Skip to main content
U.S. flag

An official website of the United States government

Dot gov

The .gov means it’s official.
Federal government websites often end in .gov or .mil. Before sharing sensitive information, make sure you’re on a federal government site.


The site is secure.
The https:// ensures that you are connecting to the official website and that any information you provide is encrypted and transmitted securely.

Notice of Proposed Rule Making for Standards for Privacy of Individually Identifiable Health Information

Published November 3, 1999; Comment period ended February 17, 2000

Complete NPRM as published on November 3, 1999 in the Federal Register:

Comment period extension as published on December 15, 1999 in the Federal Register:

Technical Corrections as published on January 5, 2000 in the Federal Register:

To read files in Adobe's Portable Document Format (PDF), you will need Adobe Acrobat Reader 3.0 or above. If you do not already have Acrobat, click here:Get acrobat Reader

Also available in text format (for faster viewing but without formatting):

Read NPRM, by Section
Summary and Introduction
Table of Contents
Background: Need for Privacy Standards
Statutory Background
Summary and Purpose of the Proposed Rule
Introduction to General Rules
Use and Disclosure for Treatment, Payment, and Health Care Operations
Minimum Necessary Use and Disclosure
Right to Retrict Uses and Disclosures
Creation of De-Identified Information
Application to Business Partners
Application to Information About Deceased Persons
Adherence to the Notice of Information Practices
Application to Component Entities
Uses and Disclosures With Individual Authorization
Introduction to Uses and Disclosures Without Individual Authorization
Uses and Disclosures for Public Health Activities
Use and Disclosure for Health Oversight Activities
Use and Disclosure for Judicial and Administrative Proceedings
Disclosure to Coroners and Medical Examiners
Disclosure for Law Enforcement
Uses and Disclosures for Governmental Health Data Systems
Disclosure of Directory Information
Disclosure for Banking and Payment Processes
Uses and Disclosures for Research
Uses and Disclosures in Emergency Circumstances
Disclosure to Next-of-Kin
Additional Uses and Disclosures Required by Other Law
Application to Military Services
Application to the Department of Veterans Affairs
Application to the Department of State
Application to the Intelligence Community
Introduction to Rights of Individuals
Rights and Procedures for a Written Notice of Information Practices
Rights and Procedures for Access for Inspection or Copying
Rights and Procedures for Accounting of Disclosures
Rights and Procedures for Amendment or Correction
Introduction to Administrative Requirements
Designation of a Privacy Official
Duty to Mitigate
Development and Documentation of Policies and Procedures
Relationship to State Laws
Relationship to Other Federal Laws
Small Business Assistance
Preliminary Regulatory Impact Analysis
Initial Regulatory Flexibility Analysis
Unfunded Mandates
Environmental Impact
Collection of Information Requirements
Executive Order 12612: Federalism
Executive Order 13086: Consultation and Coordination With Indian Tribal Governments
List of Subjects in 45 CFR Parts 160 and 164
Appendix to the Preamble: Sample Content of Provider Notice
Regulation Text
Appendix: Model Authorization Form