HIPAA Privacy Rule
The HIPAA regulation that governs how protected health information (PHI) may be used and disclosed, and gives patients rights over their records. Codified at 45 CFR Part 160 and Part 164 (Subparts A and E).
In depth
The Privacy Rule limits PHI use and disclosure to treatment, payment, and health-care operations unless the patient authorizes otherwise, and it grants patients rights to access, amend, and get an accounting of disclosures of their records. For a pharmacy this means a Notice of Privacy Practices, minimum-necessary handling of PHI, safeguards at the counter and in the system, and documented policies for requests and complaints.