Confidentiality laws create legally enforceable duties to keep sensitive information secret, and those duties can come from federal statutes, state law, professional relationships, or private contracts. They bind not only the person who promised secrecy but often their employees, contractors, and business partners. Breaking one gives the injured party grounds to sue for damages, obtain a court order stopping further disclosure, and in serious cases trigger government fines or criminal prosecution.
Where the Duty Comes From
The obligation to keep information secret usually has more than one source at once. Federal and state statutes impose confidentiality requirements on specific industries: healthcare providers handling patient records, banks storing account data, schools holding student files. Courts have added protections through case law, recognizing that certain relationships carry an inherent expectation of secrecy even without a written agreement.
Fiduciary relationships create some of the strongest duties. When one person has a legal duty to act in another’s best interest, such as an attorney advising a client or a financial advisor managing investments, disclosing that person’s private information without permission is a breach of fiduciary duty. Courts will sometimes find an implied duty of confidentiality based on the nature of the relationship, even absent an express agreement.
Confidentiality and privacy are related but different. Confidentiality is the obligation placed on the person who receives information to keep it secret. Privacy is the broader right of an individual to control who sees their personal information in the first place. A hospital’s duty not to share your medical records is a confidentiality obligation. Your right to decide whether that information is collected at all is a privacy right.
Health Information Under HIPAA
The Health Insurance Portability and Accountability Act sets the national standard for protecting personal health information. It applies to covered entities: health plans, healthcare clearinghouses, and any healthcare provider that transmits health information electronically.1HHS.gov. Summary of the HIPAA Privacy Rule Their business associates, meaning contractors and vendors who handle patient data on their behalf, are held to the same requirements.2Department of Health and Human Services. Summary of the HIPAA Security Rule
HIPAA protects all individually identifiable health information, whether stored electronically, on paper, or communicated verbally. Covered entities can share this information without your authorization for a limited set of purposes: coordinating your treatment with other providers, processing payment for services, and carrying out internal healthcare operations like quality improvement and training.3eCFR. 45 CFR 164.506 – Uses and Disclosures to Carry Out Treatment, Payment, or Health Care Operations Disclosures are also permitted or required for public health reporting, law enforcement requests backed by legal process, and court orders.
You have the right to inspect and obtain a copy of your own health records held in a provider’s designated record set, with narrow exceptions for psychotherapy notes and information compiled for legal proceedings.4eCFR. 45 CFR 164.524 – Access of Individuals to Protected Health Information You can also request corrections to information you believe is inaccurate.
Substance use disorder treatment records carry an extra layer of protection under 42 CFR Part 2. These records cannot be used as evidence against a patient in civil, criminal, or administrative proceedings without the patient’s written consent or a specific court order.5HHS.gov. Fact Sheet 42 CFR Part 2 Final Rule Patients can also file complaints directly with the Secretary of Health and Human Services for alleged violations.
Breach Notification
When a covered entity discovers that unsecured health information has been exposed, HIPAA’s Breach Notification Rule requires notification to affected individuals within 60 calendar days.6eCFR. 45 CFR Part 164 Subpart D – Notification in the Case of Breach of Unsecured Protected Health Information Breaches affecting 500 or more people must also be reported to HHS at the same time. Smaller breaches can be logged and reported annually but still require individual notification within 60 days.
Penalties
Civil penalties for HIPAA violations are organized into four tiers based on the violator’s level of fault. As of January 2026, the minimum fine starts at $145 per violation for unknowing violations and climbs to $73,011 per violation for willful neglect that goes uncorrected. The annual cap across all tiers is $2,190,294. The Office for Civil Rights within HHS handles enforcement.1HHS.gov. Summary of the HIPAA Privacy Rule
Criminal penalties apply separately. Knowingly obtaining or disclosing someone’s health information in violation of HIPAA can bring a fine of up to $50,000 and a year in prison. If the violation involves false pretenses, the penalty increases to $100,000 and five years. Violations committed with intent to sell or use the information for personal gain carry fines up to $250,000 and up to ten years in prison.
Professional Privileges That Protect Communications
Testimonial privileges are evidentiary rules giving people in certain relationships a legal right to refuse to disclose confidential communications in court. They exist because the law recognizes that some relationships only work when people can speak freely without fear that their words will end up in a legal proceeding.
Attorney-Client Privilege
The attorney-client privilege protects private conversations between a client and their attorney when made for the purpose of getting legal advice. The privilege belongs to the client, who can waive it, and it survives the end of the attorney-client relationship.
The most significant limitation is the crime-fraud exception. If a client consults an attorney specifically to get help committing or covering up a crime or fraud, the privilege does not apply. It does not require proof that a crime was actually committed; it applies when the client’s purpose in seeking advice was to further wrongdoing. Once a judge finds sufficient evidence that the consultation served a criminal or fraudulent purpose, the communications lose their protection entirely.
