NCLEX-PN • COORDINATED CARE

Confidentiality And Privacy

Protecting patient health information is both a legal mandate and a cornerstone of the therapeutic nurse-patient relationship.

Historical Context & Motivation

The duty to keep patient information private is far older than modern healthcare law. From the moment healers first recorded observations about a patient's condition, a tension arose between the need for accurate documentation and the patient's reasonable expectation that sensitive details would not be disclosed to others. In early Western medicine, the Hippocratic Oath (circa 400 BCE) included explicit language prohibiting physicians from revealing what they saw or heard in the course of treatment. This ethical tradition persisted for centuries, but it was not codified into binding law until the twentieth century, when advances in electronic record-keeping, insurance billing, and multi-provider care teams dramatically increased the number of people who could access a patient's health data.

Several landmark events accelerated the push for formal patient privacy protections in the United States. The rise of managed care in the 1980s and 1990s meant that insurers, utilization review companies, and administrative staff routinely handled sensitive diagnoses and treatment histories. High-profile breaches—unauthorized disclosures of HIV status, psychiatric records, and genetic test results—underscored the real harm that could follow when confidentiality safeguards were absent. These forces converged to produce the most significant patient-privacy statute in U.S. history: the Health Insurance Portability and Accountability Act (HIPAA) of 1996, followed by its Privacy Rule in 2003 and its Security Rule in 2005.

~400 BCE
Hippocratic Oath
Ancient Greek physicians pledged to keep patient information confidential—establishing the earliest known ethical standard for medical privacy.
1974
Privacy Act
The U.S. Privacy Act established protections for personal records held by federal agencies, creating a legal precedent for restricting access to sensitive information collected by the government.
1996
HIPAA Enacted
Congress passed the Health Insurance Portability and Accountability Act (HIPAA), mandating national standards for protecting individually identifiable health information.
2003
HIPAA Privacy Rule
The Privacy Rule took effect, defining Protected Health Information (PHI) and establishing patients' rights to access and control their health records.
2009
HITECH Act
The Health Information Technology for Economic and Clinical Health (HITECH) Act strengthened breach notification requirements and increased penalties for HIPAA violations, reflecting the explosion of electronic health records (EHRs).

Understanding this history matters for licensed practical and vocational nurses because the NCLEX-PN expects you to recognize not just the rules themselves but the rationale behind them. Confidentiality protections exist to prevent concrete harms—discrimination, stigma, emotional distress, and erosion of trust in the healthcare system. When patients doubt that their information will remain private, they may withhold symptoms, avoid seeking care, or refuse treatment—outcomes that endanger both the individual and public health.

Core Principles & Definitions

Although the terms confidentiality and privacy are often used interchangeably in everyday conversation, they carry distinct meanings in healthcare law and nursing ethics. Privacy refers to the patient's right to control who can access their personal health information and under what circumstances it may be collected. Confidentiality, by contrast, is the professional obligation of healthcare providers to safeguard information that has already been shared within the therapeutic relationship. A third related concept, security, encompasses the physical and technical measures used to prevent unauthorized access to records. Taken together, these three principles form the foundation of information governance in healthcare.

1

Privacy

The patient's fundamental right to decide what health information is collected, how it is used, and to whom it may be disclosed. Rooted in patient autonomy and self-determination.
2

Confidentiality

The provider's duty to protect information shared within the nurse-patient relationship. Breaching confidentiality without legal justification can lead to civil liability and licensure action.
3

Protected Health Information (PHI)

Any individually identifiable information—oral, written, or electronic—that relates to a patient's past, present, or future health condition, treatment, or payment for care. Includes 18 HIPAA-specified identifiers such as name, date of birth, and Social Security number.
4

Minimum Necessary Standard

HIPAA requires that disclosures of PHI be limited to the least amount of information needed to accomplish the intended purpose. Nurses must apply this standard every time they share patient data.
5

Need-to-Know Basis

Within the care team, access to PHI should be restricted to those directly involved in the patient's treatment. Discussing a case with a colleague who is not part of the treatment team violates this principle.
KEY TAKEAWAY
Think of patient information as a sealed letter. Privacy is the patient's right to decide who may open the envelope. Confidentiality is the nurse's promise not to open it or share its contents without permission. Security is the locked mailbox that keeps the letter safe while it is in transit. All three must work together; a failure in any one can compromise the other two.

