Skip to main content
U.S. flag

An official website of the United States government

Return to Search

Covered Entities Fast Facts

These are Summaries re: Privacy Rule Oblgiations for Providers


Issued by: Office for Civil Rights (OCR)

Fast Facts for Covered Entities

The Privacy Rule provides federal protections for personal health information held by covered entities, and gives patients an array of rights with respect to that information. At the same time, the Privacy Rule is balanced so that it permits the disclosure of personal health information needed for patient care and other important purposes.

The Privacy Rule does not require you to obtain a signed consent form before sharing information for treatment purposes.  Health care providers can freely share information for treatment purposes without a signed patient authorization.


The Privacy Rule does not require you to eliminate all incidental disclosures.  The Privacy Rule recognizes that it is not practicable to eliminate all risk of incidental disclosures.  In August 2002, specific modifications to the Rule were adopted to clarify that incidental disclosures do not violate the Privacy Rule when you have policies which reasonably safeguard and appropriately limit how protected health information is used and disclosed.


The Privacy Rule does not cut off all communications between you and the families and friends of patients. As long as the patient does not object, The Privacy Rule permits you to:

  • share needed information with family, friends, or anyone else a patient identifies as involved in his or her care;
  • disclose information when needed to notify a family member or anyone responsible for the patient's care about the patient's location or general condition;
  • share the appropriate information for these purposes even when the patient is incapacitated if doing so is in the best interest of the patient.


The Privacy Rule does not stop calls or visits to hospitals by family, friends, clergy or anyone else.  Unless the patient objects, basic information such as phone number, room number and general condition can: 

  • be listed in the hospital directory;
  • be given to people who call or visit and ask for the patient;
  • be given to clergy along with religious affiliation--when provided by the patient--even if the patient is not asked for by name.

The Privacy Rule does not prevent child abuse reporting.  You may continue to report child abuse or neglect to appropriate government authorities. 

The Privacy Rule is not anti-electronic.  You can communicate with patients, providers, and others by e-mail, telephone, or facsimile, with the implementation of appropriate safeguards to protect patient privacy.

HHS is committed to making its websites and documents accessible to the widest possible audience, including individuals with disabilities. We are in the process of retroactively making some documents accessible. If you need assistance accessing an accessible version of this document, please reach out to the

DISCLAIMER: The contents of this database lack the force and effect of law, except as authorized by law (including Medicare Advantage Rate Announcements and Advance Notices) or as specifically incorporated into a contract. The Department may not cite, use, or rely on any guidance that is not posted on the guidance repository, except to establish historical facts.