HIPAA and applicable state consent and confidentiality laws govern how covered healthcare providers may share minors’ clinical records by email. Beyond these, specific regulations also cover substance abuse treatment files, educational documents, and digital platforms. To understand who's allowed to receive an email with results, treatment instructions, or billing details, you first need to identify the governing law for your HIPAA email.
HHS guidance notes, when discussing how a parent can receive an email of a minor’s record, “when such access is not inconsistent with state or other law.” Therefore, you may need to consider that the family member's usual address on record is not always the appropriate contact for all services.
Establish the parent’s authority under HIPAA
Parents typically can act as the personal representative for a minor patient, which allows them to act on behalf of the patient and exercise HIPAA rights. According to the HHS, there are situations where you would not allow a parent to be a personal representative. It can happen if the minor is legally empowered to consent to their own care, if another individual is designated to make healthcare choices for them, or if a parent has already given consent for the minor to access confidential treatment.
A provider may decline to treat a parent as the minor’s personal representative when there is a reasonable belief that the child has experienced or may experience abuse or neglect by that parent, or that recognizing the parent could endanger the child. The provider must also determine, using professional judgment, that treating the parent as the representative would not be in the child’s best interests. Before you email a minor's record, confirm who has the authority to decide on the relevant care. Authority to receive asthma care instructions does not automatically establish access to confidential counseling records.
Check state consent and confidentiality laws separately
Knowing if you can get a parent to consent to a minor’s treatment and if they can receive records about the minor’s care are two different questions. Depending on your state law, they may allow certain services to have unique rules.
According to the HHS, HIPAA will follow state law on how a parent can access a minor’s record. Even if the parent is not the minor’s personal representative. If state law does not specify how a parent can access the record and you are dealing with an exception listed above, a provider can use professional judgment to allow or deny the parent access within state law. If you are an employee preparing to send an email about a minor’s counseling session, you should look at the consent and confidentiality laws for your area. You may need to exclude the parent from the email or not attach a summary of visits.
Apply Part 2 to covered substance use records
Records from a federally assisted program that provides diagnosis, treatment, or referral for substance use are protected under 42 CFR Part 2. Just because substance use is mentioned in a medical record, it does not automatically apply to the record. Updated rules now allow a patient to provide one consent that covers treatment, payment, and healthcare operations.
Part 2 has rules that allow only a minor to provide consent if they are able to get treatment under state law. This means only the minor can provide written consent to disclose the record to another party, including a parent, for reimbursement. If the minor is not able to get treatment without parental consent, then you will most likely need both consents to disclose. Always know what consent you have on file or if an exception applies to 42 CFR Part 2 before emailing a parent about a bill that will disclose this type of treatment.
Assess online services under COPPA and FTC rules
Online services that are directed to children under 13 or knowingly collect information on children under 13 fall under the Children’s Online Privacy Protection Act (COPPA). There are some exceptions, but you should obtain parental consent before collecting any information. Before you email your patient a link to track their symptoms, make sure you know who is running the app, what information it is collecting, and if it will be considered a business associate of your practice. COPPA will not apply to every consumer health service that isn't covered by HIPAA. Some will fall under the FTC’s health breach notification rule and will require you to notify patients in case of a breach of their unsecured identifiable health information.
Confirm who can read the minor’s messages
A 2021 US study published in JAMA Network Open examined 3,429 accounts belonging to patients aged 13–18 at three academic children’s hospitals. They stated that “Guardian access of adolescent patient portal accounts could compromise adolescents’ confidentiality.”
While these findings were made from a calculation of algorithm-based data on a handful of patients' portal accounts, it can give you an idea of who may have access to an email address. Always know who can view the email you are sending to a minor about their care. Confirm the appropriate recipient and verify their email address before sending. Also take care to remind your patient to be cautious if they are using a shared device.
FAQs
Does every treatment email require written authorization?
HIPAA generally permits treatment disclosures without authorization, although state law, Part 2, or specially protected records may impose additional conditions.
Can HIPAA prevent mandatory child abuse reporting?
No, HIPAA permits reports of suspected child abuse or neglect to appropriate authorities, including reports required by state law.
Does HIPAA require a BAA with a specialist receiving a treatment referral?
No, HIPAA does not require a BAA solely for provider-to-provider treatment disclosures, although other confidentiality requirements may still apply.
