Chapter 5. Protecting Patient Privacy and Maintaining Appropriate Boundaries
Hospitals and health systems have access to some of the most personal information people can share. Medical records may include diagnoses, medications, test results, treatment histories, mental-health information, financial details, family circumstances, photographs, recordings, and other sensitive information. Protecting this information is essential to maintaining patient dignity, complying with applicable requirements, and preserving public confidence.
Hospital visibility, community outreach, and health education should never come at the expense of patient privacy. Before hospital personnel participate in an interview, article, video, event, photograph, social-media campaign, or Sanj Talks initiative, they should establish clear privacy protections and appropriate professional boundaries.
Understanding the HIPAA Privacy Rule
The HIPAA Privacy Rule establishes national standards protecting individuals’ medical records and other individually identifiable health information. It applies to health plans, healthcare clearinghouses, and healthcare providers that conduct certain healthcare transactions electronically. The rule also applies to business associates in specified circumstances.
The U.S. Department of Health and Human Services explains that the Privacy Rule protects individually identifiable health information held or transmitted by a covered entity or its business associate in electronic, paper, oral, or other forms. This information is generally known as protected health information, or PHI. HHS overview of the HIPAA Privacy Rule
Individually identifiable health information may include demographic or medical information that identifies a person—or for which there is a reasonable basis to believe the information could identify that person. A name is an obvious identifier, but identity may also be revealed through an address, photograph, date, medical condition, workplace, family relationship, unusual treatment history, or combination of details.
Hospital teams should not assume that removing a patient’s name makes a story anonymous. A description such as “the only 42-year-old firefighter treated after a particular local incident” may reveal the individual’s identity even without stating a name.
HIPAA is not the only consideration. State privacy laws, professional obligations, hospital policies, contractual requirements, research rules, accreditation standards, and other requirements may provide additional protections. Hospitals should rely on their privacy, legal, compliance, clinical, and communications professionals to determine what is permitted in each situation.
Never Assume Informal Consent Is Enough
An appreciative patient may offer to share a positive experience, appear in a photograph, provide a testimonial, or participate in a video. That willingness does not necessarily mean hospital personnel can immediately record, publish, or distribute the patient’s story.
A casual verbal statement such as “Yes, you may use my picture” may not satisfy HIPAA authorization requirements, hospital policy, or other applicable rules. HHS explains that, with limited exceptions, a valid written HIPAA authorization is generally needed before a covered entity or business associate posts an individual’s PHI in a website testimonial or social-media campaign. HHS HIPAA enforcement guidance concerning patient testimonials
Before using a patient’s name, photograph, video, quotation, diagnosis, treatment history, or testimonial, hospital personnel should confirm:
- Whether a valid written authorization is required
- Whether the authorization covers the intended information and purpose
- Where and how the material may be published
- Whether editing, redistribution, advertising, or social-media use is permitted
- Whether the hospital has completed its internal privacy and legal review
- Whether additional consent or release forms are required
- Whether the proposed use remains respectful and appropriate
Authorization for one purpose should not automatically be treated as permission for every future use. A patient who agrees to appear in an internal hospital newsletter may not have authorized use in an external video, public event, sponsored campaign, or Sanj Talks article.
Protect Privacy During Photography and Recording
Hospitals should maintain strict controls over photography and recording on hospital property. Treatment areas, waiting rooms, hallways, nurses’ stations, patient rooms, computer screens, medical charts, identification bracelets, room signs, whiteboards, voices, and background conversations may reveal PHI.
HHS states that healthcare providers generally cannot allow media personnel or film crews into treatment areas—or other locations where PHI will be accessible—without prior written authorization from each affected individual. Blurring a face or altering a voice afterward does not solve the problem if unauthorized media access to PHI already occurred. HHS guidance on media and film crews in healthcare facilities
Hospital approval should therefore be obtained before any Sanj Talks representative, photographer, videographer, interviewer, or event participant records on hospital property. The hospital should decide:
- Which locations may be used
- Who may enter those locations
- Whether patients or visitors could appear
- How background PHI will be protected
- Which hospital personnel may participate
- Who will supervise the recording
- How files will be transferred, reviewed, stored, edited, and published
- Whether hospital branding and signage may be shown
When practical, recording in a controlled conference room, studio, administrative office, or off-site location may reduce privacy risks.
