HIPAA Privacy Rule Explained: Patient Rights & Provider Obligations
Quick Answer
The HIPAA Privacy Rule gives patients rights to access their health records, request amendments, receive an accounting of disclosures, and request restrictions on how their information is used. Healthcare providers must provide a Notice of Privacy Practices, limit use and disclosure of PHI to treatment/payment/operations or purposes authorized by the patient, and implement safeguards protecting patient privacy. Violations can result in penalties of $100-$1,500,000 per violation.
Overview of the HIPAA Privacy Rule
The HIPAA Privacy Rule (45 CFR Parts 160 and 164, Subpart E) is the regulation that sets federal standards for the use and disclosure of protected health information (PHI) by covered entities and their business associates. Unlike the Security Rule which specifically addresses electronic PHI, the Privacy Rule applies to PHI in any form—electronic, paper, or oral.
The Privacy Rule is built on a core principle: PHI is patient property, and healthcare organizations are stewards responsible for protecting it. The rule grants patients significant rights over their information and limits when and how organizations can use or disclose PHI without patient authorization.
The rule applies to all covered entities (healthcare providers, health plans, healthcare clearinghouses) and their business associates. It's enforced by the Office for Civil Rights within the Department of Health and Human Services.
Patient Rights Under the Privacy Rule
The Privacy Rule grants patients several fundamental rights regarding their health information:
Right to Access
Patients have the right to access and receive a copy of their entire medical record, including clinical notes, test results, imaging reports, and other documentation. Your organization must provide access within 30 days of request (or 60 days if records are off-site). You can charge reasonable copying fees but cannot deny access because you believe the information might be harmful or embarrassing to the patient. The only exceptions are: psychotherapy notes (created by mental health professionals for personal use), information compiled for legal proceedings, and information prohibited from disclosure by other federal laws.
Right to Amendment
Patients can request amendments or corrections to inaccurate information in their medical records. If you agree the record is inaccurate, you must make the amendment. If you deny the request, the patient can submit a statement of disagreement that must be included with the record. You should respond to amendment requests within 60 days. Common amendments include correcting misspelled names, dates of birth errors, or removing diagnoses the patient disputes.
Right to an Accounting of Disclosures
Patients have the right to receive an accounting of all non-routine disclosures of their PHI. This accounting must include: who received the information, when they received it, what information was disclosed, and the purpose of the disclosure. You must provide this accounting within 30 days of request. Disclosures for treatment, payment, healthcare operations, patient authorization, and legal requirements don't need to be tracked, but all other disclosures do.
Right to Request Restrictions
Patients can request restrictions on how you use or disclose their PHI. For example, a patient might request that you not disclose their mental health information to their insurance company, or that certain information not be shared with family members. You're not legally required to agree to all requests, but if you do agree, you must honor the restriction. If you later change your mind, you must notify the patient.
Right to Request Confidential Communications
Patients can request that you communicate with them about their health in a specific way (e.g., calling their work number instead of home, sending mail to an alternative address) or at a specific location. You must accommodate reasonable requests. This is especially important for patients in sensitive situations—domestic violence victims, patients with substance abuse issues, or others who need privacy.
Right to Breach Notification
If unsecured PHI is breached, patients have the right to be notified within 60 days of discovery. The notification must explain what happened, what information was compromised, steps they should take, and what steps your organization is taking to investigate and prevent recurrence.
Permitted Uses and Disclosures of PHI
The Privacy Rule permits certain uses and disclosures of PHI without patient authorization:
Treatment
You can use and disclose PHI as necessary to provide healthcare to the patient. This includes sharing information with other healthcare providers involved in treatment, such as consulting specialists, nursing facilities, or pharmacies.
Payment
You can use and disclose PHI to obtain payment for healthcare services. This includes sharing information with insurance companies for claims processing, benefits eligibility determination, and payment collection.
Healthcare Operations
You can use and disclose PHI for business operations such as quality assurance, utilization review, peer review, training, accreditation, and other administrative purposes necessary to run your healthcare business.
