USConsent, privacy and disclosure

HIPAA Privacy and Patient Confidentiality

Applying the HIPAA Privacy, Security and Breach Notification Rules, 42 CFR Part 2 and state law in everyday practice

  • 3CPD hours
  • 20final questions
  • 80%pass mark
  • PDFcertificate

What you will learn

  • Identify covered entities, business associates and workforce members, and determine whether information is PHI or de-identified.
  • Apply the TPO permission and the minimum necessary standard, including its exceptions, to everyday disclosures.
  • Decide when and how to involve family members, friends and personal representatives, including parents of minors, under 164.510(b) and 164.502(g).
  • Recognize when a valid authorization is required and identify its core elements, including for psychotherapy notes and marketing.
  • Analyze requests from law enforcement, attorneys and courts using 164.512(e) and (f), and respond with a documented legal basis.
  • Apply 164.512(j) and your state's duty-to-protect rules to a patient's threat of violence, and document a defensible decision.
  • Explain HIPAA preemption, give examples of more stringent state laws, and describe the 2024 changes to 42 CFR Part 2.
  • Respond correctly to patient requests for access, amendment, accounting, restrictions and confidential communications.
  • Use safe practices for conversations, EHR access, messaging, telehealth, AI tools, social media and online reviews.
  • Apply the Breach Notification Rule, describe OCR and board enforcement, and plan a credible response that demonstrates accountability and remediation.

About this course

This course explains how licensed health professionals in the United States should protect, use and share patient information. It works through the HIPAA Privacy Rule in practical terms: covered entities and business associates, protected health information, treatment, payment and health care operations, the minimum necessary standard, family involvement, authorizations and the public interest disclosures in 45 CFR 164.512, including law enforcement requests, subpoenas and serious threats. It also covers patients' rights, the Security Rule basics, the Breach Notification Rule and OCR enforcement.

It is written for licensees across professions: physicians, nurses and APRNs, PAs, pharmacists, dentists and dental hygienists, psychologists, counselors, social workers, therapists and other licensed health care professionals. It is suitable for routine professional development, for clinicians moving into new roles or states, and for licensees responding to a privacy complaint, an employer investigation or a state board inquiry.

Confidentiality in the U.S. is shaped by a federal floor and fifty different state layers. The course explains when stricter state law applies, the 2024 changes to 42 CFR Part 2 for substance use disorder records, the current status of reproductive health privacy rules after the 2025 court decision, the duty to warn or protect after Tarasoff, snooping, social media and online reviews, and how state boards treat confidentiality failures. It ends with practical guidance on responding to a lapse with honesty, understanding and evidenced remediation.

Course facts

CPD value
Approximately 3 CPD hours (estimated learning time including knowledge checks, reflection and assessment)
Audience
U.S. licensed health professionals: physicians (MD/DO), nurses and APRNs, PAs, pharmacists, dentists and dental hygienists, psychologists, counselors, social workers and other licensees
Standards covered
HIPAA Privacy, Security, Breach Notification and Enforcement Rules (45 CFR Parts 160 and 164, including 164.502, 164.506, 164.508, 164.510, 164.512, 164.514, 164.520 to 164.530); 42 CFR Part 2 (2024 final rule); 42 U.S.C. 1320d-6; 45 CFR Part 171 (information blocking); state law examples (California Civil Code 43.92 and CMIA, Texas Health and Safety Code chapter 181, New York Regents Rules Part 29)
Format
Self-paced, gated lessons with knowledge checks, case studies and reflection
Assessment
20 scenario-based questions, 80% to pass (16 of 20)
Outcome
Certificate of completion and a written reflection for your CPD record
Alignment
Mapped to HHS OCR requirements and to confidentiality standards in the AMA Code of Medical Ethics, ANA Code of Ethics for Nurses (2025), APhA Code of Ethics, ADA Principles of Ethics and Code of Professional Conduct, AAPA Guidelines, FSMB and NCSBN social media guidance, and state practice acts. Not board-approved.

Syllabus

10 sections, 3 CPD hours, 20-question final assessment

  1. 1Foundations of confidentiality and HIPAA3 lessons
    • Confidentiality, privacy and trust in U.S. health care
    • The HIPAA framework: who and what it covers
    • Protected health information and de-identification
  2. 2Permitted uses and disclosures3 lessons
    • Treatment, payment and health care operations, and the minimum necessary standard
    • Family, friends and personal representatives
    • Authorizations, psychotherapy notes and marketing
  3. 3Disclosures without authorization and the duty to protect3 lessons
    • Public interest disclosures under 45 CFR 164.512
    • Law enforcement, subpoenas and court orders
    • Serious threats and the duty to warn or protect
  4. 4State law and specially protected information3 lessons
    • State law, preemption and your license
    • Substance use disorder records: 42 CFR Part 2 after the 2024 final rule
    • Reproductive health information and other sensitive data
  5. 5Patient rights over their information2 lessons
    • The Notice of Privacy Practices and the right of access
    • Amendment, accounting, restrictions and confidential communications
  6. 6Confidentiality in everyday and digital practice3 lessons
    • Conversations, workspaces and snooping
    • Electronic PHI: Security Rule basics, messaging, telehealth and AI tools
    • Social media, the media and online reviews
  7. 7Breaches, enforcement and professional accountability3 lessons
    • The Breach Notification Rule
    • OCR enforcement and penalties
    • Board discipline, employer action and showing insight and remediation
  8. 8Conclusion and key points1 lesson
    • Conclusion and key points
  9. 9References and further reading1 lesson
    • References and further reading
  10. 10Your reflective account1 lesson
    • Your reflective account

Who this course is for

U.S. licensed health professionals: physicians (MD/DO), nurses and APRNs, PAs, pharmacists, dentists and dental hygienists, psychologists, counselors, social workers and other licensees.

Your certificate

Certificate of completion. Not CE or CME credit unless accepted by your board.

  • Your name, the course title and the CPD hours
  • Completion date and a unique certificate ID that can be verified
  • Downloads as a PDF; save it to your portfolio

Questions about this course

How is this different from my employer's annual HIPAA training?

Workforce HIPAA training is usually a short compliance module. This course is written for licensed professionals making disclosure decisions: involving family, responding to law enforcement and attorneys, the duty to protect, 42 CFR Part 2 records and state laws stricter than HIPAA, plus how confidentiality breaches lead to board discipline.

How fast must patients be notified after a HIPAA breach?

Under the Breach Notification Rule, you must notify the people affected without unreasonable delay, and in any case within 60 days of discovering the breach. If 500 or more people are affected, HHS must also be told within 60 days, and the media where more than 500 residents of a state are affected. Smaller breaches go on an annual log to HHS.

What changed for substance use disorder records under 42 CFR Part 2?

The 2024 final rule, with compliance due by February 16, 2026, allows a single consent for future treatment, payment and health care operations disclosures, applies HIPAA breach notification, aligns penalties with HIPAA and creates a protected category of SUD counseling notes. Records still cannot be used in proceedings without consent or a court order.

How quickly must I respond to a patient's request for their records?

Under 45 CFR 164.524 a covered entity must act on a request for access within 30 days, with one 30-day extension. Psychotherapy notes and information compiled for legal proceedings are excluded. The course also covers amendment, accounting of disclosures, restrictions and confidential communications.

Does this HIPAA course give CE credit or a HIPAA certification?

No. The government offers no official HIPAA certification for individuals, and this independent course carries no CE or CME credit. What you do get, after scoring 80% on a 20-question test, is our certificate of completion. The course costs $89 for about 3 hours.

Related courses

All courses
US$893 CPD hours
Enrol now