Psychotherapist-Patient Privilege
The U.S. Supreme Court recognized the psychotherapist-patient privilege in 1996, holding that confidential communications made during psychotherapy are protected from forced disclosure in federal court.7Justia US Supreme Court. Jaffee v Redmond, 518 US 1 (1996) The Court extended the privilege to licensed social workers performing psychotherapy as well. The privilege belongs to the patient, and only the patient can waive it. It has significant exceptions, discussed below, when a patient poses a danger to themselves or others.
Spousal Privilege
Spousal privilege covers two separate protections. The testimonial privilege, sometimes called spousal immunity, applies only in criminal cases and allows a witness spouse to refuse to testify against the defendant spouse. In most federal courts and a majority of states, the witness spouse holds this privilege and can choose to testify even if the defendant objects. It expires when the marriage ends.
The confidential marital communications privilege is broader in some ways and narrower in others. It protects private statements made between spouses during a valid marriage and applies in both civil and criminal cases. It can survive divorce or the death of a spouse since it protects communications made while the marriage existed. In most states, either spouse can assert it to prevent the other from disclosing their private conversations.
Clergy-Penitent Privilege
All 50 states and the federal government recognize some form of the clergy-penitent privilege, but the scope varies. About half the states protect any confidential communication made to a member of the clergy acting in their professional capacity, a definition broad enough to include general pastoral counseling. Roughly a quarter restrict the privilege to communications made in the context of formal religious confession or discipline required by the person’s faith tradition. The remaining states fall between these poles, covering confidential communications necessary for the clergy member to carry out their religious duties.
When the Law Requires Disclosure
Every privilege and confidentiality rule has exceptions, and some of the most important ones require disclosure rather than merely permitting it. Professionals who assume their duty of secrecy is absolute are wrong.
Child Abuse Reporting
Every state has a mandatory reporting law requiring certain professionals to report suspected child abuse or neglect. Healthcare providers, teachers, social workers, and law enforcement officers are mandatory reporters everywhere. Many states extend the obligation to clergy, coaches, and other adults who work with children. These requirements override professional confidentiality, including the therapist-patient relationship. A therapist who learns during a session that a child is being abused cannot invoke privilege to stay silent, and failure to report is itself a criminal offense in most states.
Duty to Warn
Since a 1976 California court decision, almost every state has adopted some version of a duty requiring mental health professionals to act when a patient poses a credible threat of serious violence to an identifiable person. Some states require the therapist to warn the intended victim directly, others require notification of law enforcement, and some allow the therapist to choose among several protective actions including involuntary commitment. When confidentiality conflicts with preventing serious physical harm, the duty to protect wins.
Public Health and Legal Process
HIPAA itself contains mandatory disclosure exceptions for certain public health threats, including reporting communicable diseases to public health authorities and disclosing information in response to a valid court order or subpoena. These exceptions are built into the statute, so complying with them is not a breach. Similar carve-outs exist in most state confidentiality statutes.
Business Confidentiality and Trade Secrets
In business, confidentiality obligations usually begin with a contract. A non-disclosure agreement creates a binding duty for the person receiving information to keep it secret. Unilateral NDAs, where only one side is sharing sensitive information, are common in employment and contractor relationships. Mutual NDAs, where both sides anticipate exchanging proprietary data, are standard in business negotiations and joint ventures.
Trade secrets get independent legal protection beyond whatever a contract says. The Uniform Trade Secrets Act has been adopted in 48 states, the District of Columbia, and several U.S. territories. To qualify as a trade secret, information must have economic value specifically because it is not publicly known, and the owner must have taken reasonable steps to keep it secret. Those steps typically include limiting who has access, marking sensitive documents appropriately, and requiring anyone who sees the information to sign a confidentiality agreement.
At the federal level, the Defend Trade Secrets Act created a civil cause of action in federal court for trade secret theft involving products or services used in interstate commerce.8Office of the Law Revision Counsel. 18 USC 1836 – Civil Proceedings The statute of limitations is three years from the date the theft was discovered or should have been discovered. Having both state and federal options gives trade secret owners a choice of forum and, in cases involving defendants in multiple states, a way to consolidate claims in a single federal proceeding.
Whistleblower Immunity
NDAs and trade secret protections cannot be used to punish someone for reporting a suspected crime. Federal law provides explicit immunity: a person who discloses a trade secret to a government official or an attorney solely to report a suspected legal violation cannot be held liable under any federal or state trade secret law.9Office of the Law Revision Counsel. 18 USC 1833 – Exceptions to Prohibitions The same immunity covers trade secret information included in a sealed court filing as part of a lawsuit.
Employers who use confidentiality agreements covering trade secrets or proprietary information must include a notice of this whistleblower immunity in those agreements. An employer who fails to provide the notice cannot recover enhanced damages or attorney’s fees if it later sues that employee for trade secret theft.
Limits on NDAs in Harassment Settlements
Not all confidentiality agreements are enforceable. Recent years have brought significant restrictions on using NDAs to silence victims of workplace harassment.
