Chapter 11: HIPAA Privacy Rule: Part II
• As introduced in chapter 10, the Health Insurance Portability and Accountability Act (HIPAA) Privacy Rule protects
patient information. It also ensures the rights of individuals about whom patient information exists and imposes obligations on
those responsible for that information. This chapter, which exists in conjunction with chapter 10, is part II of the HIPAA Privacy
Rule. It focuses on individual rights; breaches and breach notification; requirements pertaining to researchers using patient
information;
preemption, which is the interplay between federal and state law; administrative requirements imposed on those who are
subject to the HIPAA Privacy Rule; and privacy advocacy by the American Health Information Management Association.
Individual Rights
• The Privacy Rule provides patients with significant rights that allow them some measure of control over their health
information. Those rights include right of access, right to request amendment of protected health information (PHI), right to an
accounting of disclosures, right to request confidential communications, right to request restrictions of PHI, and right to complain
of
Privacy Rule violations. These rights are described next. A chart that details all individual rights except the right to complain of
Privacy Rule violations is located at the end of this chapter (appendix 11).
Access
• Section 164.524 of the Privacy Rule states that an individual has a right of access to inspect and obtain a copy of his
or her own PHI that is contained in a designated record set (DRS), such as a health record (45 CFR 164.524). The individual's right
extends for the same period that the PHI is maintained.
• Access to information may be denied in some situations because it is specifically exempted from access by the Privacy
Rule or it is not part of the DRS. The Privacy Rule preamble makes clear that individuals do not have a right of access to
o Psychotherapy notes
o Information compiled in reasonable anticipation of, or for use in, a civil, criminal, or administrative action or proceedi
o PHI held by clinical laboratories if the Clinical Laboratory Improvement Amendments of 1988 (CLIA) (42 CFR
493) prohibit such access (Note: CLIA regulations aim to ensure quality laboratory testing.)
o PHI held by certain research laboratories that are exempt from the CLIA regulations (45 CFR 164.524)
• Why is it so important that individuals be able to access (with exceptions) their own PHI? Although the physical health
record belongs to the organization that created it, the patient has an interest (or ownership) in the information about him or her
that is contained within the record. To provide no specific right of access allows providers and others the ability to deny access.
For
example, Ohio Revised Code 3701.74 at one time required only hospitals to provide patients with copies of their health records,
thus exempting physicians and other healthcare providers (as well as other CEs that are now subject to the Privacy Rule). Thus,
physicians and others could deny or ignore patients requesting their own information because there was no statute compelling
them to respond. Fortunately, Ohio law subsequently changed in the face of the Privacy Rule's implementation, and patients are
now dually given the right of access through Ohio law and the HIPAA Privacy Rule. Nonetheless, this law is an important reminder
of the need for a federal law that protects patients' rights with respect to their own health information.
Grounds for Denial of Access
• According to the Privacy Rule, a covered entity (CE) can at times deny individuals' access to PHI without providing
them an opportunity to review or appeal the denial. This is an unreviewable denial and is important, particularly in the release of
information.
• Denials that are not subject to an appeals process include
o Requests for access to PHI contained in psychotherapy notes
o PHI held by CEs that are correctional institutions or by providers acting under the direction of correctional institutions
if it jeopardizes safety (the inmate still has the right to inspect his or her PHI)
o PHI created or obtained as part of the DRS by a covered healthcare provider in the course of research that
includes treatment, and the individual in the research study agrees to suspend his or her right to access PHI while the
study is in progress. This is usually for protection of the integrity of the research study.
o PHI obtained from someone other than a healthcare provider under a promise of confidentiality, and access would
be reasonably likely to reveal the source of the information
, o PHI contained in records that are subject to the federal Privacy Act (5 USC 552a) if the denial of access under the
Privacy Act would meet the requirements of that law
• Individuals do have a right to review a denial of access in situations where a licensed healthcare professional
determines that access to PHI would be reasonably likely to
o Endanger the life or physical safety of the individual or another person
o Cause substantial harm to another person (not a healthcare provider) mentioned in the PHI
o Cause substantial harm to the individual or another person if the individual's personal representative requests access
• According to the Privacy Rule, when a denial subject to review is made, the CE must write the denial in plain language
and include a reason. It must explain that the individual has the right to request a review of the denial and describe how the
individual can complain to the CE, including the name or title and phone number of the person or office to contact. Finally, it must
explain how the individual can lodge a complaint with the Secretary of the Department of Health and Human Services (HHS).
When
access to PHI is denied on the grounds mentioned earlier, the individual has the right to have the denial reviewed by a licensed
health care professional who did not participate in the original denial and who is designated by the CE to act as the reviewing
official. The CE must then grant or deny access in accordance with the reviewing official's decision.
Requesting Access to One’s Own PHI
• The Privacy Rule specifies that the CE may require individuals to make their requests in writing, provided it has
informed them of such a requirement. Timely response is important. A CE must act on an individual's request for review of PHI no
later than 30 days after the request is made, extending the response by no more than 30 days if within the 30-day period it gives
the reason for the delay and the date by which it will respond. The CE may extend the time for action on a request for access only
once.
