Practical Guidance for Physicians
Interactions with law enforcement can place physicians and healthcare teams in a difficult position: wanting to cooperate with public safety officials while also protecting patient privacy, complying with HIPAA, and preserving trust in the physician-patient relationship. The default rule under HIPAA is that protected health information, or PHI, should not be disclosed without the patient’s authorization unless a specific exception applies, such as a disclosure required by law or certain law enforcement-related circumstances.
The key is not to treat every law enforcement request the same. A police officer asking a question in a hallway, a detective presenting a subpoena, a sheriff’s deputy accompanying a patient in custody, and an officer requesting information during an emergency may all raise different legal and operational considerations. HIPAA permits certain disclosures to law enforcement without patient authorization, but those permissions are limited and fact-specific.
Start with the basics: Is this PHI?
Before disclosing patient information to law enforcement, a provider should consider whether it is protected under the federal Health Insurance Portability and Accountability Act (HIPAA) rules, which provide privacy protections for individually identifiable health information held by healthcare clinicians and their business associates. HIPAA “covered entities” include healthcare clinicians who transmit any health information in electronic form in connection with a transaction covered under the HIPAA regulations.
Protected health information (PHI) includes individually identifiable health information transmitted or maintained in electronic media or any other form or medium.
Individually identifiable health information is information created or received by a healthcare clinician that identifies the individual and relates to the past, present, or future physical/mental health or condition of an individual; the provision of healthcare to the individual; or payment for the provision of healthcare to the individual.1
Who Is Considered a Law Enforcement Official?
As outlined in the HIPAA Privacy Rule, a law enforcement official means an officer or employee of any agency or authority within the U.S., who is empowered by law to:
- Investigate or conduct an official inquiry into a potential violation of law; or
- Prosecute or otherwise conduct a criminal, civil, or administrative proceeding arising from an alleged violation of law.2
Law enforcement officials include (but are not limited to):
- Police officers and state troopers
- Sheriffs and sheriffs’ deputies
- District attorneys
- DEA and FBI special agents
- ICE officers
The default position under HIPAA is that PHI cannot be disclosed without the patient’s authorization, but there are some exceptions relevant to law enforcement, including where reporting is required by state law.
Key Considerations for Any Law Enforcement Interaction:
Don’t be afraid to ask for identification. Have they properly identified themselves? If the law enforcement official is not known to the clinician, the clinician must verify the identity and authority of the person.3 Processes should be in place for in-person, phone, and email interactions.
Share your side of the situation. Explain your understanding of the situation and the laws (HIPAA, etc.) that govern your actions of what you can and can’t do.
When trying to decide which federal or state law applies, the more restrictive one will likely apply. In general, if there is a state or federal law that is more restrictive than HIPAA (more protective of a patient’s privacy), clinicians are required to comply with the more restrictive law.
Document the details. Carefully document any disclosures and any supporting information about why the decision was made to provide information to law enforcement officials.4
Respect law enforcement and the challenges they are dealing with. Do not physically interfere with law enforcement officials or provide them false or misleading information.
Don’t provide more information than what is necessary. Unless disclosures made to law enforcement are required by law, they should be held to the “minimum necessary” standard. This means that when using or disclosing protected health information (PHI), the HIPAA-covered entity or clinician must make reasonable efforts to limit PHI to the minimum necessary to accomplish the purpose of the use, disclosure, or request.5 A clinician may rely upon the representations of a law enforcement official that the information requested is the minimum necessary for the stated purpose.6
For more information about the responsibility to patients while respecting the requests of law enforcement, download a copy of our resource booklet, Law Enforcement Interactions, available at www.copic.com/tools-and-resources. You will need to be logged in with your username and password to access this resource.
1 45 C.F.R. § 160.103
2 45 C.F.R. § 164.103
3 45 C.F.R. § 164.514(h)(1)(i)
4 45 C.F.R. § 164.514(h)(1)(ii)
5 45 C.F.R. § 164.502(b)
6 45 C.F.R. § 164.514(d)(3)(iii)(A)
The information provided herein does not, and is not intended to constitute legal, medical, or other professional advice; instead, this information is for general informational purposes only. The specifics of each state’s laws and the specifics of each circumstance may impact its accuracy and applicability, therefore, the information should not be relied upon for medical, legal, or financial decisions and you should consult an appropriate professional for specific advice that pertains to your situation.
Article originally published in Copic’s Copiscope 3Q26 newsletter.
