Selling protected health information (PHI) is a sensitive topic that has legal, ethical, and practical concerns. Under the Health Insurance Portability and Accountability Act (HIPAA), the sale of PHI is strictly regulated, and unauthorized transactions can lead to severe penalties.
According to the U.S. Department of Human and Health Services (HHS), “The Privacy Rule prohibits you from selling PHI unless you obtain an authorization stating that you will receive remuneration from making the disclosure.”
Covered entities and business associates must obtain explicit, written consent from the individual whose information is being sold. This authorization must detail:
HIPAA allows for cost-based remuneration in cases where PHI is disclosed. For example, charging for the labor involved in transferring records is acceptable. However, transactions aiming for profit are not permitted under the law.
See also: HIPAA Compliant Email: The Definitive Guide
The sale of PHI involves disclosing PHI in exchange for direct or indirect payment or remuneration. This includes any transaction where PHI is exchanged for monetary or non-monetary value.
Organizations should understand HIPAA regulations, implement robust safeguards, obtain written authorization when necessary, and seek legal advice to navigate complex scenarios.