US · guidance
CMS SOM App. A, Tag A-0147
§482.13(d)(1) - The patient has the right to the confidentiality of his or her clinical records
Interpretive Guidelines §482.13(d)(1)
The right to confidentiality of the patient’s medical record means the hospital must safeguard the
contents of the medical record, whether it is in paper or electronic format, or a combination of the two,
from unauthorized disclosure. Confidentiality applies wherever the record or portions thereof are stored,
including but not limited to central records, patient care locations, radiology, laboratories, record storage
areas, etc.
A hospital is permitted to disclose patient information, without a patient’s authorization, in order to
provide patient care and perform related administrative functions, such as payment and other hospital
operations.
• Payment operations include hospital activities to obtain payment or be reimbursed for the provision
of health care to an individual.
• Hospital operations are administrative, financial, legal, and quality improvement activities of a
hospital that are necessary to conduct business and to support the core functions of treatment and
payment. These activities include, but are not limited to: quality assessment and improvement
activities, case management and care coordination; competency assurance activities, conducting or
arranging for medical reviews, audits, or legal services, including fraud and abuse detection and
compliance programs; business planning, development, management, and administration and certain
hospital-specific fundraising activities.
The hospital must develop policies and procedures that reasonably limit disclosures of information
contained in the patient’s medical record to the minimum necessary, even when the disclosure is for
treatment or payment purposes, or as otherwise required by State or Federal law.
When the minimum necessary standard is applied, a hospital may not disclose the entire medical record
for a particular purpose, unless it can specifically justify that the whole record is the amount reasonably
needed for the purpose.
A hospital may make an authorized disclosure of information from the medical record electronically,
and may also share an electronic medical record system with other health care facilities, physicians and
practitioners, so long as the system is designed and operated with safeguards that ensure that only
authorized disclosures are made.
The hospital must obtain the patient’s, or the patient’s representative’s, written authorization for any
disclosure of information in the medical record when the disclosure is not for treatment, payment or
health care operations.
Survey Procedures §482.13(d)(1)
• Verify that the hospital has policies and procedures addressing the protecting of information in
patients’ medical record from unauthorized disclosures.
• Observe locations where medical records are stored to determine whether appropriate safeguards
are in place to protect medical record information.
• Interview staff to determine their understanding of and compliance with the hospital’s policies
and procedures for protecting medical record information.
History
Rev. 95, Issued: 12-12-13, Effective: 06-07-13, Implementation: 06-07-13
Provenance
- Source
- cms.gov
- Retrieved
- 2026-07-22
- Edition
- som-2026-07-22
- Content hash
fa10ff335b9abacdf6fed0cf220a120aa703debf2fc93d901d2c2c0cf1b401d4
The link goes to the issuing authority’s own document — the one we read to produce this record. Where a source publishes whole titles rather than sections, your browser may need a moment to jump to the provision.
Unofficial copy of government-published law, reproduced from official sources with full provenance. Not an official publication; verify against official sources before relying on it in a filing. Records in the 'guidance' corpus, and only that corpus, are sub-regulatory (interpretive guidelines, survey procedures) and are not binding law. Validity bounds follow each jurisdiction's declared temporalBasis.