Blog|Articles|August 27, 2026

Selling patient data without authorization can be a HIPAA crime

Fact checked by: Keith A. Reynolds

HIPAA treats paid third-party access to patient records as marketing. Without a separate signed authorization, it can carry criminal penalties.

Most people would agree that there is an expectation of privacy when a patient walks into an exam room that extends beyond the clinical encounter to maintaining confidentiality, integrity and availability of an individual’s medical record. This concept pre-dates the Health Insurance Portability and Accountability Act of 1996 (HIPAA). In fact, the United States Supreme Court in UNION PAC. RY. CO. v. BOTSFORD, 141 U.S. 250 (May 25, 1891) held that “[n]o right is more sacred, or is more carefully guarded, by the common law, than the right of every individual to the possession and control of his own person.”

What do privacy and confidentiality mean in the context of HIPAA? First, the Privacy Rule is something that most people are aware of because upon entering a provider’s care, we are required to read the Notice of Privacy Practices (NPPs). There are nuances under 42 CFR Part 2 for substance use disorder treatment, which now more closely align with HIPAA and, since February 16, 2026, must be included in the NPP.

Patients or their legal surrogate decision maker, also execute the requisite HIPAA Authorization Form. An important nuance – under the Privacy Rule, “consent” is different than “authorization.” As the U.S. Department of Health and Human Services (HHS) explains, “[t]he Privacy Rule permits, but does not require, a covered entity voluntarily to obtain patient consent for uses and disclosures of protected health information for treatment, payment, and health care operations.”

By way of contrast, “authorization” connotes the “require[ment] by the Privacy Rule for uses and disclosures of protected health information not otherwise allowed by the Rule. Where the Privacy Rule requires patient authorization, voluntary consent is not sufficient to permit a use or disclosure of protected health information unless it also satisfies the requirements of a valid authorization. An authorization is a detailed document that gives covered entities permission to use protected health information for specified purposes, which are generally other than treatment, payment, or health care operations, or to disclose protected health information to a third party specified by the individual.”

This brings us to a scenario that is not uncommon – the physician or other provider has a remunerative arrangement with a third party (e.g., pharmaceutical company clinical trial or consulting arrangement with a medical device company) where the third party wants access to the electronic medical records and patient schedule to determine what patient may be a candidate for a clinical trial or procedure involving a medical device. Unfortunately, this conduct treads into illegal marketing and sale of the patient’s protected health information.

Marketing” which appears in NPPs and is set forth in 45 CFR §§164.501, 508(a)(3), means "any communication that meets the definition of marketing is not permitted, unless the covered entity obtains an individual’s authorization. To determine what constitutes an acceptable “authorization,” see 45 CFR 164.508. If the marketing involves direct or indirect remuneration to the covered entity from a third party, the authorization must state that such remuneration is involved. See 45 CFR 164.508(a)(3)." Stated another way, the patient must authorize the provider to give access to the medical record and the remuneration must be clearly stated, in bold on a separate HIPAA Authorization Form, with the ability of the patient to opt out or revoke the authorization at any time.

This type of conduct, if appropriate patient authorization is not obtained, can also result in criminal HIPAA violations. As the November 10, 2022, U.S. Department of Justice (DOJ) Press Release states, “[a] federal grand jury has indicted five former Methodist Hospital Employees for conspiring with Roderick Harvey, 40, to unlawfully disclose patient information in violation of [HIPAA].” The DOJ emphasized that “HIPAA’s provisions make it a crime to disclose patient information, or to obtain patient information with the intent to sell, transfer or use such information for personal gain.” Other key features of the indictment:

  • Between November 2017 and December 2020, Harvey paid Kirby Dandridge, 38, Sylvia Taylor, 43, Kara Thompson, 30, Melanie Russell, 41, and Adrianna Taber, 26, to provide him with names and phone numbers of Methodist patients who had been involved in motor vehicle accidents. After obtaining the information, Harvey sold the information to third persons including personal injury attorneys and chiropractors.
  • The conspiracy charge carries a maximum penalty of five years imprisonment, a fine of $250,000 and three-year period of supervised release.
  • Harvey was also charged with seven counts of obtaining patient information with the intent to sell it for financial gain on various dates between November 12, 2017, and September 7, 2019. Each of those charges carries a maximum penalty of 10 years’ imprisonment, a fine of $250,000 and three years’ of supervised release.
  • Dandridge, Taylor, Thompson, Russell, and Taber were each charged with separate violations of disclosing the information to Harvey in violation of HIPAA. That charge carries a maximum penalty of one year imprisonment, a $50,000 fine and a one-year period of supervised release.

In sum, the sales and marketing of PHI without the requisite patient authorization is both violative of the fundamental trust that should exist between a provider and a patient and can also lead to criminal liability. Making sure that appropriate safeguards are in place and that patients are fully informed before signing a separate Authorization Form are two steps to mitigate risk.