MPJE: MULTISTATE PHARMACY JURISPRUDENCE EXAMINATION • PHARMACY AND PHARMACIST PRACTICE

Permitted Disclosure — Identify permitted uses/disclosures of patient health information in pharmacy operations

Understanding when pharmacies may lawfully use or share protected health information without patient authorization.

Historical Context & Motivation

Before federal privacy legislation, patient health information in pharmacy settings was governed by a patchwork of state laws, professional ethical codes, and informal norms that varied dramatically across jurisdictions. Pharmacists have always occupied a unique position in healthcare — they interact with patients' most sensitive medical data on a daily basis through prescription records, medication histories, and counseling notes. The explosion of electronic health records in the 1990s and the growing interconnectedness of healthcare systems made it clear that a uniform federal standard for protecting protected health information (PHI) was essential. The passage of the Health Insurance Portability and Accountability Act (HIPAA) in 1996 and its subsequent Privacy Rule in 2003 fundamentally reshaped how pharmacies handle, share, and safeguard patient information.

1996
HIPAA Enacted
Congress passes the Health Insurance Portability and Accountability Act, establishing the framework for national standards on health information privacy and security.
2000
Privacy Rule Finalized
The Department of Health and Human Services (HHS) issues the final Privacy Rule under HIPAA, defining permitted uses and disclosures of PHI and establishing patient rights over their health information.
2003
Privacy Rule Compliance Deadline
Most covered entities, including pharmacies, must comply with the HIPAA Privacy Rule. Pharmacies implement Notice of Privacy Practices (NPP) and new disclosure policies.
2009
HITECH Act Strengthens Protections
The Health Information Technology for Economic and Clinical Health (HITECH) Act expands HIPAA enforcement, increases penalties for violations, and extends certain obligations to business associates of pharmacies.
2013
Omnibus Rule
The HIPAA Omnibus Rule finalizes HITECH provisions, modifies the breach notification standard, and strengthens privacy protections for genetic information — further clarifying permitted disclosures in pharmacy practice.

The central question this body of law addresses is deceptively simple: When may a pharmacy use or disclose a patient's health information, and under what conditions? Understanding the answer requires distinguishing between disclosures that require patient authorization and those that are permitted without authorization — a distinction that lies at the heart of MPJE examination questions and everyday pharmacy practice.

Core Principles & Definitions

The HIPAA Privacy Rule establishes a tiered system for the use and disclosure of protected health information. At its foundation, the rule recognizes that certain uses of PHI are essential for the healthcare system to function — a pharmacist cannot fill a prescription without accessing a patient's medication history, and an insurer cannot reimburse a pharmacy without reviewing the claim. Accordingly, the Privacy Rule creates categories of permitted uses and disclosures that do not require a patient's written authorization. These categories represent a careful balance between the patient's right to privacy and the practical demands of healthcare delivery, public safety, and regulatory oversight.

1

Protected Health Information (PHI)

Individually identifiable health information created, received, maintained, or transmitted by a covered entity. This includes prescription records, medication profiles, billing data, and counseling notes that can be linked to a specific patient.
2

Covered Entity

Health plans, healthcare clearinghouses, and healthcare providers (including pharmacies) that transmit health information electronically. Pharmacies are covered entities under HIPAA because they conduct electronic transactions such as insurance claims.
3

Minimum Necessary Standard

When using or disclosing PHI, a covered entity must make reasonable efforts to limit the information to the minimum amount necessary to accomplish the intended purpose. This standard does not apply to disclosures for treatment purposes.
4

Treatment, Payment, and Healthcare Operations (TPO)

The three core categories for which PHI may be used or disclosed without patient authorization. TPO encompasses the essential activities that pharmacies perform daily — dispensing, billing, quality assurance, and compliance activities.
5

Authorization vs. Consent

Authorization is a detailed, written permission from the patient for specific uses of PHI beyond TPO (e.g., marketing). Consent is a general acknowledgment — the Privacy Rule permits but does not require consent for TPO disclosures.
KEY TAKEAWAY
Think of permitted disclosures like the lanes on a highway. The TPO lane is the widest and most frequently traveled — pharmacists use it every time they fill a prescription, submit an insurance claim, or conduct a drug utilization review. Other lanes exist for public health, law enforcement, and judicial proceedings, but each has its own speed limit (conditions). Activities that fall outside any recognized lane — like selling patient lists for marketing — require a special permit (written patient authorization). The minimum necessary standard is the rule that you must stay in the narrowest lane that gets you to your destination.

