A provider is permitted, but not required, to use and disclose protected health information, without an individual’s authorization, for the following purposes or situations:  

(1) To the individual (unless required for access or accounting of disclosures)

(2) Treatment, payment, and healthcare operations 

(3) Opportunity to agree or object 

(4) Incident to an otherwise permitted use and disclosure 

(5) Public interest and benefit activities 

(6) Limited data set for research, public health, or healthcare operations

 Providers may rely on professional ethics and best judgments in deciding which of these permissive uses and disclosures to make:

 (1) A provider may disclose protected health information to the individual who is the subject of the information. 

(2) Treatment, payment, and healthcare operations