South Carolina Pulmonary Function Lab Privacy Laws: Sharing Spirometry Curves with Referring Clinics

Product Pricing
Ready to get started? Book a demo with our team
Talk to an expert

South Carolina Pulmonary Function Lab Privacy Laws: Sharing Spirometry Curves with Referring Clinics

Kevin Henry

HIPAA

August 10, 2026

7 minutes read
Share this article
South Carolina Pulmonary Function Lab Privacy Laws: Sharing Spirometry Curves with Referring Clinics

Overview of HIPAA Treatment Exceptions

What “treatment” covers for spirometry

Under the Health Insurance Portability and Accountability Act, you may disclose Protected Health Information for “treatment” without patient authorization. For pulmonary function labs, that includes sending spirometry curves, flow–volume loops, technician notes, and interpretations to the patient’s referring or treating clinicians for diagnosis, consultation, or care coordination.

HIPAA’s Privacy Rule permits PHI Treatment Exceptions for exchanges between covered entities engaged in a patient’s care. No separate HIPAA authorization is required to share spirometry results with a referring clinic. Your local consent forms and referral agreements can still clarify expectations, but HIPAA does not mandate patient authorization for these treatment disclosures.

The “minimum necessary” nuance

The minimum necessary standard does not apply to treatment disclosures. Even so, right-size each disclosure to what the clinician needs to manage the case, such as pre/post-bronchodilator curves, quality grades, and key indices (FEV1, FVC, FEV1/FVC), while avoiding unrelated records that add risk without clinical value.

Business associates and intermediaries

Referring clinics are typically covered entities, so a Business Associate Agreement with them is not required. However, if you use cloud portals, archival vendors, analytics tools, or third-party interpretation services to transmit or store spirometry data, you must have Business Associate Agreements and enforce appropriate confidentiality provisions and security controls.

South Carolina Prescription Information Privacy Act

Scope and applicability

The South Carolina Prescription Information Privacy Act primarily governs the confidentiality and use of prescription information. It restricts the commercial use and disclosure of prescription data while permitting sharing for treatment, payment, and healthcare operations. Spirometry curves are not prescription information, but the Act may apply when test results are transmitted along with medication histories.

Interaction with spirometry data

When you send pulmonary function reports that include medication lists, bronchodilator details, or prescribing information, apply the Act’s confidentiality provisions to that prescription data. Align your workflows so that both HIPAA and the South Carolina Prescription Information Privacy Act are respected within a single, secure transmission.

Redisclosure expectations

Make clear in cover notes that the receiving provider must protect any included prescription information under state law and general HIPAA rules. While HIPAA allows providers to use received PHI for treatment, reminding recipients about redisclosure limits supports Legal Compliance in Healthcare and reduces downstream risk.

Confidentiality Requirements for Healthcare Data

Privacy Rule essentials

Define who may access spirometry records, how you verify identity, and when you disclose data for treatment, payment, or operations. Maintain clear role-based permissions so only authorized staff generate, review, or transmit spirometry curves and associated demographic details.

Security Rule safeguards

Implement administrative, physical, and technical protections for Patient Data Security. Conduct a risk analysis, encrypt data in transit and at rest, enforce unique user IDs and multifactor authentication, log access to PFT files, and manage device/media disposal. Regularly patch systems and validate vendor security as part of your due diligence.

Patient rights and special categories

Patients can access their results and request amendments or restrictions consistent with HIPAA. If your data set contains specially protected information (for example, substance use disorder records under separate federal rules), apply those stricter controls. For research or quality improvement, use de-identification or obtain appropriate permissions before broader sharing.

Compliance Strategies for Pulmonary Labs

Build a practical policy playbook

Create concise SOPs that map when and how you share spirometry curves with referring clinics. Include standardized disclosure rationales, documentation checkpoints, and escalation steps for edge cases, ensuring your team follows consistent Confidentiality Provisions every time.

Verify recipients and scope

Confirm the recipient’s identity, role, and treatment relationship before sending PHI. Match the data set to the clinical question—full loop images and quality statements for complex cases, targeted values for routine follow-up—so information is useful without excess exposure.

