A central aspect of the Privacy Rule is the principle of "minimum necessary" use and disclosure. Facility Directories. 164.502(a)(1).19 45 C.F.R. Special Case: Minors. Sections 261 through 264 of HIPAA require the Secretary of HHS to publicize standards for the electronic exchange, privacy and security of health information. Breach Reporting | HHS.gov Protected health information (PHI) under U.S. law is any information about health status, provision of health care, or payment for health care that is created or collected by a Covered Entity (or a Business Associate of a Covered Entity), and can be linked to a specific individual. 164.530(j).76 45 C.F.R. Privacy Policies and Procedures. 164.508.45 A covered entity may condition the provision of health care solely to generate protected health information for disclosure to a third party on the individual giving authorization to disclose the information to the third party. They are a true partner that complements our mission and vision, which is to improve the health and well-being of the communities we serve. Toll Free Call Center: 1-800-368-1019 Treatment is the provision, coordination, or management of health care and related services for an individual by one or more health care providers, including consultation between providers regarding a patient and referral of a patient by one provider to another.20. There are exceptionsa group health plan with less than 50 participants that is administered solely by the employer that established and maintains the plan is not a covered entity. Summary of the HIPAA Privacy Rule | HHS.gov See additional guidance on Notice. 164.512(e).34 45 C.F.R. (6) Limited Data Set. A covered entity may also disclose PHI to aid in TPO, which is the acronym for "Treatment, Payment and Health Care Operations". After making this designation, most of the requirements of the Privacy Rule will apply only to the health care components. Access and Uses. (4) Incidental Use and Disclosure. Every health care provider, regardless of size, who electronically transmits health information in connection with certain transactions, is a covered entity. The notice must include a point of contact for further information and for making complaints to the covered entity. 164.524.56 45 C.F.R.