
Estimated reading time: 21 minutes
Every physician was taught in medical school that patient confidentiality is sacred. However, school doesn’t always teach that this principle also contains important exceptions—such as mandatory reporting and public health requirements—that are essential to modern healthcare.
HIPAA laws get the most attention when it comes to privacy issues in medicine, but the scope extends far beyond that, shares Whit Johnson with Sermo, an attorney who specializes in medical malpractice and licensure defense in the Jackson, Miss. area. “It’s not just about legal issues,” Johnson says. “There are also ethical situations that you have to think about, which means the state licensure board could get involved. Then you’re not only dealing with fines, you’re dealing with someone taking your license or suspending it for a period of time.”
To help navigate these high-stakes situations, this article presents a guide for practicing physicians that directly answers “What do I do?” when these complex scenarios walk into your exam room or arrive in your email inbox.
Disclaimer: This article reflects real conversations taking place within the Sermo physician community and is published for educational purposes only. It does not constitute legal or medical advice. The information provided is general in nature; laws governing medical malpractice, standard of care, and liability vary significantly by jurisdiction. Physicians should contact a qualified legal representative for advice specific to their circumstances. Quotes from community members have been anonymized.
The basics of patient confidentiality: a quick reminder
Patient confidentiality is the professional obligation of healthcare providers to keep a patient’s personal and medical information private, sharing it only with authorized parties or when legally mandated. It is integral to the trust that must underlie the physician-patient relationship so that patients can feel free to reveal essential medical information to their treaters. Under both ethics and law, patient confidentiality is the default position: the Hippocratic tradition, the AMA Code of Medical Ethics and HIPAA all establish that patient information cannot be disclosed without explicit authorization unless a specific legal exception applies.
Confidential information includes:
- Names, dates of birth and addresses.
- Medical histories, treatment plans and test results.
- Billing and insurance records.
- Conversations had with practitioners including doctors, nurses, therapists, and pharmacists, and their support staff such as receptionists.
Under HIPAA’s privacy rule, disclosure of confidential information is allowed in certain circumstances. These include permitted disclosures (where the physician may but is not required to disclose) and required disclosures (where the physician must disclose). Each is a distinct category with different implications.
While regulatory frameworks define the legal boundaries, applying them under pressure is rarely simple. “The real challenge isn’t the law, it’s the moment,” one physician shared on Sermo. “A subpoena lands, a cop asks questions, or a family member pleads for information. HIPAA gives rules, but it doesn’t give courage.”
Here is a practical roadmap to help you evaluate and handle those scenarios when they arrive in your clinic.
A practical decision framework for confidentiality scenarios
When a high-pressure request for patient information lands on your desk, you rarely have the luxury to brush up on statutes. This step-by-step checklist can help you evaluate the request quickly and protect both your patient’s rights and your legal standing.
“Confidentiality is sacred, but it’s not absolute: mandatory reporting, imminent third-party harm, valid court orders all override it, and knowing exactly where those exceptions sit is what keeps me safe. I’d argue that fluency in the medicolegal rules protects us better than any malpractice policy,” an early-career physician shared on Sermo.
Before releasing any PHI, run the request through this 7-step decision framework:
1. Who is asking? Determine the role and identity of the requesting party. The rules change drastically depending on whether the requestor is the patient, a family member, law enforcement representative, public health official, another healthcare provider, or a court – to name a few.
2. What legal basis applies? Determine the precise authority under which the request is requested or permitted. Types of authorizations could include:
- Patient authorization – via a HIPAA-compliant release signed by the patient.
- Permitted HIPAA disclosure – for treatment, payment or healthcare operations (TPO) purposes.
- Required HIPAA disclosure – for example, mandated requests by HHS for compliance audits.
- State-mandated disclosure – involving statutory reporting obligations, such as gunshot wounds or specific communicable diseases.
- Court order – direct mandates by a judicial authority.
