HIPAA and Subpoenas: When Can PHI Be Disclosed? (2026)

Under 45 CFR 164.512(e), a covered entity may disclose protected health information in response to a subpoena in two situations: when a court order authorizes the disclosure, or when an attorney-issued subpoena is accompanied by satisfactory assurances of individual notice or a qualified protective order.
Receiving a subpoena for patient medical records puts healthcare providers, hospitals, and health plans in a difficult position. Federal law under HIPAA permits certain disclosures of protected health information for judicial and administrative proceedings, but only when specific procedural safeguards are met. Getting it wrong can result in a Privacy Rule violation, an OCR investigation, and civil monetary penalties.
This article breaks down exactly when and how PHI can be disclosed in response to subpoenas, court orders, and other legal process under the HIPAA Privacy Rule.
Court Orders vs. Subpoenas Under HIPAA
The HIPAA Privacy Rule draws a critical distinction between court orders and subpoenas. The two require different levels of safeguards before a covered entity can release PHI.
Court Orders (45 CFR 164.512(e)(1)(i))
When a court or administrative tribunal issues an order directing the disclosure of PHI, covered entities may comply by releasing the information. However, the disclosure is limited to the PHI expressly authorized by the order. A covered entity cannot treat a court order as a blank check to produce an entire medical record if the order only requests specific treatment notes or billing records.
A court order carries the authority of a judge or magistrate who has already evaluated the need for the information. Because of that judicial oversight, the Privacy Rule does not require additional safeguards like notice to the patient or a protective order.
Subpoenas Without a Court Order (45 CFR 164.512(e)(1)(ii))
Subpoenas issued by attorneys (rather than judges) present a different situation. These discovery subpoenas, subpoenas duces tecum, and similar lawful process instruments lack the judicial oversight that court orders carry. Before disclosing PHI in response to a subpoena not accompanied by a court order, the covered entity must receive "satisfactory assurances" from the requesting party.
This requirement exists because an attorney-issued subpoena does not involve a judge weighing the privacy interests of the patient against the need for the records.
The Satisfactory Assurances Requirement
Under 45 CFR 164.512(e)(1)(ii), a covered entity can disclose PHI in response to a subpoena, discovery request, or other lawful process that is not accompanied by a court order only after receiving satisfactory assurances. The requesting party must demonstrate that one of two conditions has been met.
Option 1: Notice to the Individual
The requesting party provides a written statement and documentation showing that reasonable efforts were made to notify the individual whose PHI is being sought. According to HHS FAQ 706, the notice must include:
- Sufficient information about the litigation or proceeding
- A description of the information being requested
- The time and place to raise objections with the court or administrative tribunal
- Evidence that the time period for raising objections has elapsed and either no objections were filed or all objections have been resolved
The notice can go to the individual directly or to their attorney, as confirmed by HHS FAQ 707. If the individual has legal representation in the proceeding, notice to the attorney satisfies this requirement.
Option 2: Qualified Protective Order
As an alternative to individual notice, the requesting party can provide documentation that they have obtained, or are seeking, a qualified protective order. Under the Privacy Rule, a qualified protective order must:
- Prohibit the parties from using or disclosing the PHI for any purpose other than the specific litigation or proceeding
- Require the return or destruction of all PHI (including all copies) at the conclusion of the litigation or proceeding
The requesting party satisfies this requirement by showing either that the parties have agreed to a qualified protective order and presented it to the court, or that the requesting party has filed a motion seeking a qualified protective order from the court.
When the Subpoena Itself Serves as Satisfactory Assurance
HHS FAQ 708 clarifies an important practical point. If the subpoena itself, on its face, demonstrates that the individual received adequate notice, a separate written statement is not required. This applies when the subpoena shows that the individual is a party to the litigation, the individual or their attorney was served with the request, and the time for objections has passed without any being filed.
What Covered Entities Can Do on Their Own
A covered entity does not have to rely solely on assurances from the requesting party. Under 45 CFR 164.512(e)(1)(ii)(B) and (e)(1)(vi), the covered entity itself can take either of the following steps:
- Provide notice directly: The covered entity can send its own written notice to the individual, including the information required under the rule, and wait for the time period for objections to expire.
- Seek a qualified protective order: The covered entity can file its own motion for a qualified protective order before disclosing the records.
This option gives covered entities more control over the process, particularly when they are uncertain about whether the requesting party has actually met the satisfactory assurances standard.
The Minimum Necessary Standard
All disclosures of PHI for judicial and administrative proceedings remain subject to the minimum necessary standard under 45 CFR 164.502(b) and 164.514(d). Even when a covered entity has proper authorization to release records in response to a subpoena or court order, it must limit the disclosure to the minimum amount of PHI reasonably necessary to fulfill the request.