Visual Explanation — The Disclosure Decision Framework

This flowchart illustrates the decision pathway a pharmacist follows when determining whether a disclosure of PHI is permitted. The first checkpoint asks whether the disclosure falls under TPO. If not, the pharmacist must assess whether the disclosure falls into one of the other permitted categories (such as public health reporting or law enforcement). If neither applies, written patient authorization is required.

The flowchart above captures the essential logic pharmacists apply dozens of times each day, often without conscious deliberation. When a physician calls to check a patient's current medications before prescribing, that disclosure falls squarely within treatment. When the pharmacy's billing software transmits claim data to a pharmacy benefit manager (PBM), that is payment. When the pharmacy's quality improvement team reviews aggregate dispensing data to identify medication error patterns, that constitutes healthcare operations. Each of these activities is permitted without patient authorization, though the minimum necessary standard still governs the scope of information shared — except in the treatment context, where the full clinical picture may be needed.

The TPO Framework in Pharmacy Practice

Treatment

Under the Privacy Rule, treatment encompasses the provision, coordination, or management of healthcare and related services. In pharmacy operations, treatment disclosures include sharing prescription information with a prescriber for dosage adjustments, transferring a prescription to another pharmacy, consulting with another pharmacist about a drug interaction, and providing medication counseling to the patient. Notably, the minimum necessary standard does not apply to treatment disclosures — a deliberate policy choice reflecting the clinical reality that healthcare providers need access to the full patient picture to deliver safe care.

Payment

The payment category covers activities by which a covered entity obtains reimbursement for services rendered. In pharmacy practice, this includes submitting electronic claims to insurance companies or PBMs, conducting prior authorization processes, billing patients for copayments, and coordinating benefits between multiple payers. The minimum necessary standard applies to payment disclosures — a pharmacy should include only the PHI needed for the payer to adjudicate the claim, not the patient's entire medication history.

Healthcare Operations

Healthcare operations is the broadest and most frequently tested category. It includes quality assessment and improvement activities, case management, conducting or arranging for medical review and auditing, compliance programs, business planning, accreditation activities, and certain training programs. In the pharmacy context, drug utilization review (DUR) programs, formulary development, staff competency assessments, and state board of pharmacy inspections all fall under healthcare operations. The minimum necessary standard applies — a pharmacy conducting an internal audit should limit data access to the records pertinent to the audit scope.

The three circles represent the TPO categories, each listing common pharmacy activities. Note that Treatment is the only TPO category where the minimum necessary standard does not apply, reflecting the imperative of complete clinical information for safe patient care.

Permitted Disclosures Beyond TPO

While TPO represents the most common basis for permitted disclosures in daily pharmacy operations, the Privacy Rule identifies numerous additional circumstances under which a covered entity may disclose PHI without patient authorization. These categories reflect societal interests — public health surveillance, law enforcement, court proceedings — that the legislature determined outweigh individual privacy in specific, carefully delineated situations. For the MPJE, familiarity with these categories and the specific conditions attached to each is essential.

Permitted Disclosures of PHI Beyond Treatment, Payment, and Healthcare Operations
Permitted CategoryPharmacy-Specific ExamplesKey Conditions / Limitations
Public Health ActivitiesReporting adverse drug reactions to FDA MedWatch; notifying public health authorities of communicable diseases detected during immunization servicesDisclosure must be to a public health authority or entity authorized by law to receive such information
Law Enforcement PurposesResponding to a court order or subpoena for prescription records; reporting suspected controlled substance diversionMust meet specific conditions (e.g., valid court order, administrative request with limitations); voluntary disclosures limited to suspected crimes on pharmacy premises
Judicial & Administrative ProceedingsResponding to a discovery request in a malpractice case; providing records pursuant to a valid subpoena with satisfactory assurancesSubpoena alone (without court order) requires satisfactory assurances that the patient was notified or a protective order was obtained
Required by LawState PDMP (Prescription Drug Monitoring Program) reporting; mandatory reporting of suspected abuse or neglectDisclosure must comply with and be limited to what the law requires; state mandates often supplement federal requirements
Serious Threat to Health or SafetyNotifying law enforcement about a patient who has expressed intent to harm themselves or others; warning a family member of potential overdose riskMust be based on good-faith belief; disclosure is to a person reasonably able to prevent or lessen the threat
ResearchAllowing a researcher to review prescription records for a pharmacoepidemiologic study; providing a limited data set for outcomes researchRequires IRB/Privacy Board approval with waiver of authorization, or use of de-identified data or a limited data set with a data use agreement
DecedentsDisclosing medication records to a coroner or medical examiner investigating cause of deathLimited to the purpose of identifying the decedent, determining cause of death, or other duties as authorized by law
Workers' CompensationProviding medication records related to a workplace injury claimDisclosure must be as authorized by and to the extent necessary to comply with workers' compensation laws
⚖️ MPJE Alert: Subpoena vs. Court Order
A common MPJE question tests the distinction between a court order and a subpoena. A court order signed by a judge compels disclosure; the pharmacy may release PHI in response. A subpoena alone (not signed by a judge) requires additional steps — the pharmacy must receive satisfactory assurances that the patient was notified or that a qualified protective order was sought before disclosing records.

