BLOG

What HIPAA actually requires when you call a payer

Minimum necessary, verifying who is on the line, and what your team should never read out loud. A plain-language walkthrough for the front desk.

Table of Contents

Benefit verification involves disclosing patient information to a third party several dozen times a day. Most front desk teams have never been told exactly what the rules are, and the folklore that fills the gap tends to be wrong in one specific direction: people assume the call is fully exempt from HIPAA’s limits because it is a payment activity. It is not.

Here is what actually applies. This is a plain-language summary, not legal advice, and your compliance officer should own the final policy.

The call itself is permitted

You do not need patient authorization to contact a health plan about eligibility and benefits. Disclosures for payment purposes are permitted under the Privacy Rule’s treatment, payment, and health care operations provisions at 45 CFR 164.506. Nobody has to sign anything for you to verify coverage.

But the minimum necessary standard does apply

This is where the common misunderstanding sits. There is a well-known exception to the minimum necessary standard for treatment, and teams generalize it to everything in the TPO bucket.

HHS guidance lists the exceptions precisely. The standard does not apply to disclosures to or requests by a health care provider for treatment purposes, disclosures to the individual, uses or disclosures made under an authorization, uses required for HIPAA Administrative Simplification compliance, disclosures to HHS for enforcement, and uses or disclosures required by other law.

A health plan is not a health care provider, and verifying benefits is payment, not treatment. So the exception does not reach this call, and you are obligated to limit what you disclose to the minimum reasonably necessary to accomplish the purpose.

In practice that means the identifiers needed to locate the member and the benefit: name, date of birth, member or subscriber ID, group number, provider identifiers, and the procedure codes you are asking about. It does not mean the clinical narrative, unrelated medical history, other family members’ treatment, or a walk through the chart because the representative asked a vague follow-up question.

Verification runs in both directions

The rule most often skipped is 45 CFR 164.514(h), which requires a covered entity to verify the identity of a person requesting protected health information, and that person’s authority to have it, when they are not already known to the entity.

That obligation is yours on inbound calls. When someone phones the office claiming to be from a carrier and starts asking for patient details, the burden is on your team to establish who they are before answering. The safe habit is simple: take the reference number, end the call, and dial the payer back on a number you already have on file rather than one the caller supplies.

Related Blogs

Get the verification checklist we use internally

Every field we check before a patient's name reaches your schedule, in one page. Enter your email and we'll send it over.