According to the Commission on Quality in Pastoral Services, Association of Professional Chaplains, in its guidance template "HIPAA, Chaplains, and Community Religious Leaders," a chaplain is a clinically trained healthcare professional certified by a national pastoral care organization, and employed, contracted, or otherwise officially engaged by the healthcare organization to provide spiritual, pastoral, and emotional care to patients, families, and staff. A clergy member or community faith group leader is recognized and employed by their own faith group as a religious leader, is not employed by the healthcare organization, and tends to the religious needs of members of that faith group specifically. The Commission notes that the HIPAA provision addressing clergy exists specifically in the context of what patient information may be made available to these outside visitors.

 

Do chaplains fall under HIPAA?

HIPAA governs how "covered entities," that is, hospitals, clinics, insurers, and their business associates handle protected health information (PHI). Whether a chaplain is bound by HIPAA depends on context.

Hospital-employed or hospital-affiliated chaplains are always covered. If a chaplain works for a hospital, accesses the electronic health record, attends care team meetings, or is listed as hospital staff, they are treated as part of the covered entity's workforce. That means they're bound by the same privacy and security rules as nurses, physicians, and administrative staff.

Independent or community clergy visiting patients on behalf of a congregation occupy a different territory. HIPAA actually gives specific accommodations for clergy. In these cases, the chaplain's obligations may be governed more by pastoral ethics, denominational policy, and state clergy-communication privilege laws than by HIPAA itself.

Chaplaincy organizations contracting with healthcare systems often qualify as business associates, which brings its own set of contractual and compliance obligations.

Basically, any chaplaincy program in or affiliated with a healthcare organization should assume HIPAA applies until a compliance officer says otherwise.

 

The HIPAA provision for clergy

Under 45 CFR § 164.510(a)(1), the Privacy Rule's facility-directory provision, a covered health care provider may, "Use the following protected health information to maintain a directory of individuals in its facility: (A) The individual's name; (B) The individual's location in the covered health care provider's facility; (C) The individual's condition described in general terms that does not communicate specific medical information about the individual; and (D) The individual's religious affiliation."

That's the directory information hospitals are permitted to compile, name, location, general condition, and religious affiliation. The regulation then notes who gets access to which pieces of information, "Use or disclose for directory purposes such information: (A) To members of the clergy; or (B) Except for religious affiliation, to other persons who ask for the individual by name."

In other words, clergy are the only category of visitor who may be told a patient's religious affiliation. This confirms privacy officer Barbara Demster's characterization in her AHIMA article, religious affiliation isn't just one more directory field. It's the one piece of information the rule fences off for clergy specifically.

This provision exists because pastoral visits are considered part of a patient's care and wellbeing, not an intrusion on privacy. However, it covers directory-type information, not the full medical record.

 

The opt-out requirement

The regulation also requires that patients be told, in advance, what's being shared and with whom, explicitly calling out clergy disclosures by name. Under § 164.510(a)(2), "A covered health care provider must inform an individual of the protected health information that it may include in a directory and the persons to whom it may disclose such information (including disclosures to clergy of information regarding religious affiliation) and provide the individual with the opportunity to restrict or prohibit some or all of the uses or disclosures..." This means patients must be told that clergy may be informed of their religious affiliation, and given a clear chance to say no.

 

The emergency and incapacity exception

Writing in the Journal of AHIMA, Demster notes that when a patient is incapacitated or facing an emergency and can't consent to or decline directory inclusion, providers may still disclose consistent with the patient's known wishes or their own best-interest judgment. The regulation notes this out at § 164.510(a)(3), "If the opportunity to object to uses or disclosures required by paragraph (a)(2) of this section cannot practicably be provided because of the individual's incapacity or an emergency treatment circumstance, a covered health care provider may use or disclose some or all of the protected health information permitted by paragraph (a)(1) of this section for the facility's directory, if such disclosure is: (A) Consistent with a prior expressed preference of the individual, if any, that is known to the covered health care provider; and (B) In the individual's best interest as determined by the covered health care provider, in the exercise of professional judgment."

In practice, this is the provision that covers on-call chaplains responding to codes and deaths, situations where there's no time, or no capacity on the patient's part, to walk through a formal opt-out conversation.