Harden technical exchange channels

Prefer secure EHR-to-EHR connections or health information exchange pathways, with encryption and mutual authentication. For files, use secure messaging or SFTP rather than unsecured email. Avoid PHI in file names, and embed only necessary identifiers within PDFs or HL7/FHIR payloads.

Train, test, and audit

Educate staff on PHI Treatment Exceptions, phishing awareness, and proper release workflows. Run periodic drills for misdirected disclosures, review audit logs, and document corrective actions. Continuous testing proves your program works beyond the policy binder.

Ready to simplify HIPAA compliance?

Join thousands of organizations that trust Accountable to manage their compliance needs.

Federal exposure

HIPAA violations can trigger civil monetary penalties, corrective action plans, and prolonged oversight. Breach Notification Rule duties apply if unsecured PHI is compromised, requiring timely notice to affected individuals and federal authorities, with additional media notice for large incidents.

State-level risks

South Carolina may impose penalties for mishandling prescription data under the Prescription Information Privacy Act and can pursue unfair or deceptive practices theories for improper disclosures. Professional licensing boards may also discipline providers for confidentiality lapses.

Contractual and reputational harm

Breaches strain payer contracts, accreditation status, and referral relationships. Beyond fines, the costliest outcomes often include remediation, downtime, and erosion of patient trust—each preventable with disciplined privacy-by-design practices.

Best Practices for Data Sharing

Right-size what you send

Package the clinically relevant set: raw and interpreted spirometry curves, quality grades, and key indices, plus technician comments where needed. Exclude extraneous documents and limit demographic overlays on images to essential identifiers.

Standardize and label

Use consistent units and reference ranges, and clearly mark pre/post-bronchodilator segments. Add a concise interpretation and a confidentiality footer reminding recipients to safeguard the contents and avoid unauthorized redisclosure.

Secure the handoff

Transmit via encrypted, authenticated channels and confirm receipt by the intended clinic. Keep an internal record of what was sent, who requested it, the legal basis (treatment), and the date/time to support later auditing.

Patient Privacy Safeguards

Embed privacy in workflow

Design your PFT workflow so privacy is the default: identity verification at intake, technician prompts to avoid stray PHI in comments, and automated checks that ensure only intended recipients can retrieve shared curves.

Respect patient preferences

Honor reasonable restrictions and confidential communication requests under HIPAA where applicable. If a patient pays out of pocket and requests nondisclosure to a health plan for that service, ensure financial workflows can segment those records appropriately.

Plan for incidents

Maintain an incident response plan covering containment, investigation, risk assessment, notifications, and remediation. Tabletop exercises help your team act quickly if a misdirected fax, portal misconfiguration, or lost device exposes PHI.

Conclusion

Sharing spirometry curves with referring clinics is permissible under HIPAA’s treatment pathway and, in South Carolina, generally unaffected by the Prescription Information Privacy Act unless prescription data is included. Build security into every step, document your rationale, and align people, process, and technology to achieve compliant, patient-centered data exchange.

FAQs

What federal laws govern sharing spirometry data in South Carolina?

The HIPAA Privacy, Security, and Breach Notification Rules govern how you use, disclose, and safeguard Protected Health Information. Under HIPAA’s treatment exception, covered entities may share spirometry results with other treating providers without patient authorization, provided appropriate safeguards are in place.

How does the South Carolina Prescription Information Privacy Act affect spirometry data sharing?

The Act focuses on prescription information. Spirometry curves themselves are not prescription data, but if your report includes medication lists or prescribing details, you must protect that prescription information under the Act while also meeting HIPAA’s requirements.

Yes. You may disclose spirometry curves and related PHI to the patient’s treating providers without separate HIPAA authorization because the disclosure is for treatment. Use secure channels, verify recipients, and tailor the data set to the clinical need.

What are the consequences of violating patient confidentiality laws in South Carolina?

Consequences can include federal civil penalties and corrective action plans under HIPAA, state enforcement related to prescription data, professional discipline, contract losses, and reputational damage. Breach notification duties may also apply, adding operational and financial impact.

Share this article

Ready to simplify HIPAA compliance?

Join thousands of organizations that trust Accountable to manage their compliance needs.

Related Articles