• In responding to an individual's request for access to his or her PHI, the CE must arrange a convenient time and place
inspection with the individual or mail a copy of the PHI at the individual's request. Per HITECH, CEs with EHRs must provide
individuals with PHI electronically or, if the individual requests, send PHI to a designated person or entity electronically (Rinehart-
Thompson 2013).
• The issue of fees was addressed in the January 2013 final rule (AHIMA 2013). In early 2016, the Office for Civil Rights
(OCR) issued further guidance on the individual right of access and fees. It emphasized that, while individuals may be charged a
reasonable cost-based fee, it is to be limited to the cost of
o Certain labor
o Supplies
o Postage (if the individual requested that the PHI be mailed)
o Preparing an explanation or summary, if agreed to by the individual
• Labor is clarified as excluding costs associated with reviewing requests, or searching for and retrieving PHI (such
as locating and reviewing the PHI in the record, and segregating and preparing the requested PHI). Search and retrieval fees
are expressly prohibited for requests by individuals for their own records, although permitted for requests by other.
• OCR clarifies that fee limits apply whether PHI is sent to the individual or whether the individual directs that it be sent
to any third party. Both are access requests by the individual, whether submitted by the individual or forwarded to the CE by the
third party on behalf of the individual. If a third party initiates a request for PHI on its own behalf, with the individual's HIPAA
authorization, fee limits do not apply. Despite the permissibility of limited fees, OCR encourages providing individuals with free
copies of their PHI (HHS 2016a).
• When requests for access to PHI are granted, the CE must provide access to the PHI in the form or format requested i
is readily producible in such form or format. If it is not, it must be produced in a readable hard-copy form or other form or format
agreed to by the CE and the individual (45 CFR 164.524(c)(2)(i)). Individuals cannot be required to purchase portable media if
they prefer their PHI be mailed or e-mailed to them, and a flat $6.50 fee for electronic copies of PHI has been recommended
(HHS 2016a). AHIMA has submitted its concerns regarding the HHS guidance.
• Following the January 2013 final rule, HITECH makes it easier for schools to receive student immunization records
where state or other law requires them prior to student admission. HITECH permits CES to disclose a child's immunization
records (considered a public health activity) to a school with the oral consent of the parent or guardian. This contrasts with the
previous written authorization requirement (HHS 2010, 40895).
• As introduced in chapter 10, the Health Insurance Portability and Accountability Act (HIPAA) Privacy Rule protects
patient information. It also ensures the rights of individuals about whom patient information exists and imposes obligations on
those responsible for that information. This chapter, which exists in conjunction with chapter 10, is part II of the HIPAA Privacy
Rule. It focuses on individual rights; breaches and breach notification; requirements pertaining to researchers using patient
information;
preemption, which is the interplay between federal and state law; administrative requirements imposed on those who are
subject to the HIPAA Privacy Rule; and privacy advocacy by the American Health Information Management Association.
Individual Rights
• The Privacy Rule provides patients with significant rights that allow them some measure of control over their health
information. Those rights include right of access, right to request amendment of protected health information (PHI), right to an
accounting of disclosures, right to request confidential communications, right to request restrictions of PHI, and right to complain
of
Privacy Rule violations. These rights are described next. A chart that details all individual rights except the right to complain of
Privacy Rule violations is located at the end of this chapter (appendix 11).
Access
• Section 164.524 of the Privacy Rule states that an individual has a right of access to inspect and obtain a copy of his
or her own PHI that is contained in a designated record set (DRS), such as a health record (45 CFR 164.524). The individual's right
extends for the same period that the PHI is maintained.
• Access to information may be denied in some situations because it is specifically exempted from access by the Privacy
Rule or it is not part of the DRS. The Privacy Rule preamble makes clear that individuals do not have a right of access to
o Psychotherapy notes
o Information compiled in reasonable anticipation of, or for use in, a civil, criminal, or administrative action or proceedi
o PHI held by clinical laboratories if the Clinical Laboratory Improvement Amendments of 1988 (CLIA) (42 CFR
493) prohibit such access (Note: CLIA regulations aim to ensure quality laboratory testing.)
o PHI held by certain research laboratories that are exempt from the CLIA regulations (45 CFR 164.524)
• Why is it so important that individuals be able to access (with exceptions) their own PHI? Although the physical health
record belongs to the organization that created it, the patient has an interest (or ownership) in the information about him or her
that is contained within the record. To provide no specific right of access allows providers and others the ability to deny access.