In practice, this means a covered entity should review the subpoena carefully and produce only the records specifically described. If a subpoena requests "all medical records" but the underlying case involves a specific injury or treatment period, the covered entity should consider whether producing the complete record truly meets the minimum necessary standard.
Grand Jury Subpoenas: A Different Framework
Grand jury subpoenas operate under an entirely separate provision of the Privacy Rule. Under 45 CFR 164.512(f)(1)(ii)(B), covered entities may disclose PHI in response to a grand jury subpoena without requiring satisfactory assurances, individual notice, or a qualified protective order.
The rationale is straightforward. Grand jury proceedings are conducted under strict judicial supervision and secrecy requirements. Federal Rule of Criminal Procedure 6(e) imposes secrecy obligations on all participants, providing built-in privacy protections that substitute for the satisfactory assurances otherwise required.
This means healthcare providers who receive a federal or state grand jury subpoena for patient records can comply without taking the additional steps required for civil litigation subpoenas. The disclosure is still limited to the information the grand jury subpoena specifically requests.
Law Enforcement Disclosures (45 CFR 164.512(f))
Beyond subpoenas and court orders, the Privacy Rule separately addresses disclosures to law enforcement under 45 CFR 164.512(f). These provisions cover situations outside of standard judicial proceedings.
Disclosures Required by Law
Covered entities must disclose PHI when required by a law that compels reporting. Mandatory reporting statutes for gunshot wounds, suspected abuse, or certain communicable diseases fall into this category.
Court Orders, Warrants, and Administrative Requests
Under 45 CFR 164.512(f)(1)(ii), covered entities can disclose PHI in response to:
- Court orders
- Court-ordered warrants or search warrants
- Subpoenas or summons issued by a judicial officer
- Grand jury subpoenas
- Administrative requests, including administrative subpoenas or civil investigative demands
For administrative requests specifically, the Privacy Rule imposes three conditions: the information must be relevant and material to a legitimate law enforcement inquiry, the request must be specific and limited in scope, and de-identified information could not reasonably serve the same purpose.
Limited Information for Identification Purposes
Law enforcement may obtain limited identifying information to locate a suspect, fugitive, material witness, or missing person. This is restricted to basic identifiers: name, address, date and place of birth, Social Security number, blood type, injury type, date and time of treatment, and a physical description. DNA analysis, dental records, and typing or tissue samples are excluded from this limited disclosure.
Substance Use Disorder Records: 42 CFR Part 2
Records covered by the federal confidentiality rules for substance use disorder treatment programs (42 CFR Part 2) follow a stricter path than the HIPAA subpoena rules above. Under 42 CFR 2.61, when a subpoena seeks Part 2 records, the holder may not use or disclose them in response to the subpoena unless a court of competent jurisdiction has entered an authorizing order under the Part 2 regulations. A subpoena with HIPAA satisfactory assurances is not enough for these records.
The reverse also holds. A Part 2 authorizing order does not by itself compel disclosure: a subpoena or similar legal mandate must also be issued, and the holder may decline to disclose if there is none or if it has expired or been quashed.
De-Identification as an Alternative
In some situations, covered entities can respond to legal requests by providing de-identified information rather than full PHI. Under 45 CFR 164.514, information qualifies as de-identified through two methods:
- Safe Harbor: Removing all 18 categories of identifiers specified in the rule, including names, geographic data smaller than a state, dates (other than year), phone numbers, email addresses, Social Security numbers, and medical record numbers.
- Expert Determination: A qualified statistical expert certifies that the risk of identifying any individual from the data is very small.
De-identified information is no longer considered PHI under HIPAA, and its disclosure does not trigger Privacy Rule requirements. For reporting HIPAA breaches, this distinction matters because disclosures of properly de-identified data do not constitute breaches.
State Laws That Provide Stronger Protections
HIPAA sets a federal floor, not a ceiling. Under 45 CFR 160.203, when a state law is "more stringent" than HIPAA (meaning it provides greater privacy protections), the state law prevails. Several states impose additional requirements for medical records subpoenas that go beyond HIPAA's satisfactory assurances framework.
California
The California Confidentiality of Medical Information Act (CMIA), codified at Cal. Civ. Code Section 56.10, generally requires patient authorization before disclosing medical information. Its subpoena exception is not a copy of HIPAA's: Section 56.10(b)(3) states that a provider shall disclose medical information when compelled by a party to a court or agency proceeding through a subpoena, subpoena duces tecum, or other discovery provision, and it does not itself contain HIPAA's satisfactory-assurances or qualified-protective-order conditions. A California provider still has to meet the federal satisfactory-assurances rule before producing PHI.
