Get HIPAA Audit →

HIPAA Privacy Rule Explained: Patient Rights & Provider Obligations

Quick Answer

The HIPAA Privacy Rule gives patients rights to access their health records, request amendments, receive an accounting of disclosures, and request restrictions on how their information is used. Healthcare providers must provide a Notice of Privacy Practices, limit use and disclosure of PHI to treatment/payment/operations or purposes authorized by the patient, and implement safeguards protecting patient privacy. Violations can result in penalties of $100-$1,500,000 per violation.

Overview of the HIPAA Privacy Rule

The HIPAA Privacy Rule (45 CFR Parts 160 and 164, Subpart E) is the regulation that sets federal standards for the use and disclosure of protected health information (PHI) by covered entities and their business associates. Unlike the Security Rule which specifically addresses electronic PHI, the Privacy Rule applies to PHI in any form—electronic, paper, or oral.

The Privacy Rule is built on a core principle: PHI is patient property, and healthcare organizations are stewards responsible for protecting it. The rule grants patients significant rights over their information and limits when and how organizations can use or disclose PHI without patient authorization.

The rule applies to all covered entities (healthcare providers, health plans, healthcare clearinghouses) and their business associates. It's enforced by the Office for Civil Rights within the Department of Health and Human Services.

Patient Rights Under the Privacy Rule

The Privacy Rule grants patients several fundamental rights regarding their health information:

Right to Access

Patients have the right to access and receive a copy of their entire medical record, including clinical notes, test results, imaging reports, and other documentation. Your organization must provide access within 30 days of request (or 60 days if records are off-site). You can charge reasonable copying fees but cannot deny access because you believe the information might be harmful or embarrassing to the patient. The only exceptions are: psychotherapy notes (created by mental health professionals for personal use), information compiled for legal proceedings, and information prohibited from disclosure by other federal laws.

Right to Amendment

Patients can request amendments or corrections to inaccurate information in their medical records. If you agree the record is inaccurate, you must make the amendment. If you deny the request, the patient can submit a statement of disagreement that must be included with the record. You should respond to amendment requests within 60 days. Common amendments include correcting misspelled names, dates of birth errors, or removing diagnoses the patient disputes.

Right to an Accounting of Disclosures

Patients have the right to receive an accounting of all non-routine disclosures of their PHI. This accounting must include: who received the information, when they received it, what information was disclosed, and the purpose of the disclosure. You must provide this accounting within 30 days of request. Disclosures for treatment, payment, healthcare operations, patient authorization, and legal requirements don't need to be tracked, but all other disclosures do.

Right to Request Restrictions

Patients can request restrictions on how you use or disclose their PHI. For example, a patient might request that you not disclose their mental health information to their insurance company, or that certain information not be shared with family members. You're not legally required to agree to all requests, but if you do agree, you must honor the restriction. If you later change your mind, you must notify the patient.

Right to Request Confidential Communications

Patients can request that you communicate with them about their health in a specific way (e.g., calling their work number instead of home, sending mail to an alternative address) or at a specific location. You must accommodate reasonable requests. This is especially important for patients in sensitive situations—domestic violence victims, patients with substance abuse issues, or others who need privacy.

Right to Breach Notification

If unsecured PHI is breached, patients have the right to be notified within 60 days of discovery. The notification must explain what happened, what information was compromised, steps they should take, and what steps your organization is taking to investigate and prevent recurrence.

Permitted Uses and Disclosures of PHI

The Privacy Rule permits certain uses and disclosures of PHI without patient authorization:

Treatment

You can use and disclose PHI as necessary to provide healthcare to the patient. This includes sharing information with other healthcare providers involved in treatment, such as consulting specialists, nursing facilities, or pharmacies.

Payment

You can use and disclose PHI to obtain payment for healthcare services. This includes sharing information with insurance companies for claims processing, benefits eligibility determination, and payment collection.

Healthcare Operations

You can use and disclose PHI for business operations such as quality assurance, utilization review, peer review, training, accreditation, and other administrative purposes necessary to run your healthcare business.

