HIPAA Privacy Rule Waiver

HIPAA Privacy Rule

Emergency HIPAA Privacy Rule Waiver

During an emergency or public health crisis, some elements of the HIPAA Privacy Rule may be waived. As of March 15, 2020, the Secretary of the Department of Health and Human Services (HHS), issued an emergency HIPAA Privacy Rule waiver in response to the COVID-19 health crisis.

A HIPAA Privacy Rule waiver is issued to facilitate quick response to public health issues, temporarily waiving fines associated with certain disclosures. The following discusses the HIPAA Privacy Rule waiver in more detail.

What Conditions Enable the HIPAA Privacy Rule Waiver?

There are two conditions that must be met before the Secretary may issue an emergency HIPAA Privacy Rule waiver:

  • The President declares an emergency or disaster; and
  • The Secretary of HHS declares a public health emergency.

In regards to the COVID-19 crisis, both conditions have been met. However, the waiver is a temporary measure, and only applies:

  • To the area identified in the public health emergency declaration.
  • To covered entities that have instituted a disaster protocol.
  • For up to 72 hours from the time the disaster protocol is implemented.

If the President or Secretary terminates the emergency declaration, the HIPAA Privacy Rule waiver no longer applies.

Which HIPAA Privacy Rule Provisions are Waived?

The HIPAA Privacy Rule waiver applies to the following:

  • The requirement to distribute a notice of privacy practices.
  • The patient’s right to request privacy restrictions.
  • The patient’s right to request confidential communications.
  • The requirement to obtain a patient’s consent to speak with family members or friends involved in the patient’s care.
  • The requirement to honor a request to opt out of a covered entity’s facility directory.

Under the Privacy Rule waiver, protected health information (PHI) may be disclosed, without prior patient consent, to public health authorities to protect public health and safety. Additionally, PHI may be disclosed without prior consent to individuals involved in the patient’s care such as family members, friends, and caregivers.

Minimum Necessary Standard and Emergencies

Even in the case of emergency, the minimum necessary standard must be upheld. All disclosures of PHI must be restricted to what is necessary for public health and safety.

For more information on HIPAA Privacy Rule Waivers, please click here.

HIPAA Resources

Need assistance with HIPAA compliance? Compliancy Group can help! They help you achieve HIPAA compliance with Compliance Coaches® guiding you through the entire process. Find out more about the HIPAA Seal of Compliance® and Compliancy Group. Get HIPAA compliant today!

Disclaimer: The views and opinions expressed in the article and on this blog post are those of the authors. These do not necessarily reflect the views, opinions, and position of the Telebehavioral Health Institute (TBHI). Any content written by the authors are their opinion and are not intended to malign any organization, company or individuals.

Your TBHI Professional Training Options

Looking for specialized legal and ethical training during COVID-19? You may be interested in the following.

To assist behavioral professionals seeking other evidence-based telehealth training to help deal with COVID-19, TBHI is honored to offer you these CME and CE-accredited programs at 50% off from the convenience of your desktop or digital device: 


Rate this post!

(4 raters, 20 scores, average: 5.00 out of 5)

Leave a Reply

Name and email are required. Your email address will not be published.

This site uses Akismet to reduce spam. Learn how your comment data is processed.