Worked Example — Analyzing a Disclosure Scenario

Consider the following scenario, which mirrors the style of questions found on the MPJE: A community pharmacist receives a phone call from a patient's spouse requesting a list of all medications the patient is currently taking. The spouse states that the patient is unconscious and has been taken to the emergency department at a local hospital. The pharmacist has not previously received any authorization from the patient to share information with the spouse.

Scenario: Spouse Requests Patient Medication List During Emergency
1
Step 1 — Identify the Type of Disclosure RequestedThe spouse is requesting PHI — specifically, the patient's current medication list. The disclosure is not to the patient directly but to a third party (family member). This does not fit neatly into Treatment (the spouse is not a healthcare provider) or Payment.
This is a disclosure to a family member involved in the patient's care.
2
Step 2 — Evaluate Permitted Disclosure CategoriesUnder 45 CFR § 164.510(b), the Privacy Rule permits a covered entity to disclose PHI to a family member, relative, close personal friend, or any other person identified by the patient if the information is directly relevant to that person's involvement in the patient's care. If the patient is present and has capacity, the pharmacy should give the patient an opportunity to agree or object. If the patient is incapacitated or unavailable, the pharmacist may use professional judgment to determine whether the disclosure is in the patient's best interest.
Patient is unconscious — professional judgment standard applies.
3
Step 3 — Apply the Professional Judgment StandardThe pharmacist must determine: (a) Is the spouse involved in the patient's care or payment? Given that the spouse is coordinating the emergency, the answer is yes. (b) Is the information directly relevant to the spouse's involvement? A medication list is critical for emergency treatment. (c) Would the disclosure be in the patient's best interest? Providing the ER with the medication list could prevent dangerous drug interactions.
Professional judgment supports disclosure of the medication list.
4
Step 4 — Apply Minimum Necessary and DocumentThe pharmacist should limit the disclosure to information relevant to the emergency — the current medication list — rather than the patient's complete dispensing history, allergy records, or payment information. The pharmacist should document the disclosure, noting the circumstances (patient unconscious, spouse coordinating emergency care) and the professional judgment rationale.
Disclose only the current medication list; document the decision.
5
Step 5 — Determine the Final AnswerThe pharmacist may disclose the patient's current medication list to the spouse without written authorization, based on the professional judgment that the patient is incapacitated, the spouse is involved in the patient's care, and the information is directly relevant to emergency treatment.
Disclosure is PERMITTED without authorization under 45 CFR § 164.510(b).

Authorization Required vs. Permitted Without Authorization

The distinction between disclosures that are permitted without authorization and those that require written patient authorization is one of the most heavily tested concepts on the MPJE. While the permitted categories are broad, several important uses of PHI fall outside them. Understanding where the line is drawn helps pharmacists avoid costly violations and protects patient trust.

Comparison of Permitted Disclosures vs. Authorization-Required Disclosures
CharacteristicPermitted Without AuthorizationRequires Written Authorization
Primary ExamplesTPO, public health, law enforcement, judicial proceedings, threat to safety, required by lawMarketing communications, sale of PHI, psychotherapy notes, most uses not covered by permitted categories
Patient InvolvementNo written permission needed; may require opportunity to agree/object in some cases (e.g., facility directory)Requires a signed, specific authorization form that includes description of PHI, purpose, expiration, and right to revoke
Minimum NecessaryApplies to all categories except treatmentNot applicable — scope is defined by the authorization itself
RevocabilityNot revocable by the patient — these are legal rights of the covered entityPatient may revoke authorization at any time in writing (cannot undo actions already taken)
Conditioning TreatmentN/A — no authorization neededGenerally prohibited from conditioning treatment on authorization, with limited exceptions (e.g., research-related treatment)
KEY TAKEAWAY
Think of HIPAA's disclosure rules like a building's access system. Employees (TPO activities) have badge access — they can enter without asking permission every time. Visitors with specific purposes (public health, law enforcement) have temporary passes issued under defined protocols. But someone who wants to use the building for an unrelated commercial purpose (marketing, selling data) must get explicit, written permission from the building owner (the patient). The MPJE tests whether you know which door requires a badge, which requires a pass, and which requires written permission.