Use Fictional or Properly De-identified Examples
Patient stories can help audiences understand complicated health topics, but an actual case is not always necessary. A fictional example may explain a general concept without exposing anyone’s private information. The content should identify the example as fictional so readers do not mistake it for a documented patient experience.
Another option may be properly de-identified information. However, de-identification involves more than casually removing a name. HHS recognizes two methods for de-identifying PHI under the HIPAA Privacy Rule: Expert Determination and Safe Harbor. Properly de-identified information must not identify an individual, and the covered entity must have no reasonable basis to believe it can be used to identify that individual. HHS guidance on de-identification of protected health information
Hospital personnel should not make informal de-identification decisions without appropriate expertise and approval. Combining details such as a rare diagnosis, approximate age, location, occupation, and treatment date may allow community members to recognize a patient.
Avoid Discussing Individual Cases Without Authorization
Physicians, nurses, therapists, administrators, researchers, and other hospital representatives should avoid discussing identifiable cases during public interviews or events unless all necessary authorizations and approvals have been confirmed.
This protection extends beyond prepared remarks. Identifying information can emerge during audience questions, informal conversations, livestreams, panel discussions, or post-event networking. Participants should be briefed in advance about how to respond.
A speaker can redirect an inappropriate question by saying, “I cannot discuss an individual patient, but I can explain the issue generally.” This protects privacy while preserving the educational value of the conversation.
Hospital employees should also avoid confirming that a particular person is a patient unless such disclosure has been approved or is otherwise permitted. Even well-intentioned comments can reveal confidential information.
Separate General Education From Individual Medical Advice
Public health education should provide general information—not individualized diagnoses or treatment recommendations. A Sanj Talks interview, article, video, or community panel does not provide the clinical examination, medical history, testing, and informed discussion ordinarily needed for personalized care.
An audience member may ask:
- “Do these symptoms mean I have heart disease?”
- “Should I stop taking my medication?”
- “Which treatment should I choose?”
- “Does my child need emergency care?”
- “Can you review my test results?”
Hospital representatives should not diagnose or prescribe through public content. They may explain general considerations, encourage the person to contact an appropriate healthcare professional, or direct the individual to emergency services when necessary.
Speakers should also avoid inviting audience members to disclose sensitive medical information publicly. A general statement such as “Please do not share private health details here” can establish a helpful boundary before questions begin.
Use Appropriate Medical and Emergency Disclaimers
Educational content should include a disclaimer suited to the topic and format. A general medical disclaimer may explain that:
This content is provided for general educational and informational purposes only. It does not constitute medical advice, diagnosis, or treatment and does not create a physician-patient or other healthcare professional-patient relationship. Individuals should consult a qualified healthcare professional regarding their circumstances.
When urgent conditions are discussed, the content should also state clearly:
If you believe you may be experiencing a medical emergency, call 911 or the appropriate emergency service in your location. Do not rely on an article, video, event, social-media post, email, or online conversation for emergency assistance.
A disclaimer does not correct otherwise irresponsible content. The information itself must still be accurate, appropriately limited, and presented by qualified and authorized representatives.
Establishing a Sanj Talks Privacy Approval Process
Any Sanj Talks interview, article, event, photograph, video, testimonial, hospital story, or sponsored campaign involving hospital personnel, facilities, or patient-related information should follow a documented approval process.
Before participation, the hospital and Sanj Talks should identify:
- The topic, purpose, audience, and format
- The authorized hospital representative
- Whether patient information or patient areas could be involved
- Required privacy, legal, compliance, clinical, communications, and brand reviews
- Necessary authorizations, releases, and property permissions
- Prohibited topics or identifying details
- Recording, editing, fact-checking, and publication procedures
- Medical and emergency disclaimers
- Sponsorship and paid-content disclosures
- Procedures for correcting, removing, or updating material when appropriate
Sanj Talks should receive only information the hospital has approved for external use. It should not receive unrestricted medical records or confidential files merely to prepare a story. Whenever possible, hospital teams should provide final approved facts, biographies, photographs, quotations, and resource links through an authorized contact.
Patient privacy is not an obstacle to hospital visibility. It is a necessary foundation for responsible healthcare communication. By protecting individually identifiable health information, obtaining proper authorizations, controlling photography and recording, maintaining educational boundaries, and establishing a careful review process, hospitals can participate in Sanj Talks opportunities while respecting the people they serve.

Leave a Reply