3. Is the request properly documented? Verify that a legal request carries the appropriate authority before moving ahead. Court orders and grand jury subpoenas are legally binding and should be honored according to their specific terms, while administrative subpoenas require verification before records can be released. Informal verbal requests (phone inquiries and person-to-person conversations) don’t provide legal justification for disclosing PHI.
4. What is the minimum necessary disclosure? Even when a disclosure is authorized or required, limit the released information only to what is asked for. Don’t “overdisclose” by releasing (for example) an entire medical record when providing only a small bit of information would satisfy the request.
5. What does state law require? State laws often impose stricter privacy protections than HIPAA – particularly regarding:
- Mental health matters/psychotherapy notes
- HIV/AIDS status and testing records
- Substance use disorder (SUD) treatment records
- Specific reportable physical conditions or injuries
6. Have I documented the decision? Thorough recordkeeping can be a solid defense in a legal dispute. When you receive a request, document the date and time of the request, the identity of the requesting party, the legal basis you’re relying upon, any consultations you may have with risk management or legal counsel, and exactly what information was released
7. Should I consult counsel? For nonroutine or ambiguous requests, it’s a good idea to pause and seek expert advice. The cost and time required for a brief consultation with legal counsel or your insurer’s risk management line is small, but the cost of an improper disclosure can be substantial.
Common gray-zone scenarios for physicians
When asked which scenario presented the most ethical friction to report, physicians on Sermo shared that reporting suspected child or elder abuse (21%), infectious diseases (14%), domestic abuse (17%) and impaired drivers (13%) gave them the most pause. Here are common scenarios you may face:
The duty to warn: when there is a credible threat to others
A physician has a duty to warn when a patient communicates an imminent, credible threat of physical harm to someone. In these scenarios, protecting the intended victim overrides standard patient confidentiality rules.
In a recent Sermo poll, however, only 20% of physician respondents said they were “highly confident” in executing their duty to warn, while 22% felt unprepared. That hesitation is understandable, given how quickly a clinical encounter can turn into a legal tightrope – but understanding the foundations of this obligation can help bridge such a confidence gap. 48% of respondents in the poll were confident in being able to act, after consulting their legal counsel.
Most U.S. states have laws that either require or permit mental health professionals to warn or take protective action when a patient presents a serious threat of violence, and it has been suggested that this duty may also extend to sexually transmissible diseases. HIPAA’s Privacy Rule allows physician disclosure of PHI to prevent or lessen a serious threat to a person or the general public. Even in states that do not require warning, the physician is not violating HIPAA or abandoning the therapeutic relationship by doing so.
The duty to warn applies most clearly when the threat is:
- Identifiable: The patient names a specific third party.
Non-specific threats and statements from patients like “I want to kill someone”, “I might hurt my ex someday” can be harder to identify. In these cases, thoroughly document your clinical rationale, consult risk management or legal counsel, and lean toward protective action whenever a credible, identifiable target exists. “I have been instructed to run things by risk/compliance colleagues if there is ever a question,” one physician shared on Sermo.
- Imminent: The threat is imminent and credible.
- Severe: The threat involves serious physical harm.
What to do
- Document the threat (verbatim) in the chart immediately
- Conduct and document a risk and credibility assessment
- If the threat meets the duty-to-warn threshold, notification may go to the identifiable third party, someone who can mitigate the threat, or law enforcement, as needed. Document who was notified, when they were told, and what was said.
- Continue clinical management of the patient if feasible.
- Consider involuntary commitment if the patient meets the criteria in your jurisdiction.
- Consult with risk management or institutional counsel if time allows. If it doesn’t, document the decision and your reasoning.
Reasonable suspicion: When a child, an elder or a vulnerable adult is being abused
Mandatory reporting of suspected abuse is one of the few legal domains where state law typically removes physician discretion entirely. A physician is required to report suspected abuse whenever clinical observations or statements establish a reasonable suspicion or cause to believe that a child, elderly individual or vulnerable adult is experiencing physical or sexual abuse, neglect or emotional mistreatment.
