Privacy, confidentiality, and security get used interchangeably in everyday conversation about health information, but they describe three different things. Untangling them matters because a healthcare organization can excel at one while falling short on another, and understanding which is which clarifies where actual protection gaps tend to appear. A hospital can pass every technical security audit and still suffer a serious confidentiality breach caused by nothing more than a careless conversation in a crowded elevator, illustrating precisely why these three concepts cannot be treated as a single, interchangeable idea.
The financial and human stakes of getting this distinction wrong are considerable. IBM’s annual Cost of a Data Breach report has repeatedly found healthcare to carry the highest average breach cost of any industry studied, exceeding $10 million per incident in recent years, more than double the cross-industry average, while HHS’s public breach reporting portal shows that health data breaches affecting 500 or more people have cumulatively exposed the records of well over 300 million individuals since federal reporting requirements began in 2009. Privacy concerns the rules and expectations governing who may collect, use, and disclose health information, and under what circumstances.
Confidentiality is the professional duty to keep entrusted information from inappropriate disclosure. Security refers to the technical and administrative safeguards protecting electronic information against unauthorized access, alteration, or loss. The rest of this guide shows how these three concepts operate together within a single patient record.
Privacy, Confidentiality, and Security in One Table
| Concept | Definition | Healthcare example |
|---|---|---|
| Privacy | Rules and expectations about collection, use, and disclosure of information | A hospital’s policy on when it can share records with an insurer |
| Confidentiality | Professional duty to protect entrusted information | A nurse not discussing a patient’s diagnosis with unrelated coworkers |
| Security | Technical safeguards against unauthorized access, alteration, or loss | Encryption protecting a patient portal login |
Privacy: Who Has the Right to Access Health Information?
Patients hold specific rights regarding their own health information, including the right to access their records, generally within 30 days of a request under HIPAA, and request corrections to inaccurate entries. Organizations, in turn, carry responsibilities about how they collect, use, store, and disclose that information.
HIPAA, where applicable, establishes permitted uses and disclosures, including sharing for treatment, payment, and healthcare operations without requiring separate patient authorization for each instance. Other disclosures, outside these core categories, generally require the patient’s explicit authorization. This structure defines privacy as fundamentally a question of who is allowed to do what with information, under which specific circumstances, and HHS’s Office for Civil Rights has investigated more than 300,000 complaints related to these exact questions since HIPAA’s Privacy Rule took effect in 2003.
Confidentiality: What Healthcare Professionals Are Expected to Protect
Confidentiality is a professional and ethical duty that predates modern privacy law by centuries, tracing back at least to the Hippocratic Oath’s explicit pledge to keep confidential whatever a physician sees or hears in the course of treatment, a principle written more than two thousand years before the first HIPAA regulation existed. This duty is rooted in the basic expectation that a person seeking medical care can speak honestly without fear of that information spreading beyond the people who need it for treatment.
This duty extends across every format information takes: a hallway conversation about a patient, a paper chart left in view, and a digital record all fall under the same confidentiality expectation. Appropriate sharing for care coordination, such as a specialist reviewing a referral, differs from inappropriate disclosure, such as discussing a patient’s condition with someone uninvolved in their care out of simple curiosity, a category of violation that continues to account for a meaningful share of reported HIPAA complaints even in an era dominated by headline-grabbing cyberattacks.
Security: How Systems Protect Electronic Health Information
The HIPAA Security Rule, summarized in current HHS guidance, organizes technical protection into three categories. Administrative safeguards include policies, workforce training, and designated security responsibility. Physical safeguards address facility access controls and device security. Technical safeguards cover access control, authentication, encryption, and audit logging within electronic systems.
Security monitoring detects unusual activity that might indicate a breach in progress, and incident response planning determines how quickly and effectively an organization can react once a security event is identified. These safeguards work together as layers rather than standing alone; a strong technical control undermined by weak administrative policy still leaves meaningful gaps, and HHS enforcement data has repeatedly found that risk analysis failures, an administrative safeguard requirement, remain among the most commonly cited violations in resolved HIPAA cases, suggesting organizations often invest more heavily in technical tools than in the foundational governance work meant to guide them.