Visual Explanation — The Layers of Patient Information Protection

The concentric-ellipse model illustrates how privacy forms the outermost boundary (the patient's right), confidentiality sits in the middle (the provider's duty), and security protects the innermost core where PHI resides. Permitted disclosures (lower-right box) are the carefully defined exceptions that allow information to flow outward through the layers.

As the diagram shows, these three concepts are nested rather than independent. A breach in the security layer—such as leaving a computer terminal unlocked—can expose PHI and violate the nurse's confidentiality obligation, which in turn infringes on the patient's right to privacy. Conversely, strong security measures (encrypted EHRs, badge-access workstations) reinforce confidentiality, which in turn upholds the patient's privacy. For NCLEX-PN purposes, remember that every nurse action that touches patient information must be evaluated through all three layers—does this action preserve the patient's privacy rights, fulfill the provider's confidentiality duty, and comply with institutional security policies?

How HIPAA Works — Rules, Rights, and Exceptions

The HIPAA Privacy Rule — Key Provisions for Nurses

HIPAA's Privacy Rule applies to covered entities (health plans, healthcare clearinghouses, and most healthcare providers) and their business associates (billing companies, IT vendors, transcription services). As an LPN/LVN, you work within a covered entity and are therefore bound by these regulations. The Privacy Rule establishes several patient rights that directly affect day-to-day nursing practice. Patients have the right to receive a Notice of Privacy Practices (NPP) upon admission, the right to access and obtain copies of their medical records, the right to request amendments to inaccurate records, the right to an accounting of certain disclosures, and the right to request restrictions on how their PHI is used or disclosed.

Permitted Uses and Disclosures Without Authorization

HIPAA does not require patient authorization for every disclosure. The rule identifies several categories where PHI may be shared without a signed authorization. The three most common are collectively known as TPO—Treatment, Payment, and Healthcare Operations. Treatment includes sharing information with other providers involved in the patient's care, such as calling the pharmacy to clarify a prescription. Payment involves submitting claims to insurers. Operations cover quality improvement, training, and compliance activities. Beyond TPO, HIPAA permits disclosure in specific situations including public health reporting (communicable diseases, vital statistics), court orders and subpoenas, law enforcement requests under defined conditions, and situations involving serious threats to health or safety. Even in these situations, the minimum necessary standard still applies—share only the information needed to accomplish the purpose.

When Written Authorization IS Required

  • Marketing purposes — Using PHI to promote products or services generally requires explicit patient authorization.
  • Sale of PHI — Any exchange of PHI for remuneration requires authorization, with narrow exceptions.
  • Psychotherapy notes — These receive heightened protection and require a separate authorization even for TPO.
  • Research — Use of PHI for research studies typically requires either patient authorization or a waiver from an Institutional Review Board.
  • Disclosures to employers — Releasing health information for employer use (beyond workers' compensation) requires written authorization.
💡 NCLEX-PN TIP
On the exam, if a question asks whether a nurse can share information and the scenario involves a member of the treatment team providing direct care, the answer is usually yes—this falls under the Treatment exception. However, if the person requesting information is a family member, friend, or non-treating staff member, look for evidence of patient consent before selecting an answer that permits disclosure.

Types of Breaches & Common Nursing Scenarios

Understanding the types of confidentiality breaches and common scenarios in which they occur is essential for NCLEX-PN preparation. A breach under HIPAA is defined as the acquisition, access, use, or disclosure of PHI in a manner not permitted by the Privacy Rule that compromises the security or privacy of the information. Breaches can be intentional—as when an employee looks up a celebrity's medical records out of curiosity—or unintentional, such as faxing lab results to the wrong number. The HITECH Act requires covered entities to notify affected individuals, the Department of Health and Human Services (HHS), and in some cases the media when a breach occurs. Penalties range from $100 to $50,000 per violation, with annual maximums of $1.5 million per violation category, and criminal penalties can include imprisonment for up to 10 years.

The upper portion categorizes breaches into verbal, electronic, and physical types. The lower flowchart guides the nurse through the decision-making process when someone requests patient information, emphasizing the TPO exception and the need for written authorization when that exception does not apply.