All 50 states have child abuse reporting laws that name physicians as mandated reporters. Most states also have parallel elder abuse and dependent adult abuse reporting laws. The threshold is typically “reasonable suspicion” or “reasonable cause to believe,” not proof. In other words, the physician should not put themselves in the position of verifying abuse, but they must report any suspicions to the agency that investigates such situations.
What to do
- Document the clinical findings that prompted the suspicion
- Make the report to the appropriate agency (child or adult protective services, a state-specific elder abuse hotline) within the timeframe state law requires (often within 24 hours). Do not delay reporting to confirm suspicion through further investigation. Investigation is the agency’s job.
- Document the report in the chart, including who was contacted and when, and what was reported.
- Continue clinical care of the patient. Document any safety planning steps taken, such as hospital admission for protective reasons, a social work consultation, or a separate family interview.
Physicians are sometimes reluctant to report because of anxiety over damaging the therapeutic relationship or uncertainty about the abuse. As one physician on Sermo emphasized, protecting vulnerable patients is crucial, but reporting concerns can challenge the physician-patient relationship, particularly when families resist reporting or seek to keep the situation confidential. 42% of physicians in a Sermo poll agreed that suspected abuse represents a key driver of friction in a doctor-patient relationship.
However, state mandatory reporting laws are specifically written to remove this discretion, because the burden of delayed reporting falls disproportionately on the victim. When “reasonable suspicion” exists in your professional judgment, the decision is already made: The report must occur.
The set-off to the mandate, though, is that doctors and other mandated reporters are generally granted broad immunity from both civil and criminal liability when they report suspected abuse based on reasonable suspicion, provided the report is made in good faith.
Criminal injuries
Gunshot wounds and certain other injuries trigger mandatory reporting requirements in almost every state – often with strict timelines regarding notification.
Most U.S. states require physicians (and often hospitals) to report gunshot wounds, stab wounds and other suspected criminal injuries to law enforcement. Some states extend this to burns, certain blunt force trauma and animal bites. The reporting threshold varies; some states require reporting of any gunshot wound, while others only mandate reports be made if the physician believes the wound has been criminally inflicted. If you’re in a state that mandates reporting of violent injuries, you can release certain medical information without violating HIPAA.
What to do
- Stabilize and treat the patient first.
- Document the injury, the history given by the patient and the clinical findings.
- Make the report to law enforcement within the timeframe required by the laws in your state (often immediately or within 24 hours).
- Disclose only the minimum information necessary to satisfy the reporting requirement.
- Do not volunteer additional PHI beyond what the law requires.
Physicians sometimes feel torn between protecting the patient-physician alliance and fulfilling a legal mandate to contact law enforcement — especially when a patient begs the doctor not to call the police. In cases like these, transparency is best; explain to the patient that state law requires you to notify authorities about these specific types of injuries, while reassuring them that their broader medical information remains confidential.
Population health and communicable disease
This is one of the oldest and most settled exceptions to medical confidentiality. By reporting certain contagious conditions to public health authorities, physicians can help keep the public safer and healthier. State public health agencies maintain and regularly update these reportable disease registries, including requirements for timely reporting.
HIPAA’s Privacy Rule explicitly accommodates public health reporting by permitting PHI disclosure for the purpose of monitoring, preventing or controlling disease. Patient consent isn’t required.
Every U.S. state mandates that physicians report specific communicable diseases and infections to state and local health authorities. The exact list of conditions varies by state, but typically includes sexually transmitted infections, airborne and respiratory illnesses, foodborne pathogens, and emerging public health threats, like novel viruses.
What to do
- Know your state’s current reportable disease list. Most state public health departments publish it online.
- Make the report through the prescribed channel within the required timeframe.
- Document the report in the patient’s chart.
- For some conditions (HIV, STIs, tuberculosis), partner notification programs may be available. These programs allow public health staff to notify exposed contacts without revealing the original patient’s identity. Use them where available.
- Discuss the reporting with the patient where clinically appropriate. Framing the report as a routine, mandatory public health requirement, and assuring the patient that their identity remains protected, helps preserve trust. (Note that in some states, confidentiality requirements for HIV infections are more stringent than for other conditions, so verify your specific state’s laws on these disclosures.)