State Law Preemption & Advanced Considerations

One of the most critical concepts for MPJE preparation is federal-state preemption in the context of health information privacy. HIPAA establishes a federal floor — a minimum standard of privacy protection. States may enact laws that are more protective of patient privacy than HIPAA, and when they do, the more stringent state law prevails. However, if a state law is less protective than HIPAA, the federal standard controls. This "more stringent" analysis is a recurring theme on the MPJE because the exam is state-specific, and candidates must demonstrate knowledge of how their state's laws interact with federal requirements.

Federal-State Preemption: When State Law Prevails Over HIPAA
ScenarioHIPAA StandardIf State Law Is More Protective
Substance Abuse Treatment RecordsGeneral PHI protections under Privacy Rule42 CFR Part 2 imposes stricter federal rules; many states add further restrictions requiring patient consent for any disclosure
Minor's Prescription RecordsDefers to state law regarding parental accessSome states restrict parental access to minor's contraceptive or mental health prescriptions
HIV/AIDS StatusTreated as PHI under general Privacy RuleMany states impose specific consent requirements and limit who may access HIV-related records
Genetic InformationGINA provides baseline protections; HIPAA Omnibus Rule restricts use for underwritingSome states prohibit disclosure of genetic test results without explicit patient consent, even for treatment

As you advance in pharmacy practice and prepare for the MPJE, you will encounter increasingly nuanced scenarios involving the intersection of HIPAA, the HITECH Act, 42 CFR Part 2 (substance use disorder records), state pharmacy practice acts, and evolving technologies such as telepharmacy and mobile health applications. The guiding principle remains constant: when federal and state laws conflict on privacy, apply the law that provides greater protection to the patient. This principle extends to business associate agreements, breach notification timelines, and the handling of de-identified data across jurisdictions.

Practice Problems

PROBLEM 1CONCEPTUAL
A pharmacist receives a phone call from a patient's physician requesting the patient's current medication list to evaluate a potential drug interaction before prescribing a new medication. Is the pharmacist permitted to disclose this information without the patient's written authorization? Explain your reasoning.
PROBLEM 2BASIC CALCULATION
A community pharmacy receives a request from a public health department asking for de-identified aggregate data on the number of influenza vaccinations administered in the past month. Which permitted disclosure category applies, and does the minimum necessary standard apply?
PROBLEM 3INTERMEDIATE
A pharmacy technician notices that a pharmaceutical sales representative is asking the pharmacist to provide a list of patients currently taking a competitor's statin medication so that the representative can send them promotional materials about a new statin product. The pharmacist has not obtained patient authorization. Can the pharmacist provide this information?
PROBLEM 4APPLIED
A pharmacist in a state with a mandatory PDMP (Prescription Drug Monitoring Program) receives a request from an out-of-state law enforcement officer (not accompanied by a court order) asking for a specific patient's controlled substance dispensing history. The officer claims to be investigating a drug trafficking ring. How should the pharmacist handle this request?
PROBLEM 5CRITICAL THINKING
A hospital pharmacy participates in a multi-site clinical trial investigating a new anticoagulant. The research protocol was approved by the IRB with a waiver of patient authorization for accessing pharmacy dispensing records. During a routine audit, the pharmacy compliance officer discovers that a research assistant has been downloading complete patient medication profiles — not just the anticoagulant dispensing data specified in the protocol. Analyze the privacy implications, identify the violations, and describe the corrective actions the pharmacy should take.

Summary

The HIPAA Privacy Rule creates a structured framework for when pharmacies may use or disclose protected health information (PHI) without patient authorization. The most frequently invoked category is Treatment, Payment, and Healthcare Operations (TPO), which encompasses virtually every routine pharmacy activity — from dispensing prescriptions and submitting insurance claims to conducting drug utilization reviews and compliance audits. The minimum necessary standard requires pharmacists to limit PHI disclosures to the smallest amount needed for the purpose, with the critical exception that treatment disclosures are exempt from this requirement.

Beyond TPO, permitted disclosures extend to public health activities, law enforcement (with proper legal process), judicial proceedings, research (with IRB approval), serious threats to health or safety, and disclosures required by law such as PDMP reporting. Activities that fall outside these permitted categories — most notably marketing and the sale of PHI — require written patient authorization. When federal and state privacy laws conflict, the pharmacist must apply the more stringent standard, ensuring the greatest protection for the patient.

Varsity Tutors • MPJE: Multistate Pharmacy Jurisprudence Examination • Permitted Disclosure — Identify permitted uses/disclosures of patient health information in pharmacy operations