records to process a claim. Can we send them?

Yes — a disclosure for payment is permitted — but it is subject to the minimum necessary standard (45 CFR 164.502(b)). Send the documentation that supports the claim, not the patient's entire record. And check first whether the record carries a stricter rule, such as substance use disorder information under 42 CFR Part 2, which can require patient consent that HIPAA alone would not.

Is our outside billing company a business associate?

Yes. A company that handles protected health information to bill on the practice's behalf is a business associate, and the practice must have a written business associate agreement in place before disclosing PHI to it (45 CFR 164.502(e), 164.504(e)). The same is true of a clearinghouse, a collections agency, and a software or storage vendor whose systems hold claim data.

Can we share information with another provider or a secondary payer?

Yes. A covered entity may disclose PHI to another covered entity or a health care provider for that entity's own payment activities (45 CFR 164.506(c)). That is what lets coordination of benefits and secondary billing work — a practice can send the primary plan's remittance to the secondary payer so it can process its share.

Does minimum necessary mean we can't send enough to get the claim paid?

No. Minimum necessary is a reasonable-efforts standard to limit a disclosure to what the purpose requires, and substantiating a claim is a legitimate purpose. It does not ask a practice to withhold information a payer genuinely needs; it asks that the disclosure be no broader than the purpose. Send what the payer needs to adjudicate the claim — no more, and no less.

Authoritative sources

Ready to improve your revenue cycle?

Explore our services and knowledge base to see how we can help.