PHI demands from law enforcement
Requests from police for health information are the scenarios most likely to result in HIPAA violations, since they come in many different forms and physicians often don’t realize that not all law enforcement requests are equal.
When law enforcement requests patient records, doctors should immediately identify the specific legal basis being used, refrain from releasing information in response to informal requests, and consult legal or compliance colleagues before responding. 38% of physicians on Sermo agreed that they’d wait for a warrant or subpoena, and another 27% said they’d defer the interaction to their legal counsel before disclosing any information.
Law enforcement requests typically come from one of these five categories:
- Court order or warrant signed by a judge or magistrate: Comply strictly with the order or warrant. Disclose precisely what is specified in the document — nothing more. Failure to comply with a direct judicial order can result in contempt-of-court sanctions.
- Grand jury subpoena: Comply with the subpoena. Grand jury proceedings are confidential, so HIPAA permits compliance, without requiring additional assurances or patient notification.
- Administrative subpoena, summons or investigative demand: The requesting agency must confirm that the information is relevant and material to a legitimate law enforcement inquiry, the request is specific and limited in scope, and that de-identified information could not reasonably be used to fulfill the purpose. Verify these conditions before disclosing.
- Subpoena signed by a court clerk, lawyer or prosecutor (not a judge): A piece of paper labeled “subpoena” does not automatically authorize disclosure. Under HIPAA, you may disclose PHI only after receiving satisfactory assurance that either the patient was notified and given an opportunity to object, or that a qualified protective order was obtained.
- Informal phone calls or in-person requests: Never disclose PHI based on a verbal request, or routine inquiry by an officer. Direct the officer to the appropriate written process and to your institution’s legal or compliance team. “Warrantless law enforcement requests get a polite but firm redirection to our legal team; no data leaves without a court order or explicit patient consent,” one physician shared on Sermo.
What to do
- Identify the type of request and confirm the identity and authority of the person making it.
- Notify your institution’s legal counsel, compliance officer or risk management team before responding. This is mandatory for any nonroutine request.
- Disclose only the minimum information necessary to satisfy the legal requirement.
- Document the request, the type of legal process used and exactly what was disclosed.
As of 2026, substance use disorder treatment records protected under 42 CFR Part 2 carry heightened protections that go beyond general HIPAA standards. SUD records cannot be disclosed in legal or criminal proceedings based on a standard subpoena or general court order. Access requires a specific type of court order, and the court must find that alternative means of obtaining the information are unavailable or ineffective.
Care discussions with a patient’s family member
Navigating conversations with a patient’s family involves a surprisingly flexible regulatory framework, yet it remains a source of confusion for many clinical teams.
Under HIPAA regulations, physicians are permitted to share relevant PHI with family, friends or others identified by the patient as involved in their care. According to guidance from HHS, this is one of the broadest permitted disclosure exceptions under HIPAA. Information can be shared if:
- The patient explicitly agrees or does not object when given the opportunity.
- The physician reasonably infers from the circumstances (using professional judgment) that the patient does not object.
- The patient is incapacitated or in an emergency: The physician determines, using professional judgment, that sharing directly relevant information is in the patient’s best medical interest.
74% of physicians on Sermo said they required a verified authorization form or verbal verification from their patient before sharing information with family.
What to do
- Ask the patient who they want included in care discussions. Document the answer.
- If the patient cannot consent (unconscious/incapacitated), use professional judgment to determine what disclosure is in the patient’s best interest.
- Disclose only the information directly relevant to the family member’s involvement in care. Do not disclose unrelated PHI.
- If a family member contacts the practice asking about the patient and the patient has not authorized disclosure, do not confirm or deny that the patient is being treated. The mere fact that an individual is receiving treatment is itself PHI.
- For minor patients, the parent or legal guardian generally has the right to PHI, but with some exceptions for confidential care related to sexually transmitted infections, contraception, substance use and mental health (this varies by state).