California's own notice protection for records subpoenas in civil cases sits in Code of Civil Procedure Section 1985.3. For a subpoena duces tecum seeking a consumer's personal records from a physician, hospital, clinic, or other listed witness, the subpoenaing party must serve the consumer with a copy of the subpoena and the required notice not less than 10 days before the production date and at least five days before serving the records custodian (plus extra time for mail service), and must give the custodian proof of that service before the records are produced. Mental health records receive separate, additional confidentiality protection under California's Lanterman-Petris-Short Act (Welf. & Inst. Code Section 5328), which makes mental health treatment records confidential and restricts their disclosure to a specific list of authorized circumstances beyond the general CMIA subpoena framework.
New York
New York Public Health Law Article 27-F requires written informed consent for any disclosure of HIV-related information, even in response to a subpoena. Mental health records receive additional protection under Mental Hygiene Law Section 33.13, which generally requires a court order (not just a subpoena) for disclosure.
Texas
Texas Health and Safety Code Chapter 181 (the Texas Medical Records Privacy Act) adds state-level privacy duties on top of HIPAA. One frequently cited deadline in that chapter, Section 181.102, is a patient-access rule rather than a subpoena rule: a provider using an electronic health records system capable of fulfilling the request must give a person their electronic health record in electronic form no later than the 15th business day after receiving the person's written request. It does not set a deadline for responding to a subpoena.
General Principle
Covered entities operating in multiple states must identify and comply with the most protective applicable law for each disclosure. When a state law requires a court order where HIPAA would permit disclosure with satisfactory assurances alone, the state law controls.
Penalties for Improper Disclosure
Disclosing PHI in response to a subpoena without meeting the Privacy Rule's requirements constitutes a HIPAA violation. The HHS Office for Civil Rights (OCR) investigates complaints and can impose civil monetary penalties under the HIPAA Enforcement Rule.
OCR has documented cases where covered entities improperly disclosed PHI in response to subpoenas. In one enforcement example, a public hospital disclosed a patient's PHI in response to a subpoena that was not accompanied by a court order, without first verifying that the requesting party had provided satisfactory assurances of notice to the individual or a qualified protective order.
Penalty tiers under the HITECH Act depend on the level of culpability, and HHS adjusts the dollar amounts for inflation, publishing them in the table at 45 CFR 102.3. In the 2024 adjustment printed in that table, amounts ran from a $141 minimum per violation for violations the entity did not know about to a $2,134,831 maximum (and calendar-year cap) for willful neglect that is not corrected. Later adjustments change these figures, so check the current 45 CFR 102.3 table for the amounts that apply to a given violation.
Practical Steps for Covered Entities
Healthcare providers and health plans that receive subpoenas for medical records can follow a structured approach to stay compliant.
Step 1: Determine the type of legal process. Identify whether the request is a court order, an attorney-issued subpoena, a grand jury subpoena, or an administrative demand. Each follows a different pathway under the Privacy Rule.
Step 2: Verify satisfactory assurances (for non-court-order subpoenas). Request and review the written statement and documentation from the requesting party. Confirm that the individual received proper notice, or that the parties have presented an agreed qualified protective order to the court or the requesting party has asked the court for one.
Step 3: Apply the minimum necessary standard. Review the scope of the request and limit the disclosure to the specific records identified. Do not produce an entire medical chart when the subpoena requests records from a specific date range or related to a specific condition.
Step 4: Check for specially protected records. If the request reaches substance use disorder treatment records covered by 42 CFR Part 2, do not disclose them on a subpoena alone; a Part 2 authorizing court order is also required (42 CFR 2.61).
Step 5: Check state law. Determine whether the state where the patient was treated or where the provider is located imposes additional requirements. If state law is more restrictive, follow the state law.
Step 6: Document the process. Maintain records of the subpoena, the satisfactory assurances received, the PHI disclosed, and the legal basis for the disclosure. HIPAA requires covered entities to retain documentation of disclosures for six years under 45 CFR 164.530(j).
Understanding these requirements is part of the broader framework of HIPAA privacy protections that govern how covered entities handle protected health information across all contexts, not only legal proceedings.
This article provides legal information, not legal advice. Laws and regulations change, and their application depends on specific facts and circumstances. Consult an attorney for advice specific to your situation.
Frequently Asked Questions
Can a lawyer subpoena medical records without a court order?
Under HIPAA, an attorney can issue a subpoena for medical records without a court order, but the covered entity cannot release the records until it receives satisfactory assurances. The attorney must demonstrate that the patient received proper notice of the request (with time to object) or that a qualified protective order has been obtained or requested. Without these assurances, the covered entity should not disclose the PHI (45 CFR 164.512(e)(1)(ii)).
Does a patient have to be notified before their medical records are subpoenaed?
In most cases involving civil litigation subpoenas, yes. The HIPAA Privacy Rule requires that either the requesting party provides written notice to the individual (or their attorney) with sufficient time to raise objections, or that a qualified protective order has been agreed to or requested from the court. Grand jury subpoenas are the notable exception, as they do not require individual notice due to the secrecy protections built into grand jury proceedings (45 CFR 164.512(f)(1)(ii)(B)).
