Research · 11 min read

What a Company May Do With Your Record Without Asking You

Most of what happens to a medical record happens under a standing permission rather than a signature. The rule that grants it is short, and the list of activities it covers is much longer than the word treatment suggests.

Key takeaways

  • The general rule bars use and disclosure, then names six permitted routes, and only one of them is a permission you sign.
  • Treatment, payment and health care operations need no consent, and a consent obtained for them cannot stand in for a required authorization.
  • Health care operations is defined across six paragraphs, and it names business planning, customer service and a merger of the entity.
  • The definition of payment permits disclosure to consumer reporting agencies of six named data elements, and a diagnosis is not among them.
  • Minimum necessary is an effort standard with six stated exclusions, and the first switches it off between clinicians treating the same person.
  • An entire medical record may not be used, disclosed or requested unless the whole record is specifically justified.

Answer first: a signature is the exception, not the rule

People picture health privacy as a gate that opens when they sign something. The federal rule is built the other way around.

It starts with a flat prohibition, then lists the routes out of it. Only one of those routes is a permission you give.

The rest run on their own, covering the ordinary business of providing care and getting paid for it, and they need nothing at all from the person the record is about.

What follows is that list, and the one limit that applies across most of it.

The six routes out of the prohibition

The general rule opens by saying a covered entity or business associate may not use or disclose protected health information at all, except as the rules permit or require.

Then it names six ways a covered entity is permitted to. To the individual, for treatment, payment or health care operations, and incident to another permitted use or disclosure.

Under a valid authorization, under an agreement in the section covering things you get a chance to object to, and as permitted by a short list of other sections.

Two disclosures are not permitted but required. One is to the individual, when the access or accounting rights are exercised. The other is to the Secretary, to investigate compliance.

Reading that list in order is the useful part. The signature route is fourth of six, and the two routes ahead of it carry the daily traffic.

Treatment, payment and operations, and why consent is optional

The section covering those three purposes is unusually direct. A covered entity may use or disclose protected health information for treatment, payment or health care operations.

It then adds something most summaries skip: a covered entity may obtain consent for those uses, which means it is free to ask and free not to.

The next sentence closes the loop. Consent obtained that way is not effective where an authorization is required, or where some other condition has to be met.

So a consent box in a signup flow can be real and can still add nothing to what the rules already allow. The permission was there before the box existed.

That is the sentence to hold on to when a form says you are agreeing to information sharing. The question is which of the six routes the sharing is travelling on.

Health care operations is a defined term, and it is wide

The definition runs to six numbered paragraphs, and each one covers a family of activities rather than a single task.

Quality assessment, outcomes evaluation, developing clinical guidelines, care coordination, and contacting patients with information about treatment alternatives.

Reviewing the competence of health professionals, evaluating practitioner performance, training, accreditation, certification, licensing and credentialing.

Underwriting and enrollment activities related to creating or renewing a contract of health insurance, subject to a separate limit. Medical review, legal services, auditing, and fraud and abuse detection.

Business planning and development, named to include cost-management analyses, formulary development and the development of coverage policies.

And general administrative activities, which the definition spells out to include customer service, resolution of internal grievances, and the sale, transfer, merger or consolidation of the entity with another covered entity.

That last item is worth pausing on. A company changing hands sits inside the definition of an operation, which is a route rather than an event.

The payment definition names a credit bureau

Payment is defined just as carefully, and it reaches further than billing you.

It covers eligibility and coverage determinations, coordination of benefits, cost-sharing calculations, claims adjudication and subrogation.

It covers billing, claims management, collection activities and related data processing. It covers review of services for medical necessity and justification of charges.

It covers utilization review, including precertification and preauthorization, and both concurrent and retrospective review.

And the last item in that list is the one nobody expects. Payment includes disclosure to consumer reporting agencies of six named things about you.

Name and address, date of birth, and social security number. Payment history, account number, and the name and address of the provider or the health plan.

That is a closed list, which is the protective part of it. A diagnosis is not on it, and neither is anything about what the care was for.

Your record can move to a company you have not dealt with

The same section sets out five specifications, and only the first is about a company using its own records.

The second lets a covered entity disclose information for the treatment activities of a health care provider, which is not the same thing as its own provider.

The third lets it disclose to another covered entity or provider for the payment activities of the entity receiving the information.

The fourth is the one with conditions attached. Disclosure to another covered entity for that entity's own health care operations is permitted only where both have or had a relationship with the same person, and the information pertains to that relationship.

Even then the operation has to be in the first two paragraphs of the definition, or be fraud and abuse detection or compliance.

The fifth covers participants in an organized health care arrangement, who may disclose to each other for the arrangement's operations.

Minimum necessary, and the six places it does not apply

There is a limit that runs across most of this, and it is stated as an effort rather than an outcome.