Misunderstandings around family care discussions often extend to scenarios where a physician is treating or advising their own relatives. In a Sermo poll, 32% of physician respondents incorrectly believed that HIPAA and state confidentiality laws are waived if the physician is a family member of the patient. One Sermo member with medicolegal expertise clarified during the community discussion: “HIPAA and state confidentiality laws apply fully to the dissemination of protected health information on family members. If the family member is an adult, it stops there; they dictate who can receive their PHI.”
Impaired drivers
Reporting at-risk drivers sits in a complex legal ground between legal compliance and permissive clinical discretion. State laws governing the reporting of medically impaired drivers vary. Some states, including California, Pennsylvania and Oregon, require physicians to report patients with certain medical conditions affecting their ability to drive safely. Other states permit – but do not require – such reporting.
What to do
- Know your state’s specific reporting law. The conditions covered vary (they can include epilepsy, syncope, dementia, vision impairment and others), and the mechanism to submit a report can differ as well.
- Discuss driving safety with the patient and family directly. Document the clinical findings, the discussion with the patient, and any recommendations made.
- If the state requires reporting, make the report through the appropriate motor vehicle authority within the timeframe required.
- If the state permits but does not require reporting, exercise clinical judgment. The American Medical Association generally supports physician discretion in these cases.
Patient secrets
Requests to keep information “off the record” are difficult scenarios encountered frequently across psychiatry, addiction medicine, primary care and OB-GYN.
Physicians have an obligation to maintain complete and accurate medical records. The chart is the medical and legal record of any care provided, so leaving information out at a patient’s request typically violates both the standard of care and any applicable recordkeeping regulations.
What to do
- Acknowledge the patient’s concern about confidentiality. Often, patients are not concerned about the existence of the record itself, but who will see it.
- Discuss the exact scenario the patient is worried about – this could include custody issues, employers getting the info or legal liabilities. For some of these situations, there may be statutory safeguards.
- If state law allows it, consider segregated documentation for particularly sensitive content (sensitive psychotherapy notes, SUD records). These may have specific protections.
- Do not omit clinically relevant information from the chart. Document the patient’s confidentiality concerns and any specific steps taken to address them. If the patient becomes uncooperative or angry, consider whether discontinuing the therapeutic relationship is appropriate.
A complete and accurate chart is one of the strongest protections you can maintain. Fragmented or altered records can lead to misinterpretation by future providers or in legal proceedings. Frame the conversation honestly with your patient: the choice is never whether to document, but rather how to address the patient’s underlying medical concern.
The gray areas: Scenarios where the rules don’t give a clear answer
Most physicians can identify well-defined compliance scenarios and apply the proper rules. The harder question is what to do when the situation does not fit cleanly into any of them. “I’ve found that the toughest moments aren’t the clinical ones, but those ‘gray areas’ where the law clashes with the patient’s trust,” a Sermo member shared with peers.
General steps for gray areas:
When facing ambiguous cases like the ones described below, applying a set of core principles can help you take the right actions. In general, you should:
- Document your reasoning for releasing PHI
- Consult institutional resources when time allows
- Lean toward the more cautious interpretation in cases of uncertainty
- Follow established protocols
Here are a few examples of ambiguous situations in patient confidentiality, and how to navigate them:
A minor patient discussing sensitive topics
This is the most common gray area in pediatric and adolescent primary care. A 16-year-old patient may discuss sexual activity, substance use, contraception or mental health, after which a parent requests details of the discussion.
The general HIPAA rule gives parents access to a minor’s PHI, but state laws carve out significant exceptions for confidential adolescent care in sexually transmitted infection treatment, contraception, mental health and substance use. State statutes regarding this vary significantly.
- Know your state’s rules in advance of a visit from a minor.
- Establish confidentiality boundaries with both the adolescent and the parent at the start of care, explaining what remains confidential and what statutory exceptions require parental notification
- When invoking a confidentiality exception, document its legal basis (state statute, age, type of care) in the patient’s chart.
