(2) The rules adopted under subsection (1) of this section shall include but are not limited to:
(a) Permitted uses and disclosures of:
(A) Personal financial information for business, professional or insurance purposes; and
(B) Protected health information for treatment, payment and health care operations.
(b) Requirements for notice of privacy practices for protected health information and notice of information practices for personal financial information. [2003 c.87 §4]