Skip to main content

When Can Doctors Share Patient Information Without Permission?

Key Takeaways

Doctors generally cannot share a patient’s medical information without permission because federal and state privacy laws protect confidential health records. HIPAA’s Privacy Rule allows disclosure only in limited situations, such as emergencies, routine care within the same treatment team, or required public‑health reporting.

The information contained in medical records is confidential under federal and state law. The Health Insurance Portability and Accountability Act of 1996 (HIPAA) is a federal law that protects “individually identifiable health information” (or “protected health information”). It does so through the Privacy Rule.

The Privacy Rule covers a patient’s medical records and PHI. The Privacy Rule gives patients rights over their medical information. This includes the right to access their protected health information. It also gives them the right to get a copy of their protected health information and request corrections.

Patients must permit disclosure of their medical records or protected information. There are many scenarios requiring patient authorization to disclose medical records. This includes:

  • health plans
  • health care clearinghouses
  • other health care operations

These entities can access a patient’s medical records and health information. As a result, they are subject to patient privacy rules.

But there are exceptions to these laws. Physicians may share medical records and personal medical information without consent. This article shares privacy protections and instances in which permission is not required.


Learning that your personal medical information has been shared without your consent can feel violating and deeply personal. A local healthcare attorney can review what happened, determine if an exception applies, and recommend next steps. 


HIPAA and Your Health Information

HIPAA includes federal privacy protections for personal health information. Covered entities typically need consent under HIPAA’s privacy rule to disclose medical records. They cannot share medical information without permission. HIPAA defines covered entities. They include insurance companies, pharmacies, and health care professionals. Covered entities also include HMOs and government health plans, such as Medicaid.

In most cases, patients must provide written authorization to disclose personal health information. If the patient has a personal representative, that person can provide written authorization upon presenting documentation that they are the patient’s representative. Health care providers must provide their patients with a notice of privacy practices.

This notice outlines the safeguards providers use to protect patients’ privacy. Patients learn how their provider or health care system uses their private health information. They also have a right to access their medical information.

The only exception to this rule is mental health. Patients do not have the right to psychotherapy notes. The U.S. Department of Health and Human Services (HHS) has an Office for Civil Rights (OCR). The OCR enforces HIPAA’s Privacy Rule and Security Rules. Any patient who has experienced an improper disclosure should contact the OCR. Report improper disclosures that include a criminal offense to law enforcement.

Exception: Emergencies

Consider this scenario: A patient gets into an accident and needs emergency surgery. After surgery, the patient is unconscious. The surgeon may discuss the patient’s medical information with a family member.

This is an example of a time when consent is not needed. Medical information includes test results and X-rays. They may also discuss this information with a personal representative.

This exception includes friends if it is in the patient’s best interest. The physician can disclose information relevant to the patient’s current medical care. But they can’t discuss medical information unrelated to the traumatic injury.

The physician cannot discuss any unrelated information from before the injury occurred. The law limits the discussion to the injury only.


When a disclosure falls outside these exceptions, patients have the right to challenge it and seek help from a healthcare attorney. Find local legal help.


Patient Privacy and Routine Care

Many providers use electronic health records in their practices. Often, practices include different providers and allied health providers. Allied health providers include nurses and pharmacy technicians.

Consider a health maintenance organization (HMO) as an example. Many HMOs bundle primary care, specialized care, and radiology in one building. In this scenario, other providers do not need permission to view patient records. This is because patients consent to share information when they sign up.

Electronic Health Records

Electronic health records offer seamlessness in patient care. Electronic health records provide one central location for a patient’s test results, vital signs, and more. Electronic health records also include a patient’s personally identifiable information. This includes birth date, address, and Social Security number.

Under HIPAA, doctors can share patient information and records as necessary. This includes general health and medical treatment.

For example, say a primary care physician refers their patient for an x-ray in the same practice. The radiologist does not need consent to review the patient’s records. By contrast, hospital employees cannot look up a patient’s medical record on a whim.

Without permission, this would violate HIPAA’s Privacy Rule. This exception to the Privacy Rule helps streamline medical treatment. For example, a new provider within the same practice does not require consent to access the patient’s records. They can view the patient’s medication list before prescribing a new medication.

A patient’s electronic health records receive the same privacy protection as paper records. Covered entities must notify the patient of any breach. They must also inform the Secretary of Health and Human Services. They must also notify major media outlets if the breach affects more than 500 people in the same state.

Disclosing Health Information for Government Reporting

There are circumstances where a physician must disclose personal medical information. Doctors must file birth and death certificates, for example. They must report diseases they’ve treated so state agencies can track public health. These disclosures should not include the patients’ names.

Doctors can also use your health information if necessary to protect public health. This includes reporting a flu outbreak or a pandemic.

Doctors must also report suspected cases of child abuse. As “mandated reporters,” they do not need patient consent. A mandated reporter is a person required to make such disclosures. They include physicians, social workers, and child care workers. This is similar for mental health providers.

If they believe their patient is a danger to themselves or others, they must report this. Mental health providers should include this in their notice of privacy practices.

Need Help With a Privacy Violation? Talk to an Attorney

Medical privacy laws are complex. Both state law and federal law address health information privacy. For personalized advice, contact an experienced healthcare lawyer today.

FindLaw’s directory of healthcare attorneys can get you started. Enter your city or ZIP code for a list of qualified legal professionals near you. Because some of your state’s laws are relevant, your attorney should be licensed in your state. Your search results will also show important details about prospective attorneys, like ratings and whether they offer free case evaluations. 

Was this helpful?

You Don’t Have To Solve This on Your Own – Get a Lawyer’s Help

Meeting with a lawyer can help you understand your options and how to best protect your rights. Visit our attorney directory to find a lawyer near you who can help.

Or contact an attorney near you:
SPONSORED
Copied to clipboard