Since 2017, federal tax law has denied any business deduction for settlement payments related to sexual harassment or sexual abuse when those payments are tied to a nondisclosure agreement.10Office of the Law Revision Counsel. 26 USC 162 – Trade or Business Expenses The deduction ban extends to the attorney’s fees the business pays in connection with the settlement.11Internal Revenue Service. Certain Payments Related to Sexual Harassment and Sexual Abuse The person receiving the settlement, however, can still deduct their own legal fees if otherwise eligible. Adding a secrecy clause significantly raises the after-tax cost to the employer.
A growing number of states have gone further. California prohibits confidentiality clauses that prevent disclosure of factual information in sexual harassment, assault, or discrimination claims, though the settlement amount itself can remain confidential. Colorado’s 2023 POWR Act voids NDAs that limit an employee’s ability to disclose discriminatory practices unless the agreement applies equally to both parties and explicitly preserves the employee’s right to report to government agencies. New Jersey, Nevada, Maine, and several other states have enacted similar restrictions with varying scope. Where these laws apply, a confidentiality clause that violates them is unenforceable regardless of what the agreement says.
Financial Data and Breach Notification
The Gramm-Leach-Bliley Act requires financial institutions, including banks, lenders, investment advisors, and insurance companies, to protect the security and confidentiality of their customers’ personal financial information.12Federal Trade Commission. Gramm-Leach-Bliley Act The law covers data like account numbers, transaction histories, income information, and credit reports.
Financial institutions must tell customers how they collect, share, and protect personal information. Before sharing customer data with nonaffiliated companies, the institution must give customers a clear way to opt out. The Safeguards Rule goes further, requiring each covered institution to develop and maintain a written information security program with administrative, technical, and physical protections for customer data. The FTC enforces these requirements.
Outside healthcare and finance, there is no single comprehensive federal data breach notification law. All 50 states have enacted breach notification statutes, but the details differ. About 20 states set specific numeric deadlines ranging from 30 to 60 days after discovery. The remaining states use qualitative language requiring notification “without unreasonable delay.” A majority of states also require reporting breaches to the state attorney general or another designated agency.
What counts as a covered breach varies too. Nearly half the states now explicitly cover biometric data and medical information. A smaller number cover breaches of paper records in addition to electronic data. About half provide a private right of action, meaning affected consumers can sue the breaching entity directly rather than waiting for a regulator to act. A business that holds personal data from customers in multiple states is generally bound by the strictest applicable law.
What Happens When Someone Breaches Confidentiality
When someone breaches a confidentiality obligation, the injured party can pursue several types of relief depending on the source of the duty and the nature of the harm.
Civil Damages
The most straightforward remedy is monetary compensation for provable financial losses: lost profits from a leaked trade secret, the cost of notifying affected customers after a data breach, expenses for damage control and credit monitoring. If the duty came from a contract like an NDA, the agreement may specify a predetermined amount of liquidated damages, which saves the injured party from having to prove the exact dollar value of the harm. In cases involving malicious or deliberate breaches, courts can also award punitive damages intended to punish the wrongdoer rather than just compensate the victim.
Court Orders Stopping Further Disclosure
Money often cannot fix a confidentiality breach after the fact, which is why injunctive relief is frequently the most important remedy. A court order can prohibit the breaching party from any further use or disclosure of the confidential information. Getting one typically requires showing that the harm is irreparable, meaning money alone cannot adequately compensate for the ongoing damage, and that you are likely to win the underlying case. Courts can issue temporary restraining orders on an emergency basis when the risk of continued disclosure is imminent.
Regulatory Enforcement
Breaches involving regulated data trigger enforcement by the responsible federal agency. HHS enforces HIPAA violations with civil penalties that can exceed $2 million per year per violation category. The FTC enforces consumer data protections, including the Gramm-Leach-Bliley Act’s Safeguards Rule and the Health Breach Notification Rule, which applies to health data held by entities not covered by HIPAA. Violations of the Health Breach Notification Rule can result in penalties of up to $51,744 per violation.13Federal Trade Commission. Health Breach Notification Rule – The Basics for Business State attorneys general bring enforcement actions under their own breach notification and consumer protection statutes as well.
Criminal Liability
The most severe breaches carry criminal penalties. Willful HIPAA violations can result in prison sentences ranging from one year for a knowing violation up to ten years when the breach was committed to sell or misuse the information for personal gain. Trade secret theft is a federal crime under the Economic Espionage Act. In regulated industries like banking and healthcare, individuals who knowingly participate in unauthorized disclosures can face personal criminal liability separate from any penalties imposed on their employer.
Deadlines for Acting
Statutes of limitations for filing civil breach-of-confidentiality claims vary by jurisdiction and legal theory. Breach of contract claims typically must be filed within four to six years in most states. Federal trade secret claims under the Defend Trade Secrets Act carry a three-year limitations period running from when the theft was or should have been discovered.8Office of the Law Revision Counsel. 18 USC 1836 – Civil Proceedings Waiting too long after learning of a breach can forfeit your right to a remedy entirely.