When using or disclosing information, or requesting it from another covered entity, an entity must make reasonable efforts to limit it to the minimum necessary for the purpose.

Then the rule names six situations where that requirement does not apply at all, and reading them is more informative than reading the rule.

Disclosures to or requests by a health care provider for treatment. Uses or disclosures made to the individual, and anything made under an authorization.

Disclosures to the Secretary for a compliance investigation. Uses or disclosures required by law, and anything required for compliance with the rules themselves.

The first exclusion is the significant one for a person receiving care. Between clinicians treating you, the minimum necessary limit is switched off by design.

What minimum necessary looks like inside a company

A separate section turns that standard into concrete work, and the work is mostly about staff and about routine.

A covered entity has to identify which people or classes of people in its workforce need access to carry out their duties. For each of them it has to identify which categories of information they need, and any conditions on that access.

Then it has to make reasonable efforts to hold access to what it identified. That is role-based access, written as a rule rather than as a product.

For any disclosure it makes on a routine and recurring basis, it has to implement policies limiting the information to what is reasonably necessary. Everything else needs criteria and an individual review.

The rule also names four situations where an entity may reasonably rely on the requester's own judgment of what is minimum necessary. One of them is a public official's representation to that effect.

And it closes with a sentence worth quoting whole. An entity may not use, disclose or request an entire medical record, except where the entire record is specifically justified as the amount reasonably necessary.

What a reader can actually look at

Whether the document in front of you is describing what already happens, or asking permission for something new. Those are different instruments and they look alike.

Whether a consent box is attached to treatment, payment and operations, since a consent there adds nothing the rules had not already permitted.

Whether the notice you were given describes disclosures to other companies for their own operations, and on what basis.

Whether it mentions reporting to a consumer reporting agency, which the payment definition allows for a closed list of six data elements.

Whether it says anything about limiting staff access, which is the visible half of the minimum necessary work.

What this does not decide

It does not say whether any company is a covered entity or a business associate. That is a legal conclusion about a specific business and it turns on facts a homepage does not show.

It does not say what any company has done. A permission describes what a rule allows, not what happened.

It does not describe every route, and two large ones sit outside it. The section covering disclosures where neither a permission nor an objection is required is a separate subject. So are the rights to see a record, to correct it, and to be told where information went.

And it is not legal advice. It reports what four provisions of one federal subpart say.

Sources

  1. 45 CFR 164.502, "Uses and disclosures of protected health information: General rules"Department of Health and Human Services, via the Electronic Code of Federal Regulations · Source note printed on the section: 65 FR 82802, Dec. 28, 2000, as amended at 67 FR 53267, Aug. 14, 2002; 78 FR 5696, Jan. 25, 2013; 89 FR 33063, Apr. 26, 2024 · Retrieved September 2026Paragraph (a), that a covered entity or business associate may not use or disclose protected health information except as permitted or required by the subpart. Paragraph (a)(1), the six permitted routes: to the individual; for treatment, payment or health care operations as permitted by 164.506; incident to a use or disclosure otherwise permitted or required; pursuant to a valid authorization under 164.508; pursuant to an agreement under 164.510; and as permitted by the listed sections. Paragraph (a)(2), the two required disclosures, to an individual under 164.524 or 164.528 and to the Secretary for a compliance investigation. Paragraph (b), the minimum necessary standard as a duty of reasonable efforts, and its closed list of six situations where it does not apply.
  2. 45 CFR 164.506, "Uses and disclosures to carry out treatment, payment, or health care operations"Department of Health and Human Services, via the Electronic Code of Federal Regulations · Source note printed on the section: 67 FR 53268, Aug. 14, 2002, as amended at 78 FR 5698, Jan. 25, 2013 · Retrieved September 2026Paragraph (a), the permission to use or disclose for treatment, payment or health care operations. Paragraph (b)(1), that a covered entity may obtain consent of the individual for those purposes, and paragraph (b)(2), that such a consent is not effective to permit a use or disclosure where an authorization is required or where another condition must be met. Paragraph (c)(1) through (c)(5), the five implementation specifications: use or disclosure for the entity's own purposes; disclosure for the treatment activities of a health care provider; disclosure to another covered entity or provider for the recipient's payment activities; disclosure to another covered entity for the recipient's health care operations, conditioned on a relationship with the individual, on the information pertaining to that relationship, and on the operation falling in paragraph (1) or (2) of the definition or being health care fraud and abuse detection or compliance; and disclosure among participants in an organized health care arrangement.
  3. 45 CFR 164.501, "Definitions", read for the defined terms treatment, payment and health care operationsDepartment of Health and Human Services, via the Electronic Code of Federal Regulations · Source note printed on the section: 65 FR 82802, Dec. 28, 2000, as amended at 67 FR 53266, Aug. 14, 2002; 68 FR 8381, Feb. 20, 2003; 74 FR 42769, Aug. 24, 2009; 78 FR 5695, Jan. 25, 2013 · Retrieved September 2026The definition of health care operations, in six numbered paragraphs, including quality assessment and improvement, outcomes evaluation, care coordination and contacting patients with information about treatment alternatives; reviewing competence or qualifications, evaluating practitioner performance, training, accreditation, certification, licensing and credentialing; underwriting, enrollment and premium rating for a contract of health insurance; medical review, legal services and auditing functions including fraud and abuse detection and compliance programs; business planning and development including cost-management analyses and formulary development; and business management and general administrative activities including customer service, resolution of internal grievances, and the sale, transfer, merger or consolidation of all or part of the covered entity. The definition of payment, including eligibility and coverage determinations, coordination of benefits, cost-sharing determination, claims adjudication and subrogation, billing, claims management, collection activities, review for medical necessity and justification of charges, utilization review including precertification and preauthorization, and the closed list at paragraph (2)(vi) of information that may be disclosed to consumer reporting agencies: name and address, date of birth, social security number, payment history, account number, and the name and address of the health care provider or health plan. The definition of treatment as the provision, coordination or management of health care and related services, consultation between providers, and referral.
  4. 45 CFR 164.514, "Other requirements relating to uses and disclosures of protected health information", read at paragraph (d)Department of Health and Human Services, via the Electronic Code of Federal Regulations · Source note printed on the section: 65 FR 82802, Dec. 28, 2000, as amended at 67 FR 53270, Aug. 14, 2002; 78 FR 5700, Jan. 25, 2013; 78 FR 34266, June 7, 2013 · Retrieved September 2026Paragraph (d)(2), requiring a covered entity to identify the persons or classes of persons in its workforce who need access to carry out their duties, and for each the categories of information needed and any conditions on that access, and to make reasonable efforts to limit access accordingly. Paragraph (d)(3), requiring policies and procedures limiting routine and recurring disclosures, and criteria plus individual review for all others, together with the four situations in which reliance on the requester's representation may be reasonable, including a representation by a public official. Paragraph (d)(4), the parallel requirements for requests made to other covered entities. Paragraph (d)(5), that a covered entity may not use, disclose or request an entire medical record except where the entire medical record is specifically justified as the amount reasonably necessary.