What is a qualified protective order under HIPAA?
A qualified protective order is a court order or stipulation between parties that restricts how PHI can be used in litigation. It must prohibit the use or disclosure of PHI for any purpose beyond the specific proceeding and require the return or destruction of all copies of the PHI when the proceeding ends. Securing a qualified protective order (or documenting that one has been requested from the court) is one of the two ways to satisfy the satisfactory assurances requirement for subpoenas without court orders.
Can a hospital refuse to comply with a subpoena for medical records?
A covered entity can and should decline to produce medical records in response to a subpoena if the requesting party has not provided satisfactory assurances of either individual notice or a qualified protective order. Producing records without these safeguards violates the HIPAA Privacy Rule and can lead to OCR enforcement action. The covered entity should notify the requesting party of the deficiency rather than simply ignoring the subpoena.
Do state laws override HIPAA when it comes to medical records subpoenas?
State laws override HIPAA only when they are more stringent, meaning they provide greater privacy protections for individuals. Under 45 CFR 160.203, the more protective law controls. For example, New York requires a court order (not just a subpoena with notice) for HIV-related records, and California imposes additional confidentiality protections on mental health records under the Lanterman-Petris-Short Act (Welf. & Inst. Code Section 5328), separate from the general CMIA subpoena framework. Covered entities must comply with both HIPAA and applicable state law, following whichever is more restrictive.
Updates
Corrected the satisfactory-assurances description, the California and Texas state-law sections, and the penalty figures, and added the 42 CFR Part 2 court-order requirement for substance use disorder records.
Governing law re-checked for recent changes
Corrected the California mental-health-records disclosure rule, which the article had wrongly attributed to Cal. Civ. Code 56.10; the heightened protection actually comes from the separate Lanterman-Petris-Short Act (Welf. & Inst. Code 5328).
Governing law re-checked for recent changes
The Law Behind This Article
This article rests on the statutory provisions below, held in our own legal record and retrieved from the official source. Tap a section to read the operative text.
Code of Federal Regulations Title 45
§ 164.512Uses and disclosures for which an authorization or opportunity to agree or object is not required.In forcecited in 5 of our articles
Except as provided by § 164.502(a)(5)(iii), a covered entity may use or disclose protected health information without the written authorization of the individual, as described in § 164.508, or the opportunity for the individual to agree or object as described in § 164.510, in the situations covered by this section, subject to the applicable requirements of this section and § 164.509. When the covered entity is required by this section to inform the individual of, or when the individual may agree to, a use or disclosure permitted by this section, the covered entity's information and the individual's agreement may be given verbally. (a) Standard: Uses and disclosures required by law. (1) A covered entity may use or disclose protected health information to the extent that such use or disclosure is required by law and the use or disclosure complies with and is limited to the relevant requirements of such law. (2) A covered entity must meet the requirements described in paragraph (c), (e), or (f) of this section for uses or disclosures required by law. (b) Standard: Uses and disclosures for public health activities —(1) Permitted uses and disclosures.
Official text (excerpt) · last checked 2026-09-16 · Read the full text in our law library · Verify at ecfr.gov
Cited in 580 court opinions in our collectionLatest citing opinion in our collection: 2026
Opinions citing this section in our collection:
- Northwestern Memorial Hospital v. John Ashcroft, Attorney General of the United States (Court of Appeals for the Seventh Circuit 2004, 362 F.3d 923)“…f this subchapter.”) (emphasis added). Of relevance here is 45 C.F.R. 164.512(e)(l)(i), which authorizes the disclosu…”
- Law v. Zuckerman (District Court, D. Maryland 2004, 307 F. Supp. 2d 705)“…patient’s health information may be disclosed pursuant to 45 C.F.R. § 164.512 (e)(l)(i), which states that disclosure…”
- Bayne v. Provost (District Court, N.D. New York 2005, 359 F. Supp. 2d 234)“…h information may be disclosed or disseminated pursuant to 45 C.F.R. § 164.512 . See, supra, 2004 WL 555…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Also relied on in: Does a Failed Drug Test Show Up on Your Record?, 45 C.F.R. § 164.512 Explained: HIPAA Disclosure Rules, Statutes Explained: Plain-English Guides to Major US Laws
§ 164.502Uses and disclosures of protected health information: General rules.In forcecited in 16 of our articles
(a) Standard. A covered entity or business associate may not use or disclose protected health information, except as permitted or required by this subpart or by subpart C of part 160 of this subchapter. (1) Covered entities: Permitted uses and disclosures. A covered entity is permitted to use or disclose protected health information as follows: (i) To the individual; (ii) For treatment, payment, or health care operations, as permitted by and in compliance with § 164.506; (iii) Incident to a use or disclosure otherwise permitted or required by this subpart, provided that the covered entity has complied with the applicable requirements of §§ 164.502(b), 164.514(d), and 164.530(c) with respect to such otherwise permitted or required use or disclosure; (iv) Except for uses and disclosures prohibited under § 164.502(a)(5)(i), pursuant to and in compliance with a valid authorization under § 164.508; (v) Pursuant to an agreement under, or as otherwise permitted by, § 164.510; and (vi) As permitted by and in compliance with any of the following: (A) This section. (B) Section 164.512 and, where applicable, § 164.509. (C) Section 164.514(e), (f), or (g).
