HIPAA Compliance for OB/GYN Practices: Partners, Labs, Ultrasounds, and a Vacated Rule

Practical guidance for healthcare teams and business associates

Wednesday in an OB/GYN practice. A husband at the front desk asks what time his wife's appointment is and whether the results are in. A prenatal genetic screen posts to the portal before the physician has called. A seventeen-year-old asks about contraception and whether her mother will find out. A law firm's subpoena for a former patient's prenatal records sits in the fax tray. Every one of those is a Privacy Rule question, and in 2025 a federal court changed which version of the rule answers them.

The HHS Office for Civil Rights (OCR) enforcement listing shows the sector under scrutiny. OCR settled with Holy Redeemer Family Medicine over the disclosure of a patient's protected health information, including reproductive health information (November 2024). It entered a resolution agreement and corrective action plan with Regional Women's Health Group, LLC (August 2025). Years earlier, careless handling of HIV information cost an entity $387,000 (May 2017). Reproductive and sexual health information is the category where a single mishandled disclosure does the most damage to a patient.

This guide covers why HIPAA applies to an OB/GYN practice, the current status of the 2024 reproductive health privacy rule, what protected health information looks like in women's health, the violations that cluster around partners, minors, and legal requests, how to build the program, and which vendors need a Business Associate Agreement.

HIPAA Compliance for OB/GYN Practices: Partners, Labs, Ultrasounds, and the Rule That Was Vacated

Why HIPAA Applies to an OB/GYN Practice

45 CFR 160.103 defines a covered entity to include "a health care provider who transmits any health information in electronic form in connection with a transaction covered by this subchapter." An OB/GYN practice bills prenatal care, deliveries, procedures, and office visits electronically, so it is a covered entity. The same section defines health information as "any information, including genetic information," which matters in a specialty built on carrier screening and prenatal genetic testing; the definition of genetic information expressly includes "a fetus carried by the individual." The test is walked through in what is a covered entity under HIPAA.

The 2024 Reproductive Health Rule: Vacated, but Still Printed

In April 2024 HHS finalized a rule titled "HIPAA Privacy Rule to Support Reproductive Health Care Privacy." It added a prohibition on using or disclosing P.H.I. (Protected Health Information) to investigate or impose liability on a person for lawful reproductive health care, an attestation requirement for certain requests, and three new Notice of Privacy Practices elements. On June 18, 2025, a federal district court in Texas, in Purl v. HHS, vacated that rule nationwide. As of this writing the eCFR still displays the vacated text at 164.502(a)(5)(iii), 164.509, and 164.520(b)(1)(ii)(F) through (H). A practice reading the regulation online will see provisions that are not enforceable.

What this means in practice: the base Privacy Rule governs reproductive health P.H.I. the same way it governs everything else. Disclosures for judicial proceedings run under 164.512(e), law enforcement disclosures under 164.512(f), and required-by-law disclosures under 164.512(a). The attestation form is not required. The three notice elements are not required. What did survive from the same 2024 rulemaking is the set of notice changes tied to 42 CFR Part 2 substance use disorder records, with a compliance date of February 16, 2026; those apply only to a practice that creates or maintains Part 2 records, which is covered in 42 CFR Part 2 vs HIPAA.

State law is the other half of the answer. Under 45 CFR 160.203(b), a state law that "relates to the privacy of individually identifiable health information and is more stringent" than the federal Privacy Rule is not preempted. Several states have enacted their own reproductive health data protections since 2022. Which ones apply to a given practice is a state-by-state question for counsel, and the practice's subpoena and law enforcement procedures should be written with that answer in hand.

What P.H.I. Looks Like in OB/GYN

  • Prenatal records. Flowsheets, estimated due dates, visit notes, and the delivery summary shared with the hospital.
  • Ultrasound images. Stored in an image archive or reporting system, often with a vendor's cloud component, and printed for the patient to take home.
  • Fetal monitoring data. Non-stress test strips and surveillance records from in-office monitoring systems.
  • Genetic screening results. Carrier screening, cell-free DNA screening, and diagnostic testing results that are genetic information about the patient and the fetus.
  • Sexual health results. Pap and HPV results, sexually transmitted infection testing, and HIV status.
  • Contraception and fertility records. Prescriptions, device placements, and fertility treatment cycles.
  • Portal messages and reminders. A text that says "your prenatal visit is Thursday" discloses the pregnancy to whoever reads the phone.
  • Designated-person forms. The list of people the patient has agreed may receive information, and the ones she has said may not.

Common Violations in OB/GYN Practices

The partner at the front desk. 45 CFR 164.510(b)(1)(i) permits disclosure to "a family member, other relative, or a close personal friend of the individual" of P.H.I. "directly relevant to such person's involvement with the individual's health care," and 164.510(b)(2) conditions it on the patient's agreement, the opportunity to object, or a reasonable inference from the circumstances. A partner present in the exam room supports the inference for what is discussed while he is there. A partner at the front desk asking for results, appointment times, or whether a visit happened gets nothing unless the patient has said so. The workable fix is a designated-person form completed at intake and visible in the chart. The template is in the HIPAA release form.

Voicemails and mail to the wrong address. 164.522(b)(1)(i) requires the practice to "accommodate reasonable requests by individuals to receive communications of protected health information ... by alternative means or at alternative locations," and 164.522(b)(2)(iii) forbids requiring an explanation. In OB/GYN the request often comes from a patient whose pregnancy or test result is not safe to share at home. "Cell phone only, no voicemail, no mail" has to be honored the first time. The front desk mechanics are in HIPAA front desk rules.

Minors and parents. 164.502(g)(3)(i) makes a minor the "individual" for a service she may lawfully obtain without parental consent under state law, and 164.502(g)(3)(ii) defers to state law on whether a parent may be told. Which services qualify (contraception, sexually transmitted infection care, prenatal care) is a state-law question. The practice needs a written policy naming its state's rules, and a portal setup that does not hand a parent's proxy account the record of a confidential visit.

Subpoenas answered like records requests. 164.512(e)(1)(i) permits disclosure in response to "an order of a court or administrative tribunal," limited to what the order authorizes. A subpoena, discovery request, or other lawful process without a court order is different: under 164.512(e)(1)(ii) the practice may respond only after receiving "satisfactory assurance" that the requesting party made reasonable efforts to notify the patient, or to secure a qualified protective order. A subpoena for prenatal records that arrives by fax is not self-executing. It goes to the privacy official and to counsel, and the response is logged.

Newborn photos and testimonials. A birth announcement on the practice's social media discloses P.H.I. of the patient and the newborn. 164.508(a)(3) requires a marketing authorization, signed by the patient for herself and as the newborn's personal representative.

Results that reach the wrong person. A genetic screen posted to a shared family portal login, an HIV result faxed to the wrong number, or a Pap result read aloud to whoever answers the phone: each is an impermissible disclosure to be assessed under the breach definition at 164.402. The $387,000 HIV-information settlement above is the cautionary case.

Building the Program

Risk analysis that includes imaging and monitoring. 164.308(a)(1)(ii)(A) requires "an accurate and thorough assessment of the potential risks and vulnerabilities" to ePHI (electronic P.H.I.). For OB/GYN that includes the ultrasound archive and any cloud reporting component, fetal monitoring systems and their vendor remote access, the portal and its proxy settings, and the reminder texting platform.

Four practice-specific policies. A partner and family communication policy built on the designated-person form; a confidential communications procedure that captures the patient's contact preferences at intake and enforces them; a minors policy keyed to state law and reviewed by counsel; and a legal-request procedure covering court orders, subpoenas, and law enforcement, with the 164.512(e) and (f) conditions written in.

Notice of Privacy Practices, reviewed. 164.520(c)(2) requires the notice at first service delivery with a good-faith effort to obtain acknowledgment. The 2024 rule's added reproductive health elements are not enforceable after the vacatur; the Part 2 element applies only if the practice holds Part 2 records. A notice review with counsel, rather than a rewrite, is the sensible step. The baseline content is in Notice of Privacy Practices: HIPAA NPP requirements.

Training on the phone call. 164.530(b)(1) requires training for all workforce members. The failures in this specialty happen at the front desk and on the phone, so the training uses the actual scripts: the partner, the parent, the lawyer, the reporter. Document it and keep the record for six years under 164.530(j)(2).

Vendor B.A.A. Checklist for OB/GYN

A business associate under 160.103 is a person who, on the practice's behalf, "creates, receives, maintains, or transmits protected health information" for a regulated function. The same definition excludes "a health care provider, with respect to disclosures by a covered entity to the health care provider concerning the treatment of the individual," which covers the labs and the hospital.

Vendor categoryTypical examplesB.A.A. required?
OB/GYN EHR and portalathenahealth, eClinicalWorks, Epic Community ConnectYes
Ultrasound reporting and image archiveAny cloud reporting or PACS vendor holding imagesYes
Fetal monitoring and surveillance systemsAny system with vendor cloud storage or remote accessYes, when the vendor can reach the data
Reminder, recall, and texting platformAny patient messaging serviceYes
Telehealth and AI scribe or transcriptionAny video visit or documentation vendorYes
Billing company, IT managed services, cloud fax, shreddingThe standard back-office vendorsYes
Genetic testing and clinical laboratoriesThe labs receiving specimensNo. The lab is a health care provider receiving P.H.I. for treatment and is a covered entity itself.
Hospital labor and delivery, mammography center, maternal-fetal medicine consultantsProviders the practice coordinates care withNo, for treatment disclosures
Pregnancy and cycle-tracking apps recommended to patientsConsumer apps the patient downloads herselfNo B.A.A.; the app is not acting for the practice. Patients should know the app is outside HIPAA unless the practice contracts for it.
Public health reportingState birth, disease, and cancer registriesNo. Disclosures run under 164.512(b) to a public health authority; document the basis.

The Proposed Security Rule Update (Proposed, Not Final)

Separate from the vacated privacy rule, HHS published a Notice of Proposed Rulemaking on January 6, 2025 that would rewrite the Security Rule: encryption and multifactor authentication required rather than addressable, a written asset inventory and network map, restoration of critical systems within 72 hours, and vulnerability scans "at least once every six months." It is proposed, not final, and OCR is not enforcing it. The status is tracked in HIPAA Security Rule delayed to 2027. For an OB/GYN practice, encrypting the ultrasound archive and turning on multifactor authentication for the portal are worth doing under the current rule, because those are the systems holding the information patients most fear seeing exposed.

---

FAQ

Does the 2024 reproductive health privacy rule still apply?

No. A federal district court vacated the April 2024 rule nationwide on June 18, 2025, in Purl v. HHS. The attestation requirement, the reproductive health disclosure prohibition, and the added notice elements are not enforceable, even though the eCFR still prints them. The base Privacy Rule and any more stringent state law govern reproductive health information.

Can the front desk tell a husband or partner about his wife's appointment or results?

Only if the patient has agreed, has been given the chance to object and did not, or the circumstances reasonably support that she does not object, under 45 CFR 164.510(b). A designated-person form completed at intake is the practical way to know. Absent that, the answer at the desk is no.

Can a minor's OB/GYN visit be kept from her parents?

It depends on state law. Under 164.502(g)(3), where a minor may lawfully consent to a service alone, she is the individual for that information, and state law decides whether a parent may be told. The practice needs a written policy naming its state's minor-consent rules and a portal configuration that respects it.

Does the practice need a BAA with its genetic testing lab?

No. The lab is a health care provider receiving specimens for treatment, and 160.103 excludes treatment disclosures to a provider from the business associate definition. The lab is a covered entity responsible for its own compliance. The practice still limits what it sends to what the lab needs.

What should the practice do with a subpoena for prenatal records?

Route it to the privacy official and counsel. Under 164.512(e), a court order permits disclosure of only what the order authorizes; a subpoena without a court order requires satisfactory assurance that the patient was notified or that a qualified protective order was sought before anything is released. State law may add conditions.

Conclusion

An OB/GYN practice needs a written answer to three questions before the next phone call: who the patient has designated, how the practice responds to a subpoena, and what the current rule actually requires now that the 2024 amendments are gone. One Guy Consulting's Full-Scope plan supplies the risk analysis, the policy set including partner communication and legal-request procedures, staff training, and B.A.A. tracking. Start with a free 30-minute compliance review. No obligation, no pressure.

Sources


Related Reading