Minimum necessary standard
The HIPAA Privacy Rule's requirement to limit the protected health information used, disclosed, or requested to the least needed to accomplish the purpose — with defined exceptions, including disclosures for treatment.
Updated
The minimum necessary standard is the Privacy Rule's requirement to make reasonable efforts to limit protected health information — in a use, a disclosure, or a request — to the minimum needed to accomplish the intended purpose. In billing it means sending a payer the information that supports the claim, not the patient's entire record.
It is a reasonable-efforts standard, not an obstacle to payment: the aim is to disclose what the purpose genuinely requires and no more.
In practice
Stated at 45 CFR 164.502(b), with implementation detail at 164.514(d). The standard does not apply to several situations, including disclosures to a health care provider for treatment, disclosures to the individual who is the subject of the information, uses or disclosures made under a valid authorization, disclosures to HHS for enforcement, and uses or disclosures required by law.
Commonly confused with
- Authorization: Minimum necessary limits routine payment and operations disclosures; a use or disclosure made under a patient's signed authorization is one of the situations the standard does not restrict.