Official text (excerpt) · last checked 2026-09-16 · Read the full text in our law library · Verify at ecfr.gov
Cited in 290 court opinions in our collectionLatest citing opinion in our collection: 2026
In the courts (editorial summary, independently checked):Section 164.502 is the Privacy Rule's general bar on using or disclosing protected health information. Opis Management Resources, LLC (2013) held it preempted a Florida law compelling release of deceased residents' records to a spouse or named representative; Disability Rights Texas v. Hollis (2024) applied the required-by-law exception.
Opinions citing this section in our collection:
- Northwestern Memorial Hospital v. John Ashcroft, Attorney General of the United States (Court of Appeals for the Seventh Circuit 2004, 362 F.3d 923)“…sub-part or by subpart C of part 160 of this subchapter.” 45 C.F.R. § 164.502 (a). Before looking to the various exce…”
- Opis Management Resources, LLC v. Secretary, Florida Agency for Health Care Administration (Court of Appeals for the Eleventh Circuit 2013, 713 F.3d 1291)✓Nursing homes refused to give deceased residents' records to spouses who were not personal representatives under 45 CFR 164.502(g); the Eleventh Circuit held Florida's statute compelling those blanket disclosures was preempted as an obstacle to HIPAA's privacy objectives.
- United States ex rel. Baltazar v. Warden (District Court, N.D. Illinois 2014, 302 F.R.D. 256)“…nduct was protected under HIPAA’s whistleblower exception, 45 C.F.R. § 164.502 (j)(l). 2 Regardless of whether Baltaz…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Also relied on in: Connecticut Recording Laws (2026): Hybrid Consent Rules Explained, Michigan Recording Laws (2026): Consent Rules and Participant Exception, How to Find Old Medical Records Online
§ 164.514Other requirements relating to uses and disclosures of protected health information.In forcecited in 2 of our articles
(a) Standard: De-identification of protected health information. Health information that does not identify an individual and with respect to which there is no reasonable basis to believe that the information can be used to identify an individual is not individually identifiable health information. (b) Implementation specifications: Requirements for de-identification of protected health information. A covered entity may determine that health information is not individually identifiable health information only if: (1) A person with appropriate knowledge of and experience with generally accepted statistical and scientific principles and methods for rendering information not individually identifiable: (i) Applying such principles and methods, determines that the risk is very small that the information could be used, alone or in combination with other reasonably available information, by an anticipated recipient to identify an individual who is a subject of the information; and (ii) Documents the methods and results of the analysis that justify such determination; or (2)(i) The following identifiers of the individual or of relatives, employers, or household members of the individual,…
Official text (excerpt) · last checked 2026-07-28 · Read the full text in our law library · Verify at ecfr.gov
Cited in 53 court opinions in our collectionLatest citing opinion in our collection: 2025
Opinions citing this section in our collection:
- Northwestern Memorial Hospital v. John Ashcroft, Attorney General of the United States (Court of Appeals for the Seventh Circuit 2004, 362 F.3d 923)“…e, except as permitted by paragraph (c) of this section; 45 C.F.R. § 164.514 (b)(2)®. Once these identifiers are r…”
- In re Zyprexa Products Liability Litigation (District Court, E.D. New York 2008, 254 F.R.D. 50)“…dual is not individually identifiable health information.” 45 C.F.R. § 164.514 (a). To achieve de-identifi-cation, num…”
- Nat'l Abortion Fed v. Ashcroft, John D. (Court of Appeals for the Seventh Circuit 2004)“…except as permitted by paragraph (c) of this section; 45 C.F.R. § 164.514(b)(2)(i). Once these identifiers are…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Also relied on in: What Is TPO in HIPAA? Treatment, Payment, and Operations Explained (2026)
§ 160.203General rule and exceptions.In forcecited in 3 of our articles
A standard, requirement, or implementation specification adopted under this subchapter that is contrary to a provision of State law preempts the provision of State law. This general rule applies, except if one or more of the following conditions is met: (a) A determination is made by the Secretary under § 160.204 that the provision of State law: (1) Is necessary: (i) To prevent fraud and abuse related to the provision of or payment for health care; (ii) To ensure appropriate State regulation of insurance and health plans to the extent expressly authorized by statute or regulation; (iii) For State reporting on health care delivery or costs; or (iv) For purposes of serving a compelling need related to public health, safety, or welfare, and, if a standard, requirement, or implementation specification under part 164 of this subchapter is at issue, if the Secretary determines that the intrusion into privacy is warranted when balanced against the need to be served; or (2) Has as its principal purpose the regulation of the manufacture, registration, distribution, dispensing, or other control of any controlled substances (as defined in 21 U.S.C.