Required by Law

When federal, state, or local law requires disclosure (such as mandatory reporting of child abuse, communicable disease reporting, or legal proceedings), you can disclose PHI without authorization.

Public Health

You can disclose PHI to public health authorities for disease surveillance, outbreak investigations, and other public health activities required or authorized by law.

Law Enforcement

You can disclose PHI to law enforcement when required by law, such as reporting child abuse or responding to a subpoena. You should not disclose PHI based on a request from law enforcement unless there's legal authority requiring it.

Business Operations with Authorization

For uses beyond treatment, payment, and healthcare operations—such as marketing, fundraising, or research—you must obtain patient authorization before using or disclosing PHI.

Notice of Privacy Practices (NPP) Requirements

All covered entities must develop and provide patients with a Notice of Privacy Practices (NPP) that explains how the organization uses and discloses PHI. The NPP is a critical compliance document and a main touchpoint for patients to understand their rights.

Your NPP must explain:

You must provide the NPP to patients at their first appointment (or electronically if available), maintain a copy accessible to patients, and update it whenever there are material changes to your practices. Changes to the NPP should be documented with the effective date.

Marketing Restrictions Under the Privacy Rule

HIPAA severely restricts how healthcare providers can use PHI for marketing purposes:

Common Privacy Rule Violations

The Office for Civil Rights identifies these violations frequently during audits:

Implementing Privacy Rule Compliance

Organizations should implement these key elements:

  1. Develop and maintain a comprehensive Notice of Privacy Practices
  2. Establish policies and procedures for honoring patient access rights
  3. Implement tracking systems for disclosures (especially for accounting requests)
  4. Develop authorization forms for uses beyond treatment/payment/operations
  5. Train all workforce members on privacy obligations
  6. Implement confidentiality agreements with all staff
  7. Establish complaint procedures and track complaints
  8. Designate a privacy officer responsible for compliance
  9. Conduct annual privacy compliance reviews
  10. Maintain documentation of all policies and procedures

Frequently Asked Questions

Can I deny a patient's request to access their medical records?
Generally no, unless the records contain psychotherapy notes created by mental health professionals for their personal use, information compiled for legal proceedings, or information prohibited from disclosure by other federal laws. You cannot deny access because you believe the information might be harmful.
How much can I charge for providing copies of medical records?
You can charge reasonable costs for copying and postage, but not for labor or overhead. State laws may set specific limits. Some states cap charges at 25-50 cents per page. Check your state law for specific amounts allowed.
If a patient requests I not disclose information to their insurance company, must I comply?
If the patient requests a restriction on disclosure, you should honor it if reasonable. However, if you've already agreed to share information with their insurance company for payment purposes, the restriction may affect your ability to get paid. You should discuss the implications with the patient.
Can I market to patients about new services they might be interested in?
You can communicate about services directly related to their care without authorization. For example, notifying a diabetic patient about your new diabetes management program is treatment-related and doesn't require authorization. But marketing unrelated services to patients requires authorization.
What's the difference between the Privacy Rule and the Security Rule?
The Privacy Rule covers all PHI in any form and focuses on when information can be used and disclosed. The Security Rule specifically addresses electronic PHI and focuses on safeguards to protect it.
How long do I need to keep track of disclosures?
You must maintain records of non-routine disclosures for at least 6 years. When patients request an accounting of disclosures, you can only provide information from the past 6 years unless your state law requires a longer period.
What information must my Notice of Privacy Practices include?
Your NPP must explain your uses and disclosures of PHI, patient rights, how to file complaints, contact information, and how you handle breaches. It must be in plain language and made available to all patients.
Can I share patient information with family members?
Only if the patient agrees or if you're communicating with family members involved in the patient's care based on the patient's agreement or inferred consent. You cannot routinely share information with family members without patient authorization.

Strengthen Your Privacy Rule Compliance

Implementing comprehensive Privacy Rule compliance requires clear policies, proper documentation, and workforce training. Medcurity helps healthcare organizations develop privacy policies, create compliant Notices of Privacy Practices, establish patient rights procedures, and implement systematic compliance monitoring.

Get Privacy Compliance Review →