Required by Law
When federal, state, or local law requires disclosure (such as mandatory reporting of child abuse, communicable disease reporting, or legal proceedings), you can disclose PHI without authorization.
Public Health
You can disclose PHI to public health authorities for disease surveillance, outbreak investigations, and other public health activities required or authorized by law.
Law Enforcement
You can disclose PHI to law enforcement when required by law, such as reporting child abuse or responding to a subpoena. You should not disclose PHI based on a request from law enforcement unless there's legal authority requiring it.
Business Operations with Authorization
For uses beyond treatment, payment, and healthcare operations—such as marketing, fundraising, or research—you must obtain patient authorization before using or disclosing PHI.
Notice of Privacy Practices (NPP) Requirements
All covered entities must develop and provide patients with a Notice of Privacy Practices (NPP) that explains how the organization uses and discloses PHI. The NPP is a critical compliance document and a main touchpoint for patients to understand their rights.
Your NPP must explain:
- How you use and disclose PHI (treatment, payment, operations, etc.)
- Patient rights (access, amendment, accounting, restrictions, confidential communications)
- Your legal obligations regarding patient privacy
- How patients can file complaints about privacy violations
- Who to contact with questions about privacy
- Your privacy practices and safeguards
- How you handle breaches of unsecured PHI
You must provide the NPP to patients at their first appointment (or electronically if available), maintain a copy accessible to patients, and update it whenever there are material changes to your practices. Changes to the NPP should be documented with the effective date.
Marketing Restrictions Under the Privacy Rule
HIPAA severely restricts how healthcare providers can use PHI for marketing purposes:
- Patient authorization required: For most marketing communications, you must obtain specific written authorization from the patient before using their PHI to market healthcare services or products to them.
- Treatment-related exceptions: You can communicate about healthcare services without authorization if you're communicating directly with the patient about treatment options, health status, or other care-related information.
- Fundraising restrictions: You cannot use medical information to target fundraising campaigns to specific patients based on their diagnoses or conditions without authorization.
- No selling of contact information: You cannot sell patients' contact information to marketers without authorization.
- Opt-out option: Even for non-marketing communications, patients have the right to opt out of receiving communications from you.
Common Privacy Rule Violations
The Office for Civil Rights identifies these violations frequently during audits:
- No Notice of Privacy Practices: Failure to provide NPP to patients or maintaining an outdated version that doesn't reflect current practices.
- Improper disclosures: Sharing PHI with entities that shouldn't have access without patient authorization or legal basis.
- Failure to honor patient rights: Denying access to medical records, refusing amendment requests, or failing to provide accounting of disclosures.
- Marketing violations: Using PHI for marketing without obtaining required authorization from patients.
- No breach notification: Failing to notify patients when breaches occur or notifying them after the 60-day deadline.
- Inadequate safeguards: Not implementing physical, administrative, or technical safeguards protecting patient privacy.
- Business associate issues: Not having BAAs in place with vendors or failing to ensure business associates protect PHI.
Implementing Privacy Rule Compliance
Organizations should implement these key elements:
- Develop and maintain a comprehensive Notice of Privacy Practices
- Establish policies and procedures for honoring patient access rights
- Implement tracking systems for disclosures (especially for accounting requests)
- Develop authorization forms for uses beyond treatment/payment/operations
- Train all workforce members on privacy obligations
- Implement confidentiality agreements with all staff
- Establish complaint procedures and track complaints
- Designate a privacy officer responsible for compliance
- Conduct annual privacy compliance reviews
- Maintain documentation of all policies and procedures
Frequently Asked Questions
Strengthen Your Privacy Rule Compliance
Implementing comprehensive Privacy Rule compliance requires clear policies, proper documentation, and workforce training. Medcurity helps healthcare organizations develop privacy policies, create compliant Notices of Privacy Practices, establish patient rights procedures, and implement systematic compliance monitoring.
Get Privacy Compliance Review →