Official text (excerpt) · last checked 2026-07-28 · Read the full text in our law library · Verify at ecfr.gov
Cited in 113 court opinions in our collectionLatest citing opinion in our collection: 2025
Opinions citing this section in our collection:
- Samuel Zean v. Fairview Health Services (Court of Appeals for the Eighth Circuit 2017, 858 F.3d 520)“…ls if its restrictions are more stringent than HIPAA’s. See 45 C.F.R. § 160.203(b).…”
- Law v. Zuckerman (District Court, D. Maryland 2004, 307 F. Supp. 2d 705)“…e Historical and Statutory notes to 42 U.S.C § 1320d — 2); 45 C.F.R. § 160.203 . Defendant’s counsel has argued…”
- Thomas v. 1156729 Ontario Inc. (District Court, E.D. Michigan 2013, 979 F. Supp. 2d 780)“…o” its requirements. 42 U.S.C. § 1320d-7(a)(1); see also 45 C.F.R. § 160.203 . State law is contrary to HIPAA if (1)…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Also relied on in: Minnesota Medical Records Retention Laws (2026 Guide)
§ 164.530Administrative requirements.In forcecited in 42 of our articles
(a)(1) Standard: Personnel designations. (i) A covered entity must designate a privacy official who is responsible for the development and implementation of the policies and procedures of the entity. (ii) A covered entity must designate a contact person or office who is responsible for receiving complaints under this section and who is able to provide further information about matters covered by the notice required by § 164.520. (2) Implementation specification: Personnel designations. A covered entity must document the personnel designations in paragraph (a)(1) of this section as required by paragraph (j) of this section. (b)(1) Standard: Training. A covered entity must train all members of its workforce on the policies and procedures with respect to protected health information required by this subpart and subpart D of this part, as necessary and appropriate for the members of the workforce to carry out their functions within the covered entity. (2) Implementation specifications: Training.
Official text (excerpt) · last checked 2026-07-28 · Read the full text in our law library · Verify at ecfr.gov
Cited in 23 court opinions in our collectionLatest citing opinion in our collection: 2025
In the courts (editorial summary, independently checked):Surprise v. Innovation Group, Inc. (2013) applied 45 CFR 164.530(c), noting it requires appropriate safeguards but does not specify what they must be, and rejected a wrongful discharge claim resting on it. Baum v. KEYSTONE MERCY HEALTH PLAN (2011) treated the same duty as background to state tort claims and remanded.
Opinions citing this section in our collection:
- Baum v. KEYSTONE MERCY HEALTH PLAN (District Court, E.D. Pennsylvania 2011, 826 F. Supp. 2d 718)✓A lost flash drive exposed health data on 280,000 insured children, and a parent sued in state court for negligence per se. The court held that resting the claim on the HIPAA safeguard rule at 45 C.F.R. 164.530(c)(2)(i) raised no substantial federal question, and remanded.
- Surprise v. Innovation Group, Inc. (District Court, D. Massachusetts 2013, 925 F. Supp. 2d 134)✓An employee fired after complaining that health-information documents went into unsecured trash sued for wrongful discharge. The court read 45 C.F.R. 164.530(c) to require safeguards without prescribing a method, and held HIPAA disposal rules are not well-defined public policy.
- Michael Terpin v. at and T Mobility LLC (Court of Appeals for the Ninth Circuit 2024, 118 F.4th 1102)“…viders to protect patients’ “protected health information.” 45 C.F.R. § 164.530(c)(1); Moore, 299 Cal. Rptr. 3d at 561.…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Also relied on in: How Long Do Hospitals Keep Medical Records? (2026), Medical Records Retention Laws by State (2026 Guide), Alaska Medical Records Retention Laws (2026 Guide)
§ 102.3Penalty adjustment and table.In forcecited in 9 of our articles
The adjusted statutory penalty provisions and their applicable amounts are set out in the following table. The right-most column in the table, “Maximum Adjusted Penalty ($)”, provides the maximum adjusted civil penalty amounts. The civil monetary penalty amounts are adjusted annually. Table 1 to § 102.3—Civil Monetary Penalty Authorities Administered by HHS U.S.C. section(s) CFR 1 HHS agency Description 2 Date of last penalty figure or adjustment 3 2024 Maximum adjusted penalty ($) 2025 Maximum adjusted penalty ($) 4 21 U.S.C.: 333(b)(2)(A) FDA Penalty for violations related to drug samples resulting in a conviction of any representative of manufacturer or distributor in any 10-year period 2024 127,983 131,308 333(b)(2)(B) FDA Penalty for violation related to drug samples resulting in a conviction of any representative of manufacturer or distributor after the second conviction in any 10-yr period 2024 2,559,636 2,626,135 333(b)(3) FDA Penalty for failure to make a report required by 21 U.S.C.
