
When the Office of Civil Rights (OCR) enacted the HIPAA privacy and security rules, it was clear that the guidance would change over time. And even now, more than a decade after those initial implementations, OCR is continuing to update its HIPAA guidance.
Earlier this month, two updates were issued that could impact how you implement HIPAA guidance. Read on for the details that matter most.
Disclosing PHI to ACOs
The new HIPAA guidance that OCR released in August involves whether you can share a patient’s protected health information (PHI) via value-based care arrangements — such as accountable care organizations (ACOs) — for treatment purposes, even if the patient hasn’t authorized it.
In its response, OCR says the Privacy Rule does permit such disclosures, adding, “The Privacy Rule generally allows PHI to be used or disclosed without restriction for treatment purposes.”
The bolded “for treatment purposes” was added by OCR, and the agency goes on to define what it considers “treatment” to encompass. For privacy purposes, “treatment” does cover coordinating or managing the patient’s healthcare between providers or third parties. Because an accountable care organization would be required information for the patient’s treatment, such disclosures would be applicable.
For instance: Suppose two different providers are treating the same patient through a value-based care arrangement (an ACO). Based on the latest HIPAA guidance, the two providers are permitted to share PHI related to the patient’s treatment even if the patient hasn’t signed an authorization form.
Releasing PHI to Patients
OCR’s updated HIPAA guidance involves which PHI patients have a right to access from their healthcare providers and health plans under the HIPAA laws. OCR is very clear that patients essentially have a right to nearly everything in their designated record set.
“Designated record sets include medical records, billing records, payment and claims records, health plan enrollment records, case management records, as well as other records used, in whole or in part, by or for a covered entity to make decisions about individuals,” OCR says in its response. This includes:
- Medical records
- Billing and payment records
- Insurance information
- Clinical laboratory test reports
- X-rays
- Wellness and disease management program information
- Consent forms for treatment
- Clinical case notes or “SOAP” notes
If a patient requests one of the above items, however, your practice is only required to give them that piece of information. You don’t have to send them the entire record, for instance, if they only want their X-ray results.
OCR does include some minor exceptions to the above. For instance, patients don’t have the right to access psychotherapy notes that the therapist keeps separate from the medical record that analyze the contents of a counseling session. Patients may also be restricted from receiving information your practice has written for use in legal proceedings.
If you have any questions about what you can and can’t give patients or other providers, or you’re unclear about the latest HIPAA guidance, reach out to your practice’s attorney for clarification.
| Just when you think the HIPAA guidance is set in stone, the government changes it again. Let expert Brian L. Tuttle, CPHIT, CHP, provide the guidance you need to stay on top of the rules during his one-hour training session, Avoid Fines: Ace NEW 2025 HIPAA Security & Privacy Updates. Register today! |