Frequently asked questions

Do I have to agree before my health information is shared?

For most of what happens routinely, no. The general rule bars use and disclosure except as permitted, then lists six permitted routes. One of those routes is an authorization you sign. Another covers treatment, payment and health care operations, and it needs nothing from you. The section on those three purposes says a covered entity may obtain consent for them, which makes asking optional. It adds that a consent obtained that way is not effective where an authorization is actually required.

What counts as health care operations?

More than the phrase suggests, and the definition runs to six numbered paragraphs. It covers quality assessment, outcomes evaluation, care coordination and contacting patients about treatment alternatives. It covers reviewing practitioner competence, training, accreditation and credentialing. It covers underwriting and enrollment activity for a contract of health insurance, medical review, legal services, auditing, and fraud and abuse detection. It covers business planning, cost-management analyses and formulary development. And it covers general administration, named to include customer service and the sale, transfer, merger or consolidation of the entity.

Can my medical information reach a credit bureau?

The definition of payment includes disclosure to consumer reporting agencies, and it names exactly what may go. Name and address, date of birth, social security number, payment history, account number, and the name and address of the provider or health plan. That list is closed, which is the protective part. A diagnosis is not on it, and neither is any description of the care. What a report may then contain, and for how long, is governed by a different statute entirely.

Can one company hand my record to another company?

Under stated conditions, yes. A covered entity may disclose information for another health care provider's treatment activities, and it may disclose to another covered entity for that entity's own payment activities. Disclosure for another entity's health care operations is narrower, and it carries three conditions. Both entities must have or have had a relationship with the same person, and the information must pertain to that relationship. The operation must also fall in the first two paragraphs of the definition, or be fraud and abuse detection or compliance work.

What does minimum necessary actually require?

Reasonable efforts to limit information to the minimum needed for the purpose, when using it, disclosing it, or requesting it from another covered entity. It is an effort standard rather than a result. It does not apply in six situations, including disclosures to or requests by a health care provider for treatment, uses or disclosures made to you, anything under an authorization, and anything required by law. A separate section adds that an entire medical record may not be used, disclosed or requested unless the whole record is specifically justified.

Is a consent form in a signup flow meaningless then?

Not meaningless, but frequently narrower than it looks. A consent for treatment, payment and health care operations is expressly optional under the rules, and where one is obtained it cannot substitute for an authorization that the rules require. So the useful question is which route a particular sharing arrangement travels on. If a form is asking permission for something outside those three purposes, it is doing real work, and the rules set out what such a document has to contain.