Official text (excerpt) · last checked 2026-07-28 · Read the full text in our law library · Verify at ecfr.gov
Cited in 1 court opinions in our collectionLatest citing opinion in our collection: 2025
Opinions citing this section in our collection:
- Vape Central Group, LLC v. Food & Drug Administration (District Court, District of Columbia 2025)“…s were $21,348, $355,806, and $1,423,220, respectively. See 45 C.F.R. § 102.3.…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Also relied on in: Texas Medical Records Retention Laws (2026 Guide), Ohio Medical Records Retention Laws (2026 Guide), Pennsylvania Medical Records Retention Laws (2026 Guide)
California Civil Code
§ 56.10In forcecited in 2 of our articles
(a) A provider of health care, health care service plan, or contractor shall not disclose medical information regarding a patient of the provider of health care or an enrollee or subscriber of a health care service plan without first obtaining an authorization, except as provided in subdivision (b) or (c). (b) A provider of health care, a health care service plan, or a contractor shall disclose medical information if the disclosure is compelled by any of the following: (1) (A) A court order issued by a court of this state or a federal court, including, but not limited to, a court order issued by a court of this state pursuant to Section 2029.300 of the Code of Civil Procedure relating to a foreign subpoena. (B) A provider of health care, health care service plan, or contractor shall not comply with a court order that constitutes a foreign subpoena, absent a court order issued pursuant to Section 2029.300 of the Code of Civil Procedure. (2) A board, commission, or administrative agency for purposes of adjudication pursuant to its lawful authority.
Official text (excerpt) · last checked 2026-07-28 · Read the full text in our law library · Verify at leginfo.legislature.ca.gov
Cited in 74 court opinions in our collectionLatest citing opinion in our collection: 2026
Opinions citing this section in our collection:
- Heller v. Norcal Mutual Insurance (California Supreme Court 1994, 8 Cal. 4th 30)“…provider without first obtaining an authorization . . . .” (Civ. Code, § 56.10, subd. (a).) This core provision is fol…”
- Inabnit v. Berkson (California Court of Appeal 1988, 199 Cal. App. 3d 1230)“…e raised several affirmative defenses, including the bar of Civil Code section 56.10, subdivision (b)(3), 1 con…”
- California Consumer Health Care Council v. Kaiser Foundation Health Plan, Inc. (California Court of Appeal 2006, 47 Cal. Rptr. 3d 593)“…0, subdivision (a), a provision of the Confidentiality Act (Civ. Code, §56.10, subd. (a) (section 56.10(a)), which st…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Also relied on in: California Laws on Recording Doctors and Medical Appointments (2026)
California Code of Civil Procedure
§ 1985.3In force
(a) For purposes of this section, the following definitions apply: (1) “Personal records” means the original, any copy of books, documents, other writings, or electronically stored information pertaining to a consumer and which are maintained by any “witness” which is a physician, dentist, ophthalmologist, optometrist, chiropractor, physical therapist, acupuncturist, podiatrist, veterinarian, veterinary hospital, veterinary clinic, pharmacist, pharmacy, hospital, medical center, clinic, radiology or MRI center, clinical or diagnostic laboratory, state or national bank, state or federal association (as defined in Section 5102 of the Financial Code), state or federal credit union, trust company, anyone authorized by this state to make or arrange loans that are secured by real property, security brokerage firm, insurance company, title insurance company, underwritten title company, escrow agent licensed pursuant to Division 6 (commencing with Section 17000) of the Financial Code or exempt from licensure pursuant to Section 17006 of the Financial Code, attorney, accountant, institution of the Farm Credit System, as specified in Section 2002 of Title 12 of the United States Code, or…
Official text (excerpt) · last checked 2026-07-28 · Read the full text in our law library · Verify at leginfo.legislature.ca.gov
Cited in 38 court opinions in our collectionLatest citing opinion in our collection: 2025
Opinions citing this section in our collection:
- In Re RR (California Court of Appeal 2010, 187 Cal. App. 4th 1264)“…tecum which did not comply with the notice requirements of Code of Civil Procedure section 1985.3; (2) it was error to admit into evidenc…”
- Pub. Guardian of the Cnty. of San Luis Obispo v. S.A. (In re S.A.) (California Court of Appeal, 5th District 2018, 235 Cal. Rptr. 3d 744)“…he did not receive 10 days notice before their production ( Code Civ. Proc., § 1985.3, subd. (b)(2) ); Public Guardian had no…”
- Whitney v. Montegut (California Court of Appeal 2014, 222 Cal. App. 4th 906)“…nsider consulting an attorney.” Dr. Montegut also relies on Code of Civil Procedure section 1985.3, as applied in Sehlmeyer v. Department…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Texas Health and Safety Code
§ 181.102CONSUMER ACCESS TO ELECTRONIC HEALTH RECORDSIn force
(a) Except as provided by Subsection (b), if a health care provider is using an electronic health records system that is capable of fulfilling the request, the health care provider, not later than the 15th business day after the date the health care provider receives a written request from a person for the person's electronic health record, shall provide the requested record to the person in electronic form unless the person agrees to accept the record in another form. (b) A health care provider is not required to provide access to a person's protected health information that is excepted from access, or to which access may be denied, under 45 C.F.R. Section 164.524. (c) For purposes of Subsection (a), the executive commissioner, in consultation with the department, the Texas Medical Board, and the Texas Department of Insurance, by rule may recommend a standard electronic format for the release of requested health records. The standard electronic format recommended under this section must be consistent, if feasible, with federal law regarding the release of electronic health records.
