HIPAA Rights

Stethoscope and medical records

Most of us believe that our medical and other health information is private and should be protected, and we want to know who has this information.

The Privacy Rule, a Federal law, gives you rights over your health information and sets rules and limits on who can look at and receive your health information.

The Privacy Rule applies to all forms of individuals’ protected health information, whether electronic, written, or oral. The Security Rule is a Federal law that requires security for health information in electronic form.

What to Know

Overview
Who Must Follow HIPAA Privacy and Security Laws?

The Health Insurance Portability and Accountability Act (HIPAA) applies to organizations known as covered entities and certain organizations that perform services on their behalf, known as business associates.

Covered Entities

Covered entities are organizations that must comply with HIPAA privacy and security requirements. These include:

  • Health Plans – Including health insurance companies, Health Maintenance Organizations (HMOs), employer-sponsored health plans, Medicare, Medicaid and certain other government health programs.
  • Health Care Providers – Providers who conduct certain transactions electronically, including physicians, clinics, hospitals, psychologists, chiropractors, nursing homes, pharmacies and dentists.
  • Health Care Clearinghouses – Organizations that convert health information from one format into standardized electronic formats and vice versa.
Business Associates

Business associates are individuals or organizations that perform services for covered entities and require access to protected health information (PHI) to perform those services.

Examples of business associates include:

  • Medical billing and claims processing companies
  • Health plan administration vendors
  • Outside attorneys and legal consultants
  • Accounting and auditing firms
  • Information technology and data management providers
  • Medical record storage and destruction companies
Business Associate Agreements

HIPAA requires covered entities to have written agreements with their business associates that outline how protected health information may be used, disclosed and safeguarded.

Business associates must also enter into similar agreements with any subcontractors who may have access to protected health information.

Both business associates and their subcontractors are required to comply with applicable HIPAA Privacy Rule and Security Rule requirements and must implement appropriate safeguards to protect health information from unauthorized access, use or disclosure.

Who Must Follow HIPAA Privacy and Security Laws?

The Health Insurance Portability and Accountability Act (HIPAA) applies to organizations known as covered entities and certain organizations that perform services on their behalf, known as business associates.

Covered Entities

Covered entities are organizations that must comply with HIPAA privacy and security requirements. These include:

  • Health Plans – Including health insurance companies, Health Maintenance Organizations (HMOs), employer-sponsored health plans, Medicare, Medicaid and certain other government health programs.
  • Health Care Providers – Providers who conduct certain transactions electronically, including physicians, clinics, hospitals, psychologists, chiropractors, nursing homes, pharmacies and dentists.
  • Health Care Clearinghouses – Organizations that convert health information from one format into standardized electronic formats and vice versa.
Business Associates

Business associates are individuals or organizations that perform services for covered entities and require access to protected health information (PHI) to perform those services.

Examples of business associates include:

  • Medical billing and claims processing companies
  • Health plan administration vendors
  • Outside attorneys and legal consultants
  • Accounting and auditing firms
  • Information technology and data management providers
  • Medical record storage and destruction companies
Business Associate Agreements

HIPAA requires covered entities to have written agreements with their business associates that outline how protected health information may be used, disclosed and safeguarded.

Business associates must also enter into similar agreements with any subcontractors who may have access to protected health information.

Both business associates and their subcontractors are required to comply with applicable HIPAA Privacy Rule and Security Rule requirements and must implement appropriate safeguards to protect health information from unauthorized access, use or disclosure.

What Information Is Protected Under HIPAA?

HIPAA protects a wide range of health information that can be used to identify an individual and relates to that person's health condition, healthcare services or payment for healthcare. This information is commonly referred to as Protected Health Information (PHI).

Examples of information protected under HIPAA include:

  • Information contained in your medical records created by doctors, nurses and other healthcare providers.
  • Conversations between your healthcare providers regarding your care or treatment.
  • Health information maintained in your health insurance company's records and computer systems.
  • Billing and payment information maintained by healthcare providers, clinics and health plans.
  • Medical test results, diagnoses, treatment plans and prescription information.
  • Most other health-related information maintained by organizations required to comply with HIPAA.

HIPAA requires covered entities and business associates to safeguard protected health information and limit its use and disclosure as permitted by law.

These protections help ensure that your personal health information remains private while allowing healthcare providers, health plans and related organizations to share information when necessary for treatment, payment and healthcare operations.