For
example, Ohio Revised Code 3701.74 at one time required only hospitals to provide patients with copies of their health records,
thus exempting physicians and other healthcare providers (as well as other CEs that are now subject to the Privacy Rule). Thus,
physicians and others could deny or ignore patients requesting their own information because there was no statute compelling
them to respond. Fortunately, Ohio law subsequently changed in the face of the Privacy Rule's implementation, and patients are
now dually given the right of access through Ohio law and the HIPAA Privacy Rule. Nonetheless, this law is an important reminder
of the need for a federal law that protects patients' rights with respect to their own health information.
Grounds for Denial of Access
• According to the Privacy Rule, a covered entity (CE) can at times deny individuals' access to PHI without providing
them an opportunity to review or appeal the denial. This is an unreviewable denial and is important, particularly in the release of
information.
• Denials that are not subject to an appeals process include
o Requests for access to PHI contained in psychotherapy notes
o PHI held by CEs that are correctional institutions or by providers acting under the direction of correctional institutions
if it jeopardizes safety (the inmate still has the right to inspect his or her PHI)
o PHI created or obtained as part of the DRS by a covered healthcare provider in the course of research that
includes treatment, and the individual in the research study agrees to suspend his or her right to access PHI while the
study is in progress. This is usually for protection of the integrity of the research study.
o PHI obtained from someone other than a healthcare provider under a promise of confidentiality, and access would
be reasonably likely to reveal the source of the information
, o PHI contained in records that are subject to the federal Privacy Act (5 USC 552a) if the denial of access under the
Privacy Act would meet the requirements of that law
• Individuals do have a right to review a denial of access in situations where a licensed healthcare professional
determines that access to PHI would be reasonably likely to
o Endanger the life or physical safety of the individual or another person
o Cause substantial harm to another person (not a healthcare provider) mentioned in the PHI
o Cause substantial harm to the individual or another person if the individual's personal representative requests access
• According to the Privacy Rule, when a denial subject to review is made, the CE must write the denial in plain language
and include a reason. It must explain that the individual has the right to request a review of the denial and describe how the
individual can complain to the CE, including the name or title and phone number of the person or office to contact. Finally, it must
explain how the individual can lodge a complaint with the Secretary of the Department of Health and Human Services (HHS).
When
access to PHI is denied on the grounds mentioned earlier, the individual has the right to have the denial reviewed by a licensed
health care professional who did not participate in the original denial and who is designated by the CE to act as the reviewing
official. The CE must then grant or deny access in accordance with the reviewing official's decision.
Requesting Access to One’s Own PHI
• The Privacy Rule specifies that the CE may require individuals to make their requests in writing, provided it has
informed them of such a requirement. Timely response is important. A CE must act on an individual's request for review of PHI no
later than 30 days after the request is made, extending the response by no more than 30 days if within the 30-day period it gives
the reason for the delay and the date by which it will respond. The CE may extend the time for action on a request for access only
once.
• In responding to an individual's request for access to his or her PHI, the CE must arrange a convenient time and place
inspection with the individual or mail a copy of the PHI at the individual's request. Per HITECH, CEs with EHRs must provide
individuals with PHI electronically or, if the individual requests, send PHI to a designated person or entity electronically (Rinehart-
Thompson 2013).
• The issue of fees was addressed in the January 2013 final rule (AHIMA 2013). In early 2016, the Office for Civil Rights
(OCR) issued further guidance on the individual right of access and fees. It emphasized that, while individuals may be charged a
reasonable cost-based fee, it is to be limited to the cost of
o Certain labor
o Supplies
o Postage (if the individual requested that the PHI be mailed)
o Preparing an explanation or summary, if agreed to by the individual
• Labor is clarified as excluding costs associated with reviewing requests, or searching for and retrieving PHI (such
as locating and reviewing the PHI in the record, and segregating and preparing the requested PHI). Search and retrieval fees
are expressly prohibited for requests by individuals for their own records, although permitted for requests by other.
• OCR clarifies that fee limits apply whether PHI is sent to the individual or whether the individual directs that it be sent
to any third party. Both are access requests by the individual, whether submitted by the individual or forwarded to the CE by the
third party on behalf of the individual. If a third party initiates a request for PHI on its own behalf, with the individual's HIPAA
authorization, fee limits do not apply. Despite the permissibility of limited fees, OCR encourages providing individuals with free
copies of their PHI (HHS 2016a).
• When requests for access to PHI are granted, the CE must provide access to the PHI in the form or format requested i
is readily producible in such form or format. If it is not, it must be produced in a readable hard-copy form or other form or format
agreed to by the CE and the individual (45 CFR 164.524(c)(2)(i)). Individuals cannot be required to purchase portable media if
they prefer their PHI be mailed or e-mailed to them, and a flat $6.50 fee for electronic copies of PHI has been recommended
(HHS 2016a). AHIMA has submitted its concerns regarding the HHS guidance.
• Following the January 2013 final rule, HITECH makes it easier for schools to receive student immunization records
where state or other law requires them prior to student admission. HITECH permits CES to disclose a child's immunization
records (considered a public health activity) to a school with the oral consent of the parent or guardian. This contrasts with the
previous written authorization requirement (HHS 2010, 40895).