The Department of Health and Human Services has published FAQs about this very topic. It states: "The definition of 'health care operations' in the Privacy Rule provides for 'conducting training programs in which students, trainees, or practitioners in areas of health care learn under supervision to practice or improve their skills as health care providers.' Covered entities can shape their policies and procedures for minimum necessary uses and disclosures to permit medical trainees access to patients' medical information, including entire medical records."