By Fisher, JD, CHC, CCEP
Background
In regulations released in January 2018, SAMHSA identified 17 specific types of payment and health care operations that could support further disclosures by a lawful holder of patient-identifying information.
Clarification
SAMHSA did not include the full list of 17 items in the regulatory text itself. Instead, the items appeared in the preamble, indicating that additional disclosures for payment and health care operations may be permissible.
Examples of Permissible Activities
Examples of activities under § 2.33(b) that SAMHSA considers payment and health care operations activities include:
- Billing, claims management, collections, or related health care data processing.
- Clinical professional support services, such as quality assessment, utilization review, and care coordination.
- Patient safety activities.
- Population-based activities related to improving health or reducing health care costs.
- Protocol development, case management, and care coordination.
- Contacting health care providers and patients with information about treatment alternatives.
- Training programs for students, trainees, health care professionals, or non-health care professionals.
- Accreditation, certification, licensing, or credentialing activities.
- Underwriting, enrollment, premium rating, and other activities related to creating, renewing, or replacing health insurance or health benefits contracts.
- Third-party liability coverage determinations and related activities.
- Reviewing health care competence or qualifications of health care professionals.
- Conducting or arranging for medical review, legal services, or auditing functions.
- Business planning and development, including cost-management and planning analyses.
- Business management and general administrative activities.
- Customer service and resolution of internal grievances.
- Sale, transfer, merger, consolidation, or dissolution of an organization.
- Determining eligibility or coverage for benefits and adjudicating claims.
Importance of the Permissible Activities
These permissible activities are important because they clarify when patient-identifying information may be used or further disclosed for payment and health care operations after the patient has provided valid written consent. This helps lawful holders understand how they may support core health care functions—such as billing, quality review, care coordination, auditing, credentialing, and administrative operations—without treating every operational use as a separate or unrelated disclosure.
The list also promotes consistency and compliance. By identifying examples of payment and health care operations activities, SAMHSA gives providers, payers, contractors, and other lawful holders a clearer framework for determining whether a disclosure fits within the scope of the patient’s consent and applicable confidentiality rules.
At the same time, these activities remain tied to patient protection. The permissions do not create unlimited access to substance use disorder records; rather, they help balance the need for effective health care administration with the privacy safeguards that are central to 42 CFR Part 2.
