Sending a medical bill to a collection agency is not, by itself, a HIPAA violation. Federal privacy regulations list “collection activities” as a permitted use of protected health information under the definition of payment, so a provider can share limited billing data with a collector without asking you first.1eCFR. 45 CFR 164.501 – Definitions The violation risk lives in the details of how the handoff happens: what gets shared, whether the right contract is in place, and whether the debt is being collected or sold.
Why Collections Count as a Permitted Use
HIPAA lets covered entities use and disclose protected health information (PHI) for treatment, payment, and healthcare operations without patient authorization. The regulation at 45 CFR 164.501 defines “payment” to include “billing, claims management, collection activities, obtaining payment under a contract for reinsurance…and related health care data processing.”1eCFR. 45 CFR 164.501 – Definitions
Collections is written into the rule by name. A doctor’s office or hospital that hands your unpaid balance to a collection agency is doing something HIPAA anticipates. You don’t have to consent, and the provider doesn’t have to warn you.
What a Collector Is Allowed to See
Permitted doesn’t mean unlimited. HIPAA’s “minimum necessary” standard requires a covered entity to “make reasonable efforts to limit protected health information to the minimum necessary to accomplish the intended purpose of the use, disclosure, or request.”2eCFR. 45 CFR 164.502 – Uses and Disclosures of Protected Health Information A collector needs enough to identify you and pursue payment. It does not need your diagnoses, treatment notes, or lab results.
The payment regulation itself sets the practical ceiling by listing what a provider may report to a consumer reporting agency:1eCFR. 45 CFR 164.501 – Definitions
- Name and address
- Date of birth
- Social Security number
- Payment history
- Account number
- Name and address of the provider or health plan
If a collection agency contacts you and seems to know why you were seen, that’s a warning sign. A collector should know you owe a balance to a specific provider for services on certain dates. It should not know the reason for the visit.
The Business Associate Agreement
Before any PHI moves from a provider to an outside collection agency, HIPAA requires a written contract called a Business Associate Agreement (BAA). Under 45 CFR 164.502(e), a covered entity may only disclose PHI to a business associate after obtaining “satisfactory assurance that the business associate will appropriately safeguard the information,” documented through a written contract.2eCFR. 45 CFR 164.502 – Uses and Disclosures of Protected Health Information The agreement has to spell out what the collector can and cannot do with your data and require it to follow HIPAA’s privacy and security rules.
Without that contract, the disclosure is unauthorized, no matter how little information changed hands.3U.S. Department of Health & Human Services. Business Associates Reputable healthcare collection agencies have BAA templates ready. When a provider skips the step, the violation sits with the provider, but your data is still exposed.
When Sending a Bill to Collections Crosses the Line
The act itself is legal. The violations happen inside it.
Sending More Than the Minimum Necessary
A provider that ships your full chart, clinical notes, or diagnostic codes to a collection agency has broken the minimum necessary rule.2eCFR. 45 CFR 164.502 – Uses and Disclosures of Protected Health Information The collector needs billing and identification data. Attaching clinical detail is the most common failure point, and it’s the one most likely to cause real harm when sensitive information such as mental health or substance use records reaches a third party that had no business seeing it.
No Business Associate Agreement on File
If the provider hasn’t signed a BAA with the collection agency, the disclosure of any PHI is unauthorized. HIPAA doesn’t grade this on a curve based on the amount shared.
Selling the Debt Instead of Collecting It
Hiring a collection agency and selling the debt are different transactions. When a provider hires a collector, the collector works on the provider’s behalf, and the BAA framework covers the arrangement. When a provider sells the account to a buyer who pays cash and now owns it, that transfer of PHI for money generally counts as a “sale of protected health information” under 45 CFR 164.508, which requires your written authorization.4eCFR. 45 CFR 164.508 – Uses and Disclosures for Which an Authorization Is Required A BAA cannot paper over this because the buyer isn’t acting for the provider; the buyer owns the account. Providers who want to offload debt legitimately need either patient authorization or records stripped of identifying information before the sale.
The Pay-in-Full Restriction That Blocks Insurer Disclosure
One HIPAA right sits close to the collections question and often gets missed. Under 45 CFR 164.522(a)(1)(vi), if you pay for a service entirely out of pocket, your provider must honor your request to withhold information about that service from your health plan.5eCFR. 45 CFR 164.522 – Rights to Request Privacy Protection for Protected Health Information This restriction is mandatory; the provider cannot refuse.
If you paid in full specifically to keep a visit off your insurance record, and the provider later disclosed information about that visit to your insurer while sending the bill through collections, that’s a violation of a required restriction. Providers sometimes lose these requests inside their billing systems, so a written request kept in your own records is worth having.
Other Laws Also Apply
HIPAA governs the privacy piece. Separate laws govern how the collection itself is conducted, how the debt can be reported to credit bureaus, and how long a provider has to sue. Those rules can help you push back on a medical debt for reasons that have nothing to do with HIPAA, but they don’t change the HIPAA answer: the referral to collections is permitted, and only the mishandling of PHI turns it into a privacy violation.
What to Do If You Think Your Rights Were Violated
Start with the provider’s privacy officer. Many HIPAA problems in billing come from sloppy internal processes rather than deliberate misconduct, and a direct conversation sometimes resolves them.
If it doesn’t, you can file a complaint with the Office for Civil Rights (OCR) at the U.S. Department of Health and Human Services. The complaint has to be filed within 180 days of when you knew or should have known about the violation, and you can submit it through the OCR complaint portal or by mail.6U.S. Department of Health & Human Services – Office for Civil Rights. Complaint Portal Filing costs nothing. OCR investigates and can impose civil monetary penalties on the provider or business associate; the penalties don’t fall on you. Even complaints that don’t produce a fine contribute to enforcement patterns, and some of the largest HIPAA settlements began with a single patient’s report.
Before you file, gather what you have: the collection notices, any envelopes or letters showing what information was sent, dates of contact, and any specifics the collector mentioned that suggest they received more than the six billing categories the regulation allows. The stronger your paper trail, the more useful the complaint.