Official text (excerpt) · last checked 2026-07-28 · Read the full text in our law library · Verify at statutes.capitol.texas.gov
Code of Federal Regulations Title 42
§ 2.61Legal effect of order.In force
(a) Effect. An order of a court of competent jurisdiction entered under this subpart is a unique kind of court order. Its only purpose is to authorize a use or disclosure of patient information which would otherwise be prohibited by 42 U.S.C. 290dd-2 and the regulations in this part. Such an order does not compel use or disclosure. A subpoena or a similar legal mandate must be issued to compel use or disclosure. This mandate may be entered at the same time as and accompany an authorizing court order entered under the regulations in this part. (b) Examples. (1) A person holding records subject to the regulations in this part receives a subpoena for those records. The person may not use or disclose the records in response to the subpoena unless a court of competent jurisdiction enters an authorizing order under the regulations in this part. (2) An authorizing court order is entered under the regulations in this part, but the person holding the records does not want to make the use or disclosure. If there is no subpoena or other compulsory process or a subpoena for the records has expired or been quashed, that person may refuse to make the use or disclosure.
Official text (excerpt) · last checked 2026-07-28 · Read the full text in our law library · Verify at ecfr.gov
Cited in 24 court opinions in our collectionLatest citing opinion in our collection: 2024
Opinions citing this section in our collection:
- United States v. Ray L. Corona (Court of Appeals for the Eleventh Circuit 1988, 849 F.2d 562)“…te, 42 U.S.C. § 290ee-3, and its implementing regulations, 42 C.F.R. § 2.61 et seq. On December 22, 1…”
- United States v. Smith (Court of Appeals for the Third Circuit 1986, 789 F.2d 196)“…sure pursuant to § 290dd-3(b)(2)(C) and the regulations at 42 C.F.R. § 2.61 (1985) if “good cause” has been shown.…”
- United States v. Jackson (District Court, D. Kansas 1994, 155 F.R.D. 664)“…tory or regulatory requirements for that disclosure. See 42 C.F.R. § 2.61 et seq. . The defendants also…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Search our full record of US law — 2.1 million sections, every state + federal →
Sources and References
- 45 CFR 164.512(e) - Disclosures for judicial and administrative proceedings(law.cornell.edu)
- HHS FAQ - Judicial and Administrative Proceedings(hhs.gov).gov
- HHS FAQ 706 - Satisfactory assurances for subpoena response(hhs.gov).gov
- HHS FAQ 708 - When subpoena itself is satisfactory assurance(hhs.gov).gov
- HHS FAQ 505 - Law enforcement disclosures under the Privacy Rule(hhs.gov).gov
- HHS - Court Orders and Subpoenas (for individuals)(hhs.gov).gov
- HHS - How OCR Enforces the HIPAA Privacy and Security Rules(hhs.gov).gov
- HHS - Guidance on De-identification of PHI under HIPAA(hhs.gov).gov
- HHS FAQ 399 - Does HIPAA preempt state laws?(hhs.gov).gov
- California Confidentiality of Medical Information Act - Cal. Civ. Code 56.10(leginfo.legislature.ca.gov).gov
- 42 CFR 2.61 - Legal effect of order (substance use disorder records)(govinfo.gov)
- Cal. Code Civ. Proc. 1985.3 - Subpoena of consumer personal records(leginfo.legislature.ca.gov)
- Tex. Health & Safety Code 181.102 - Consumer access to electronic health records(statutes.capitol.texas.gov)
- 45 CFR 102.3 - Civil monetary penalty inflation adjustment table(govinfo.gov)
- 45 CFR 164.512 - Uses and disclosures for which authorization is not required (govinfo)(govinfo.gov)