How Your Health Information Is Protected

HIPAA requires covered entities and their business associates to take reasonable steps to protect the privacy and security of your health information. These safeguards are designed to prevent unauthorized access, use or disclosure of protected health information (PHI).

To help protect your information, covered entities must:

  • Implement administrative, physical and technical safeguards to secure protected health information.
  • Use and disclose health information only as permitted or required by law.
  • Limit the use and disclosure of health information to the minimum necessary to accomplish the intended purpose.
  • Establish procedures that restrict access to health information to authorized individuals who need the information to perform their job duties.
  • Provide workforce training on privacy, security and the proper handling of protected health information.
  • Monitor compliance and take appropriate action when privacy or security violations occur.

Business associates that perform services for covered entities must also implement safeguards to protect health information and comply with applicable HIPAA Privacy and Security Rule requirements.

These protections help ensure that your personal health information remains confidential, secure and accessible only to authorized individuals who have a legitimate need to use the information.

Your Rights Under the HIPAA Privacy Rule

The HIPAA Privacy Rule gives individuals important rights regarding their protected health information (PHI). Health plans, healthcare providers and other covered entities must comply with these rights and help individuals access and manage their health information.

Your HIPAA Privacy Rights

You have the right to:

  • Access Your Records – Request to inspect and obtain a copy of your health records and other protected health information.
  • Request Corrections – Ask that corrections or amendments be made to your health information if you believe it is incomplete or inaccurate.
  • Receive a Privacy Notice – Obtain a notice explaining how your health information may be used, disclosed and protected.
  • Authorize Certain Uses and Disclosures – Decide whether to allow your health information to be used or shared for certain purposes, such as marketing activities.
  • Request Restrictions – Ask a covered entity to limit how your health information is used or disclosed in certain situations.
  • Receive an Accounting of Disclosures – Request a report showing when and why your health information was shared for certain purposes.
If You Believe Your Rights Have Been Violated

If you believe your health information is not being properly protected or your privacy rights have been denied, you may:

  • File a complaint with your healthcare provider or health insurance plan.
  • File a complaint with the U.S. Department of Health and Human Services (HHS) Office for Civil Rights.

Understanding your HIPAA rights can help you take an active role in protecting your personal health information and ensuring it is used appropriately.

If you have questions about your privacy rights, contact your healthcare provider, health plan or benefits administrator for additional information.

Who Can Look at and Receive Your Health Information?

The HIPAA Privacy Rule sets rules and limits on who may access, use or receive your protected health information. These rules are designed to protect your privacy while still allowing information to be shared when needed for your healthcare.

Your health information may be used or shared:

  • For your treatment and care coordination.
  • To pay doctors, hospitals and other healthcare providers for your care.
  • To help healthcare providers and health plans manage their operations.
  • With family members, relatives, friends or others you identify who are involved in your healthcare or healthcare bills, unless you object.
  • To help ensure quality care and patient safety.
  • To protect public health, such as reporting certain diseases or outbreaks.
  • To make required reports to law enforcement, such as reporting gunshot wounds or other legally required information.

Your health information generally cannot be used or shared without your written permission unless permitted or required by law.

For example, without your authorization, your healthcare provider generally cannot:

  • Give your health information to your employer.
  • Use or share your information for marketing or advertising purposes.
  • Sell your health information.

These protections help ensure that your health information is shared only when appropriate and for purposes allowed under HIPAA.

Your Medical Records
Access to Your Health Information

HIPAA gives individuals important rights regarding access to their protected health information. In most cases, only you or your authorized personal representative has the right to access your medical records.

Healthcare providers and health plans may share copies of your records with another provider or health plan when necessary for treatment or payment purposes, or when you have given your permission.

However, the HIPAA Privacy Rule generally does not require healthcare providers or health plans to share information with other providers or health plans unless otherwise required by law.

Your Rights Include:
  • Requesting access to your medical records and other protected health information.
  • Obtaining copies of your health information in accordance with HIPAA requirements.
  • Designating a personal representative to act on your behalf when authorized.
  • Receiving protections that help keep your health information private and secure.

Understanding your right of access can help you take an active role in managing your healthcare and ensuring the accuracy of your medical information.

If you have questions about accessing your health records, contact your healthcare provider, health plan or benefits administrator for assistance.

Charges for Copies of Health Records

Under HIPAA, individuals generally have the right to obtain copies of their health records from healthcare providers and health plans.

A healthcare provider cannot deny access to your records simply because you have an outstanding balance or have not paid for healthcare services you received.