- When in doubt, consult institutional counsel or your specialty society’s adolescent care guidance.
Off-record colleague conversations
Doctors often don’t think of informal peer updates as confidentiality breaches. Examples include discussing a mutual patient in a hallway or cafeteria, sending unencrypted text messages about a case, answering an inquiry from a colleague on another service, or even sharing too much about a patient case on Sermo.
- Apply the “handoff test.” Ask yourself whether the information being shared would be appropriate to document formally in the chart as part of a clinical handoff. If yes, it falls under TPO; if it is driven by curiosity or social discussion, it does not.
- Avoid hallway conversations and text messages when discussing PHI, and use secure HIPAA-compliant platforms instead. Even if you are conversing with an individual authorized to have the patient’s PHI, the details may be overheard or accidentally seen by someone else.
A deceased patient’s family requests records
Confidentiality does not expire when care stops or when a patient passes away. Under HIPAA guidelines, protected health information (PHI) remains legally protected for 50 years after a patient’s death.
Family members may seek immediate access to records for grief processing, family health history, or estate settlement, and can be surprised when access is restricted. HIPAA rules for deceased patients differentiate between an appointed personal representative with access rights (such as an estate executor) and other family members, who do not automatically have access.
- Before releasing any information, verify the legal status of the requestor. Personal representatives, such as authorized estate executors, have the same access rights the patient had. Other family members do not, unless they were authorized by the patient prior to their death.
- Evaluate requests that may fall under health-related exceptions. Other family members may be able to access some PHI to determine genetic risk factors or risk of developing a hereditary condition, for example. In these cases, a provider may use their professional judgment to disclose limited, relevant PHI.
- Keep meticulous documentation. When information is released, note how the status of requestor was verified, and the rationale for any limited disclosures made.
How to remain compliant when posting patient cases on Sermo
While Sermo’s verified physician community is significantly safer than open social media networks, HIPAA principles still apply. Posting a case on Sermo is a disclosure of PHI. To share cases safely, information must be minimal and thoroughly de-identified.
Follow these precautions:
- Strip the 18 HIPAA Safe Harbor identifiers. This includes names, geographic location narrower than a state, specific dates, medical record numbers and more. Replace specific dates with relative timing, such as “three days post-op.” Replace ages over 89 with “90+.”
- Go for clinical specificity rather than identifying details. “54-year-old, NIHSS 12, last known well at 06:30” is clinically useful. “54-year-old teacher from a small town in northern Vermont” is potentially identifying and provides no clinical value.
- Scrub images. Crop photos tightly and strip their metadata. Watch for tattoos, jewelry, facial features and background detail that may identify a patient. Be especially cautious with pediatric images, dermatological photos and highly unique, recognizable anatomical anomalies.
- Beware the small-population problem. Merely removing Safe Harbor elements isn’t always enough to completely de-identify a case. The combination of a rare presentation, narrow specialty and small geographic region may allow others to deduce the patient’s identity.
- Check institutional regulations. Many employers have policies governing case-sharing on physician-only platforms. Before you make your first post, ensure it won’t violate any rules.
- Use this default test: Would you post the information if the patient could read it? If not, revise it, or don’t post it at all.
- If a case is unusual enough that recognition cannot be prevented, obtain patient authorization before posting anything about it.
Navigating confidentiality with certainty
Patient confidentiality is the default position and its legal and ethical exceptions are specific, narrowly defined and occasionally mandatory. Navigating these scenarios doesn’t mean that you have to memorize every regulation. Instead, develop a habit of asking questions like:
- Who is asking for this information?
- What legal basis applies?
- What is the minimum necessary disclosure?
- What does state law require?
When faced with nonroutine, ambiguous or high-stakes requests, the highest-leverage move is always to pause and consult your institution’s risk management or legal counsel before disclosing PHI. 46% of physicians on Sermo agree that this is the first step in getting clarity on how to proceed, followed by peer consultation (24%) and professional hotline resources (15%).