Verbal breaches are among the most common in clinical settings and the easiest to overlook. Discussing a patient's condition in the elevator, leaving a voicemail with detailed test results, or conducting bedside report within earshot of another patient's visitors can all constitute violations. Electronic breaches have grown significantly with the adoption of EHRs and mobile devices; posting a patient story on social media—even without using the patient's name—can be identifiable through contextual details and has led to disciplinary actions and terminations. Physical breaches involve tangible records that are improperly handled, such as discarding printouts in a regular trash bin rather than a shredding container or leaving patient charts visible at the nursing station.

Worked Example — Navigating a Confidentiality Scenario

The following scenario mirrors the type of situational question you may encounter on the NCLEX-PN. Work through each step as a model for how to analyze confidentiality questions.

Scenario: The Concerned Spouse
1
Step 1 — Read the ScenarioAn LPN is caring for a 45-year-old male patient who was admitted with abdominal pain and subsequently diagnosed with liver cirrhosis secondary to alcohol use disorder. The patient's wife calls the nurses' station and says, "I'm his wife. Can you tell me what's wrong with him? He won't tell me anything." The patient is alert and oriented and has not signed any authorization for disclosure. What is the nurse's best response?
2
Step 2 — Identify the Privacy and Confidentiality IssuesThe caller identifies herself as the patient's wife, but the nurse has no verification of her identity over the phone. Even if the caller is verified as the spouse, the patient has not provided authorization for information to be shared with family members. The patient is competent and has apparently chosen not to disclose his diagnosis. The spouse is not a member of the treatment team, so the TPO exception does not apply.
No authorization on file; TPO exception does not apply; patient is competent and has not consented to disclosure.
3
Step 3 — Apply the Minimum Necessary StandardEven in situations where disclosure is permitted, the nurse would share only the minimum amount of information necessary. In this case, however, no disclosure is permitted at all because neither patient authorization nor a legal exception exists. The nurse cannot confirm or deny the diagnosis, share test results, or even confirm that the patient is admitted (unless the facility has a patient directory and the patient has not opted out).
4
Step 4 — Determine the Appropriate Nursing ActionThe LPN should respond therapeutically without disclosing PHI. An appropriate response would be: "I understand your concern. I'm not able to share information about any patient without their permission. I encourage you to speak directly with your husband." The nurse should then document the call and inform the RN or charge nurse about the situation so the care team can address it during the patient's next visit or during discharge planning.
Best response: Decline to disclose information, suggest the wife speak directly with the patient, and document the interaction.
5
Step 5 — Consider Exceptions That Would Change the AnswerThe answer would differ if: (a) the patient had signed an authorization naming his wife as a person who may receive information; (b) the patient were incapacitated and unable to consent, in which case the nurse could use professional judgment to determine whether disclosure serves the patient's best interest; or (c) a court order specifically required the disclosure. None of these exceptions apply in this scenario.

Confidentiality — Strengths, Limitations, and Ethical Tensions

While confidentiality is a fundamental principle, it is not absolute. Nurses frequently encounter situations where the duty to maintain confidentiality conflicts with other ethical or legal obligations. Understanding both the strengths of confidentiality protections and their recognized limitations prepares you to navigate these tensions on the NCLEX-PN and in clinical practice.

Confidentiality Strengths vs. Recognized Exceptions
Strengths of ConfidentialityLimitations & Exceptions
Builds trust between patient and provider, encouraging honest disclosure of symptoms and historyMandatory reporting laws (child abuse, elder abuse, communicable diseases) override confidentiality
Protects patients from discrimination, stigma, and social harm based on diagnosesDuty to warn/protect third parties may require disclosure when a patient poses an imminent threat (Tarasoff principle)
Supports patient autonomy and self-determination in healthcare decisionsCourt orders and legal subpoenas can compel disclosure of records
Reduces liability for healthcare organizations by creating clear information-handling standardsWorkers' compensation and public health investigations may access records without patient consent
Encourages patients to seek care for sensitive conditions (mental health, substance use, STIs)In emergency situations, providers may share PHI with first responders to facilitate treatment
KEY TAKEAWAY
Confidentiality operates like a dam: it holds back the flow of patient information to protect against downstream harm. But just as a dam has controlled spillways for floods, confidentiality has structured exceptions—mandatory reporting, duty to warn, court orders—that allow information to flow when public safety or legal authority demands it. The nurse's job is not to keep information locked away forever but to ensure it flows only through the proper channels at the proper times.

