Under the Health Insurance Portability and Accountability Act of 1996 (HIPAA) and the Privacy Regulations written pursuant to the Act, the general rule is that covered entities may not use or disclose an individual's protected health information for purposes unrelated to treatment, payment, healthcare operations, or certain defined exceptions without first obtaining the individual's prior written authorization.