Skip to content

Menu

LexBlog, Inc. logo
NetworkSub-MenuBrowse by SubjectBrowse by PublisherJoin the NetworkGet StartedSubscribeSupportContact
Search
Close

HHS issues new guidance on individual access to PHI under HIPAA

By Conor Duffy on January 13, 2016
Email this postTweet this postLike this postShare this post on LinkedIn

On January 7, 2015, HHS issued new guidance (Guidance) regarding an individual’s right to access his or her health information under HIPAA’s Privacy Rule. The Guidance emphasizes that HIPAA, while protecting the privacy and confidentiality of individuals’ health information, also recognizes the importance of providing individuals with access to their health information.

The Guidance reviews the applicable provisions of the Privacy Rule that establish an individual’s general right to access protected health information (PHI) maintained about the individual by or for a covered entity in a designated record set (found at 45 C.F.R. §164.524). The Guidance notes in part that:

  • Individuals may be required (at the covered entity’s option) to make a written or electronic request for access to PHI;
  • Covered entities must take reasonable steps to verify the identity of an individual making a request for access to PHI;
  • Access to PHI must be provided in the form and format requested (i.e. paper or electronic), if readily producible in that form and format, or if not, in a readable hard copy form or other form and format as agreed to by the covered entity and individual;
  • Access must be provided within 30 calendar days of an individual’s request (which time period may be extended once by 30 days upon notification to the individual);
  • Access may only be denied in limited circumstances set forth by the Privacy Rule, certain of which are subject to review;
  • An individual may also direct a covered entity to transmit PHI about the individual directly to another person or entity; and
  • A covered entity may impose a reasonable, cost-based fee, for providing a copy of PHI or a summary or explanation of such information; provided that such fee may only include the cost of labor for copying the PHI, supplies for creating a paper copy or electronic media, postage, and the preparation of an explanation or summary (other costs permitted under state law may not be included).

The Guidance is accompanied by FAQs regarding the scope of information covered by an individual’s right of access, the type of records or other information covered, and the circumstances under which a covered entity may deny an individual’s request for access to PHI.

In a press release accompanying the release of the Guidance, Jocelyn Samuels – director of the Office for Civil Rights (OCR) – indicated that the Guidance is intended to remove barriers for individuals to accessing their health information. The Guidance appears to be one piece of a broader HHS initiative intended to ensure that individuals understand and are able to exercise their rights under HIPAA. HIPAA-covered entities and individuals will therefore want to continue monitoring HHS and OCR for the release of additional guidance and related tools concerning HIPAA and health information privacy.

Photo of Conor Duffy Conor Duffy

Conor Duffy is a member of Robinson+Cole’s Health Law Group and the firm’s Data Privacy and Security Team. Conor advises hospitals, physician groups, community providers, and other health care entities on general corporate matters and health care issues. He provides legal counsel on…

Conor Duffy is a member of Robinson+Cole’s Health Law Group and the firm’s Data Privacy and Security Team. Conor advises hospitals, physician groups, community providers, and other health care entities on general corporate matters and health care issues. He provides legal counsel on a full range of transactional and regulatory health law issues, including contracting, licensure, mergers and acquisitions, Medicare and Medicaid fraud and abuse laws and regulations, HIPAA compliance, and other data privacy and security matters. Read his rc.com bio here.

Read more about Conor DuffyEmail
Show more Show less
  • Posted in:
    Health Care and Life Sciences, Privacy and Cybersecurity
  • Blog:
    Data Privacy + Cybersecurity Insider
  • Organization:
    Robinson & Cole LLP
  • Article: View Original Source

Call us at 1-800-913-0988 or email sales@lexblog.com.

Facebook LinkedIn Twitter RSS
The Library at LexBlog
  • About LexBlog
  • The Field We Built
  • Library at LexBlog
  • Our Beliefs
  • Our Team
  • Contact LexBlog
  • Disclaimer
  • Editorial Policy
  • Terms of Service
  • Get Started
  • Publishing Solutions
  • Compass
  • Submit a Request
  • Support Center
  • System Status
Copyright © 2026, LexBlog, Inc. All Rights Reserved.
Law blog design & platform by LexBlog LexBlog Logo