Connection to Advanced Practice & Emerging Issues

While the NCLEX-PN focuses primarily on the foundational rules of confidentiality and HIPAA compliance, it is increasingly important for practical nurses to be aware of emerging challenges in information privacy. The healthcare landscape is evolving rapidly, and new technologies, care models, and patient expectations create novel confidentiality dilemmas. A working knowledge of these advanced issues will strengthen your clinical judgment and prepare you for ongoing professional development.

Foundational vs. Advanced Confidentiality Concepts
Foundational Concept (NCLEX-PN Level)Advanced / Emerging Issue
PHI is protected by HIPAA when held by covered entitiesConsumer health apps and wearable devices generate health data NOT covered by HIPAA—patients may not realize their fitness tracker data lacks federal privacy protection
Minimum necessary standard limits disclosuresInteroperability mandates (21st Century Cures Act) require data sharing between EHR systems, creating tension with minimum necessary principles
Social media posts about patients are prohibitedAI-powered language models trained on clinical notes raise questions about de-identification and re-identification risks
Telehealth sessions require the same confidentiality protections as in-person visitsTelehealth across state lines creates jurisdictional complexity—different states may have stricter privacy laws than HIPAA
Patient has the right to access their recordsInformation blocking rules now impose penalties on providers who unreasonably restrict patient access to electronic health information

For the NCLEX-PN, you are not expected to have detailed knowledge of the 21st Century Cures Act or AI governance. However, you should recognize that confidentiality is a dynamic, evolving obligation rather than a static set of rules. State nurse practice acts may impose additional requirements beyond HIPAA—for example, some states have specific statutes protecting the confidentiality of HIV test results, substance use treatment records (42 CFR Part 2), and genetic information (GINA). As a practical nurse, staying current with your state's requirements is as important as understanding federal law.

⚖️ STATE LAW NOTE
When state law and HIPAA conflict, the rule that provides greater protection to the patient generally applies. For example, if a state law requires written consent before disclosing any HIV-related information but HIPAA would allow disclosure under the TPO exception, the stricter state law prevails.

Practice Problems

PROBLEM 1CONCEPTUAL
Explain the difference between privacy and confidentiality in the context of patient care. Why is it important that nurses understand both concepts, not just one?
PROBLEM 2BASIC CALCULATION
An LPN receives a phone call from a patient's adult daughter who says, "My mother was admitted yesterday. Can you tell me her room number and diagnosis?" The patient is alert and competent. Her medical record shows no signed authorization for disclosure to family members, and she opted out of the hospital's patient directory upon admission. What information, if any, can the nurse share?
PROBLEM 3INTERMEDIATE
An LPN is giving a bedside shift report in a semi-private room. The patient in bed A has a new diagnosis of hepatitis C. The patient in bed B is awake and able to hear the conversation. How should the nurse handle this situation to protect confidentiality while still ensuring a thorough handoff?
PROBLEM 4APPLIED
A 16-year-old patient is treated in the emergency department for a sexually transmitted infection (STI). The patient's parents arrive and demand to know the diagnosis. The state in which the nurse practices has a law allowing minors to consent to STI treatment without parental notification. How does the nurse respond, and what principles guide the decision?
PROBLEM 5CRITICAL THINKING
An LPN discovers that a coworker—another LPN on the same unit—accessed the electronic health record of a well-known local politician who is admitted on a different floor. The coworker tells the LPN, "I was just curious. I didn't share the information with anyone." Analyze the ethical and legal implications of this situation. What actions should the LPN take, and how does the concept of 'minimum necessary' apply even to members of the healthcare staff?

Lesson Summary

Privacy is the patient's right to control access to personal health information, while confidentiality is the nurse's professional duty to protect information shared within the therapeutic relationship. Together with security (physical and technical safeguards), these concepts form three concentric layers of protection around Protected Health Information (PHI). HIPAA and the HITECH Act provide the legal framework that codifies these protections, defining permitted disclosures under the TPO (Treatment, Payment, Operations) exception and requiring the minimum necessary standard for all other disclosures.

For the NCLEX-PN, remember that confidentiality is not absolute—mandatory reporting (abuse, communicable diseases), duty to warn, court orders, and emergency situations are recognized exceptions. Common breach types include verbal (hallway conversations), electronic (social media posts, unattended screens), and physical (unshredded printouts). When state law provides stricter protections than HIPAA, the more protective standard applies. Always ask: Is this person authorized? Is this the minimum necessary information? Have I documented my actions?

Varsity Tutors • NCLEX-PN • Confidentiality And Privacy