One Patient Record, Three Protection Layers
Picture a single entry in an electronic health record describing a patient’s recent diagnosis. Privacy governs whether that entry can be shared with an insurance company for a claims decision, and under what conditions. Confidentiality governs whether the nurse who documented it can mention it casually to a colleague outside the care team. Security governs whether an unauthorized outside party could access that same entry through a system vulnerability.
All three layers have to hold for the information to actually stay protected the way a patient would reasonably expect. A failure in any single layer, regardless of how well the other two perform, can result in inappropriate exposure. This is why a comprehensive privacy program addresses all three areas deliberately, rather than assuming strong performance in one automatically covers gaps in another.
Where the Protection Model Gets Complicated
Third-party vendors handling data on behalf of a covered entity extend the protection model beyond the walls of a single organization; the 2013 HIPAA Omnibus Rule extended direct legal liability to these business associates for the first time, closing a gap that had previously left vendor-caused breaches in something of a regulatory gray zone. Cloud systems, health apps not directly connected to a covered entity, medical devices transmitting data wirelessly, health information exchange networks, research databases, and patient-generated data from wearables all introduce additional complexity.
Legal coverage differs significantly depending on the organization and context involved. A hospital’s internal systems are generally covered by HIPAA, while a wellness app a patient downloaded independently may fall entirely outside that legal framework, even though both handle information a patient would consider private and sensitive; surveys of popular consumer health apps have found that a large majority operate entirely outside HIPAA’s jurisdiction, a regulatory gap that has drawn growing scrutiny from the FTC and state-level privacy regulators.
A Healthcare Data Protection Checklist
- Complete inventory of where health information is stored and processed
- Clear access governance defining who can see what information
- Ongoing workforce training on confidentiality expectations
- Encryption for data in transit and at rest
- Continuous security monitoring
- Formal vendor management for third-party data handlers
- Defined data retention and disposal policies
- Documented incident response plan
- Clear, timely patient communication protocols for security incidents
Common Misunderstandings
Privacy does not mean information can never be shared; it means sharing happens according to defined rules and permitted purposes rather than freely or arbitrarily. Security does not guarantee privacy, since a technically secure system can still have overly broad or inappropriate sharing policies governing who gets access.
Confidentiality is not simply a technical control that a software system can fully enforce; it depends heavily on professional conduct and organizational culture alongside any technology in place. HIPAA does not govern every health-related dataset, since many consumer health technologies and apps operate outside its defined scope entirely, even when the information they collect feels every bit as sensitive as what a hospital holds.
Strong healthcare information protection requires privacy rules, confidentiality practices, and technical security safeguards working together as three distinct but interdependent layers, a lesson the field has learned the hard way through decades of incidents ranging from careless hallway conversations to sophisticated ransomware attacks affecting millions of patient records at once.
Organizations evaluating their own data protection posture benefit from examining each layer separately rather than assuming strength in one area compensates for weakness in another. A short internal audit that asks specifically about privacy policy, staff confidentiality practices, and technical safeguards, one at a time, tends to surface gaps that a general security review alone would miss.
This article provides general informational and compliance-related content and is not a substitute for legal advice specific to a particular organization’s situation.
FAQ
Q: What is the difference between privacy and confidentiality?
A: Privacy concerns the rules governing collection, use, and disclosure of information, while confidentiality is the professional duty to protect entrusted information from inappropriate disclosure.
Q: What is the difference between confidentiality and security?
A: Confidentiality is a professional and ethical obligation, while security refers to the technical and administrative safeguards that protect information from unauthorized access or loss.
Q: Is HIPAA about privacy or security?
A: Both. HIPAA includes a Privacy Rule governing use and disclosure of health information and a separate Security Rule governing technical protections for electronic information.
Q: Who is responsible for patient confidentiality?
A: All healthcare workers who have access to patient information carry a professional and ethical responsibility to maintain confidentiality, regardless of their specific role.
Q: How is electronic health information secured?
A: Through administrative, physical, and technical safeguards, including access controls, encryption, workforce training, and audit logging.
Q: Does encryption guarantee patient privacy?
A: No. Encryption is a security measure that protects data from unauthorized access, but it does not by itself determine whether the information is used or shared appropriately.
Q: Does HIPAA protect every health-related app?
A: No. Coverage depends on whether an app operates as, or on behalf of, a covered entity or business associate under HIPAA.