 

Chaplain or "just visiting the sick"?

Stacey A. Tovino, Research Professor at the Health Law & Policy Institute at the University of Houston Law Center, examined this in her article Hospital Chaplaincy Under the HIPAA Privacy Rule: Health Care or 'Just Visiting the Sick'? Her observation is that the confusion traces back to the Privacy Rule's own preamble, which states that "clergy or other religious practitioners that provide solely religious healing services are not health care providers within the meaning of this rule."

Tovino explains that this sentence has split opinion in the field. Some healthcare attorneys read it as barring hospitals from sharing protected health information with chaplains at all, treating them as outside visitors rather than clinical staff. Chaplains and their professional associations counter that the preamble fails to draw any distinction between them and community clergy dropping in from a local congregation, and that as credentialed members of the care team, they should have access comparable to social workers or psychologists.

That failure to distinguish is, in Tovino's view, the real problem. Nowhere in the Privacy Rule's operative text does HHS use the word "chaplain." The regulation speaks only of "clergy.” Tovino argues this suggests HHS may simply not have understood that hospital chaplains and visiting community clergy have different roles, one embedded in and accountable to the institution, the other an outside representative of a specific congregation.

She also notes why the "solely spiritual" language is hard to apply in practice. Much of what hospital chaplains actually do isn't just religious or spiritual. On that basis, Tovino suggests a real argument exists that at least some chaplain functions meet the Privacy Rule's definition of treatment. She points, too, to accreditation standards and state hospital-licensing regulations that require facilities to address patients' spiritual needs.

 

Compliance steps for chaplaincy programs

For chaplaincy departments and pastoral care organizations working within or alongside healthcare systems, a few practices could help:

  • Formal training and documentation. Chaplains who access PHI, whether through EHR systems or verbal handoffs from clinical staff, should receive the same HIPAA training as other workforce members, with records kept of completion.
  • Minimum necessary access. Chaplains generally don't need full chart access. Many hospitals configure limited views rather than granting access to lab results or full clinical documentation.
  • Secure documentation practices. Spiritual care notes, if entered into the medical record, should follow the same standards as clinical notes:. Personal chaplaincy journals or informal notes kept outside the EHR should never contain identifying patient details and should be stored securely, if kept at all.
  • Clear opt-out mechanisms. Consistent with § 164.510(a)(2)'s notice requirement, patients must be able to decline chaplaincy visits or ask that their religious affiliation not be shared.
  • Business associate agreements (BAAs). If an outside chaplaincy organization, endorsing denomination, or staffing agency provides services under contract with a healthcare facility, a BAA should be in place clarifying data-handling responsibilities.
  • Clarity around volunteer and community clergy. Facilities should have a written policy distinguishing paid, credentialed chaplains from visiting community clergy, and what access each group receives. Demster's AHIMA piece suggests this policy should go further, providing, a working definition of clergy (both external visiting clergy and internal pastoral staff), the specific rights and limitations on PHI access for each group under § 164.510(a), the credentialing or validation process the facility uses, and the procedures that apply in emergency or incapacity situations under § 164.510(a)(3).
  • Incident response awareness. Even well-meaning chaplains can make mistakes. Programs should have a clear process for reporting and addressing these situations.
  • Community education and communication. Demster also notes a step hospitals sometimes overlook, that is, proactively educating local faith communities about what the Privacy Rule does and doesn't allow.

 

FAQs

Does HIPAA apply differently to chaplains in hospice or home-health settings versus hospitals?

Yes, hospice and home health agencies are also covered entities, so hospice chaplains employed or contracted by the agency are bound by the same workforce rules as hospital chaplains.

 

Can a chaplain be personally fined or sanctioned for a HIPAA violation?

Individual workforce members, including chaplains, generally aren't directly liable under HIPAA enforcement.

 

How does clergy-penitent privilege interact with HIPAA?

Clergy-penitent privilege is a state evidentiary protection against compelled testimony, while HIPAA governs PHI handling and disclosure.

 

Do military or VA chaplains follow HIPAA?

VA chaplains fall under HIPAA as employees of a covered entity, while military chaplains operate under Department of Defense health information rules rather than HIPAA.