Providers may charge a reasonable, cost-based fee for:

  • Copying or reproducing the records.
  • Postage or mailing costs, if you request that records be mailed.
  • Supplies used to create the copy, such as paper or electronic media.

However, providers generally may not charge fees for:

  • Searching for your records.
  • Retrieving your records.
  • Verifying or locating your information.

HIPAA is designed to ensure that individuals can reasonably access their health information while allowing providers to recover the actual costs associated with producing copies of records.

If you have questions regarding fees for obtaining copies of your health records, contact your healthcare provider or health plan for additional information.

Provider's Psychotherapy Notes

Under HIPAA, individuals generally have the right to access their health records. However, there are limited exceptions to this right, including a provider's psychotherapy notes.

Psychotherapy notes are personal notes recorded by a mental health professional during or after counseling sessions. These notes document the provider's observations, impressions and analysis of conversations with a patient.

Psychotherapy notes are:

  • Maintained separately from the patient's medical record.
  • Kept separate from billing and administrative records.
  • Used primarily by the mental health professional for treatment purposes.

Because psychotherapy notes receive special protection under HIPAA, patients generally do not have the right to inspect or obtain copies of these notes.

In addition, HIPAA generally prohibits healthcare providers from using or disclosing psychotherapy notes without the patient's written authorization, except in limited situations permitted by law.

These enhanced privacy protections are intended to support open communication between patients and mental health professionals while safeguarding highly sensitive information.

Requesting Corrections to Your Health Information

If you believe information in your medical record or billing record is incorrect or incomplete, HIPAA gives you the right to request a correction, also known as an amendment, to your health information.

After receiving your request, the healthcare provider or health plan must review the information and respond to your request.

If the provider or health plan created the information and determines that it is inaccurate or incomplete, it must amend the record as appropriate.

If the provider or health plan disagrees with your request and chooses not to make the amendment, you still have important rights.

Your Rights if an Amendment Is Denied
  • Receive a written explanation of the denial.
  • Submit a written statement of disagreement explaining why you believe the information is incorrect.
  • Have your statement of disagreement included with your health record.
  • Request that future disclosures of the disputed information include your statement of disagreement when appropriate.

The right to request corrections helps ensure that your health information is as accurate and complete as possible, supporting quality care and informed healthcare decisions.

Health Information in the Workplace
Employment Records and HIPAA

HIPAA's Privacy Rule generally protects an individual's medical and health plan information, but it does not protect employment records maintained by an employer, even when those records contain health-related information.

In most situations, the Privacy Rule does not apply to actions taken by an employer in its role as an employer.

Examples of Employment Records Not Protected by HIPAA
  • Employee medical leave documentation
  • Workers' compensation records maintained by the employer
  • Fitness-for-duty examinations maintained in personnel files
  • Employment-related drug testing records
  • Workplace injury reports maintained as employment records
Employees of Health Plans and Healthcare Providers

If you work for a health plan or a healthcare provider that is subject to HIPAA, your employment records are still not protected by the HIPAA Privacy Rule when those records are maintained by your employer for employment purposes.

However, HIPAA does protect your personal medical records and health plan information when you are receiving healthcare services as a patient or are enrolled as a member of a health plan.

In other words, HIPAA distinguishes between information maintained about you as an employee and information maintained about you as a patient or health plan member.

Requests for Health Information from Your Employer

Employers may request certain health-related information from employees when it is needed for legitimate employment purposes, such as administering sick leave, workers' compensation claims, wellness programs or employer-sponsored health benefits.

However, HIPAA generally limits what your healthcare provider can disclose directly to your employer without your authorization.

What Employers May Request
  • Doctor's notes supporting medical leave requests.
  • Information required for workers' compensation claims.
  • Documentation related to wellness programs.
  • Information necessary for administering health insurance benefits.
Provider Disclosure Restrictions

If your employer contacts your healthcare provider directly to obtain health information about you, the provider generally cannot disclose that information without your written authorization unless disclosure is otherwise permitted or required by law.

In most cases, HIPAA regulates the actions of healthcare providers and health plans regarding the disclosure of protected health information—not the questions an employer may ask an employee.

Questions About Employment-Related Rights

For information regarding workplace rights, leave laws or employment discrimination issues, you may contact:

  • U.S. Department of Labor
    Phone: (866) 4-USA-DOL
  • Equal Employment Opportunity Commission (EEOC)
    Phone: (800) 669-4000

Understanding the distinction between employer records and protected health information can help you better understand your privacy rights under HIPAA.