In Episode 33 of False Claims Act Insights, Claire Postman and I tackle a critical challenge for healthcare providers: balancing HIPAA compliance with civil investigative demands (CIDs) in False Claims Act investigations. Claire explains HIPAA’s general prohibition on disclosing protected health information and the key exceptions that permit disclosure when required by law, such as in response to court orders, subpoenas, or CIDs. She emphasizes that disclosures must align with the scope of the request and sometimes require de-identification. The discussion also explores HIPAA’s provisions for health oversight agencies and highlights the importance of carefully reviewing CID language to ensure compliance. We conclude by underscoring the value of proactive communication between counsel and investigators to clarify expectations and maintain consistency with both HIPAA and legal obligations.