An incidental use or disclosure is not a violation of the hipaa privacy rule if the covered entity(ce) has permitted as long as the covered entity has adopted reasonable safeguards as required by the Privacy Rule, and the information being shared was limited to the “minimum necessary,” as required by the Privacy Rule.
The Guidelines for Privacy of Individually Identifiable Health Information ("Privacy Rule") provides national standards for the protection of particular health information for the first time. The Privacy Rule was established by the United States Department of Health and Human Services ("HHS") to implement the requirements of the Health Insurance Portability and Accountability Act ("HIPAA").
The Privacy Rule standards address the use and disclosure of "protected health information" about individuals by organizations subject to the Privacy Rule known as "covered entities," as well as requirements for individuals' privacy rights to understand and control how their health information is used. The Office for Civil Rights ("OCR") within HHS is in charge of administering and enforcing the Privacy Rule in terms of voluntary compliance efforts and civil monetary penalties.
To learn more about healthcare visit: