Qualified Protective Order (HIPAA)

Qualified Protective Order (HIPAA)

Qualified Protective Order (HIPAA)

A qualified protective order under the Privacy Rule must prohibit use of the protected health information for any purpose other than the litigation and require return or destruction at the conclusion of the proceeding.

It provides an alternative to patient authorization when responding to a subpoena or discovery request.

Alternative Names:

QPO, HIPAA Protective Order

Why it Matters?

This is the route to records when a plaintiff will not sign an authorization or when third-party medical records are needed, such as those of a comparator or a non-party witness. Providers frequently do not recognize the mechanism and reject subpoenas anyway, so including the order with the subpoena and citing the specific regulatory provision reduces friction. The two required terms are mandatory, and orders omitting either do not qualify.

Frequently Confused with

Related terms

Frequently asked questions

What must a qualified protective order contain?

What must a qualified protective order contain?

A prohibition on using the information outside the litigation and a requirement that it be returned or destroyed when the proceeding concludes.

When is it used instead of an authorization?

When is it used instead of an authorization?

When the patient will not authorize disclosure, or when records of a non-party are sought and no authorization is available.