HIPAA applies to "covered entities" (health plans, healthcare clearinghouses, and providers who transmit health information electronically for billing) and their "business associates." A hospital is a covered entity. A homeless shelter usually is not. A shelter that only provides beds, meals, and case management is generally not a health care provider under HIPAA, so it is not directly bound by the Privacy Rule. Once a hospital sends protected health information (PHI) to a shelter, the hospital remains responsible for ensuring the disclosure was permitted in the first place. Shelters that run an on-site clinic and bill insurance electronically may be covered entities themselves.

 

The treatment exception

The Privacy Rule allows a covered entity to use and disclose PHI for treatment, payment, and health care operations without the patient's written authorization. The regulation at 45 CFR § 164.506(a) says a covered entity "may use or disclose protected health information for treatment, payment, or health care operations as set forth in paragraph (c) of this section, provided that such use or disclosure is consistent with other applicable requirements of this subpart."

Treatment in this case is defined in 45 CFR § 164.501 as, "Treatment means the provision, coordination, or management of health care and related services by one or more health care providers, including the coordination or management of health care by a health care provider with a third party; consultation between health care providers relating to a patient; or the referral of a patient for health care from one health care provider to another."

This means, if a patient needs wound care, medication reminders, or a quiet place to recuperate, a hospital can often share the information a shelter needs to support that plan of care, because the definition reaches coordination "by a health care provider with a third party." However, the rule's most direct permission, § 164.506(c)(2), says a covered entity "may disclose protected health information for treatment activities of a health care provider." A shelter that isn't a provider doesn't fit that provision, so the disclosure should be tied to the patient's own care plan.

Furthermore, the "minimum necessary" standard does not apply to "[d]isclosures to or requests by a health care provider for treatment." (45 CFR § 164.502(b)(2)(i)). HHS explains that the Privacy Rule otherwise "generally requires covered entities to take reasonable steps to limit the use or disclosure of, and requests for, protected health information to the minimum necessary to accomplish the intended purpose." Since a shelter that is not a provider falls outside that exception, it becomes safer to treat the disclosure as limited and share only what the shelter needs.

 

What should and shouldn't be shared

A shelter staff member might need information such as:

  • Mobility limits, wound care, or dietary needs
  • Medication schedules and any assistance required
  • Warning signs that should prompt a call to a clinician
  • Follow-up appointment dates and transportation needs
  • Infection-control precautions, where relevant to others in a congregate setting

They wouldn't normally need a full diagnosis list, mental health history, billing information, or details of unrelated conditions. Sharing less is better practice and reduces exposure if the information is mishandled.

Limiting disclosures protects patients from more than a data breach. In a 2002 issue of Healing Hands, the newsletter of the HCH Clinicians' Network, Jan Caughlan, a clinician with Baltimore's Health Care for the Homeless project, warned that information sharing among agencies can backfire. Her worry was that shelters might turn away clients with latent tuberculosis or other communicable diseases. Information shared to improve access to services could end up restricting it, which is a reason to give a shelter only what it needs to support the care plan, and to stick to precautions and instructions rather than diagnoses.

 

What the patients say matters

Under the rules governing disclosures to people involved in a patient's care, a hospital may share relevant information if the provider either "provides the individual with the opportunity to object to the disclosure, and the individual does not express an objection," or "reasonably infers from the circumstances, based on the exercise of professional judgment, that the individual does not object to the disclosure." (45 CFR § 164.510(b)(2)(ii)–(iii))

If the patient is incapacitated or the situation is an emergency, the rule allows the provider, "in the exercise of professional judgment," to "determine whether the disclosure is in the best interests of the individual and, if so, disclose only the protected health information that is directly relevant to the person's involvement with the individual's care." (45 CFR § 164.510(b)(3))

When planning a discharge to a shelter, explain what will be shared, with whom, and why, and document the patient's response. Under § 164.508(a)(1), when a covered entity has a valid authorization, "such use or disclosure must be consistent with such authorization."The patient defines what information is shared and for how long, and it covers situations where the treatment exception is arguable.

Healing Hands noted that notifying homeless clients and getting their consent is harder than with housed patients, because people who are homeless are harder to locate and agencies have limited resources to prepare written materials clients can understand. Linda Reeder, a clinical information systems and HIPAA consultant, pointed to mobility, literacy, and language barriers as challenges.

 

Special categories

Some information carries stricter protection than ordinary PHI:.

  • Substance use disorder records. Federal rules at 42 CFR Part 2 protect records from certain federally assisted substance use treatment programs. These rules are stricter than HIPAA and require patient consent for disclosure. Under 42 CFR § 2.31(a), a written consent "may be paper or electronic" and must include required elements, among them "a description of each purpose of the requested use or disclosure."
  • Psychotherapy notes. HIPAA gives these notes special protection, "a covered entity must obtain an authorization for any use or disclosure of psychotherapy notes," subject to a short list of exceptions. They are distinct from the general mental health information in a medical chart.
  • State law. Many states impose stricter rules for mental health, HIV status, and other sensitive information. For example, California's Confidentiality of Medical Information Act and Lanterman-Petris-Short Act add protections for medical and mental health records. New York's Public Health Law Article 27-F places limits on disclosing HIV-related information, and Illinois's AIDS Confidentiality Act does the same. When state law is more protective, the stricter rule must be followed.

Emergency exception

HIPAA at 45 CFR § 164.512(j)(1)(i) permits disclosure without consent when a provider believes in good faith that it "[i]s necessary to prevent or lessen a serious and imminent threat to the health or safety of a person or the public," and the disclosure goes to someone reasonably able to prevent or lessen that threat. This is a narrow exception but it can apply in emergencies.

 

Practical safeguards

Even when sharing is permitted, how you share matters.

  • Use secure channels. Avoid unencrypted email, text messages, or personal fax lines. Use encrypted systems or a direct, verified phone call.
  • Verify the recipient. Confirm you are speaking with the right shelter and the right staff member before disclosing anything.
  • Document everything. Record what was shared, why, and the patient's agreement. Signed authorizations must be documented and retained under the rule. Reeder put it this way in Healing Hands, "People and processes present more serious risks to patient confidentiality than technology does."
  • Build formal relationships. Written partnership agreements or data-sharing protocols clarify expectations, and a signed confidentiality understanding with the shelter adds a protection even if HIPAA does not require it. Healing Hands recommended urging social service agencies not bound by HIPAA to comply voluntarily, so that all agencies sharing health information work from one standard. It also described a Nashville program, Bridges to Care, that combined both safeguards discussed here. Participants signed an authorization before their information was shared, and planners intended to create tiered levels of access to address the concerns of substance use programs and domestic violence shelters.
  • Train both sides. Hospital case managers need to know the rules, and shelter staff need to understand that the information is confidential and should be shared internally only on a need-to-know basis. Healing Hands made the same point from the information systems side. Peter Malloy of Boston Health Care for the Homeless said that only about a fifth of HIPAA compliance involves information systems, and the rest is developing policies and procedures and educating staff. Encryption helps little if the people using it haven't been trained.

Read also: Secure, HIPAA compliant email for healthcare

 

FAQs

Can a patient take back their consent after giving it?

Yes, a patient can usually revoke an authorization in writing, though it doesn't undo disclosures already made.

 

Does HIPAA apply to spoken information as well as written records?

Yes, HIPAA covers PHI in any form, including verbal conversations.

 

What happens if patient information is shared improperly?

The covered entity may have to notify affected patients and regulators, and it can face fines or other penalties.

 

Are there special rules for minors?

Usually a parent or guardian controls a minor's health information, but state laws often make exceptions for certain types of care.