Maintaining confidentiality is critical to patient trust, but there are common situations when the law permits or even requires the sharing of patient information.
The HIPAA Privacy Rule protects patients' health information by determining who can access it and how it can be used. While exceptions to the confidentiality rule exist, they are commonly buried in dense legal readings and minimized or excluded from HIPAA training.
The Hippocratic Oath captures the default position that our patients can trust us to keep their personal information private: “whatsoever I shall see or hear in the course of my profession … I will never divulge, holding such things to be holy secrets.” Yet the Hippocratic tradition combined with a cursory understanding of HIPAA can create unrealistic expectations about confidentiality for both clinicians and patients.
Physicians face situations every day in which patient information may need to be shared, but they (and their teams) may not understand when the law permits sharing, or even requires it. Although many of the exceptions to confidentiality are likely detailed in the paperwork patients sign as part of their consent to treatment, physicians may have an ethical duty in certain situations to personally educate patients before they disclose information that may be shared.
This article does not provide legal advice, because every situation is unique. Rather, it offers five categories of exceptions to patient confidentiality (discussed and summarized below) so that family physicians have a structured approach for appropriately disclosing information.
KEY POINTS
- While it's important to maintain patient confidentiality, there are five types of exceptions where the law permits or even requires the sharing of patient information.
- Exceptions include public health risks such as reporting infectious diseases or suspected abuse, decision-maker requirements involving pediatric patients, third-party interests, administrative and operational disclosures, and rare but important exceptions such as duty to warn or protect.
- Even when you can legally share patient information, it may be wise to inform patients so they are not surprised by an unwanted disclosure.

SUMMARY OF THE FIVE EXCEPTIONS TO CONFIDENTIALITY
| Category | Examples |
|---|---|
| Public health risks and mandatory reports | Infectious and other diseases |
| Suspected abuse of vulnerable populations | |
| Decision-maker required | Pediatric exceptions |
| Substitute judgment due to an adult patient's lack of capacity | |
| Third-party interests | Department of Transportation |
| Workers' compensation | |
| Sports team physicians | |
| Immigration physicals | |
| Government functions | |
| Administrative and operational disclosures | Insurance |
| Regulatory agencies | |
| Members of the health care team | |
| Family Educational Rights and Privacy Act | |
| Family member and caregiver allowances | |
| Research and quality improvement | |
| Health care professional exposures | |
| Disaster relief efforts | |
| Death investigations | |
| Unintentional disclosures | |
| Rare but important exceptions | Duty to warn/protect |
| Court orders | |
Read the full article
Get immediate access, anytime, anywhere.
Choose a single article, issue, or full-access subscription.
Earn up to 5 CME credits per issue.
